@finos/legend-server-marketplace
Legend Marketplace server client
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:serializr | AI (dependencies): serializr is a well-established serialization library; its use here is expected and stable across versions of this package. | ai | |
| provenance | no-provenance | AI (provenance): FINOS legend-studio monorepo consistently publishes without Sigstore provenance; stable false positive for this package family. | ai |
Versions (showing 51 of 123)
| Version | Deps | Published |
|---|---|---|
| 0.1.86 | 3 / 8 | |
| 0.1.85 | 3 / 8 | |
| 0.1.84 | 3 / 8 | |
| 0.1.83 | 3 / 8 | |
| 0.1.82 | 3 / 8 | |
| 0.1.81 | 3 / 8 | |
| 0.1.80 | 3 / 8 | |
| 0.1.79 | 3 / 8 | |
| 0.1.78 | 3 / 8 | |
| 0.1.77 | 3 / 8 | |
| 0.1.76 | 3 / 8 | |
| 0.1.75 | 3 / 8 | |
| 0.1.74 | 3 / 8 | |
| 0.1.73 | 3 / 8 | |
| 0.1.72 | 3 / 8 | |
| 0.1.71 | 3 / 8 | |
| 0.1.70 | 3 / 8 | |
| 0.1.69 | 3 / 8 | |
| 0.1.68 | 3 / 8 | |
| 0.1.67 | 3 / 8 | |
| 0.1.66 | 3 / 8 | |
| 0.1.65 | 3 / 8 | |
| 0.1.64 | 3 / 8 | |
| 0.1.63 | 3 / 8 | |
| 0.1.62 | 3 / 8 | |
| 0.1.61 | 3 / 8 | |
| 0.1.60 | 3 / 8 | |
| 0.1.59 | 3 / 8 | |
| 0.1.58 | 3 / 8 | |
| 0.1.57 | 3 / 8 | |
| 0.1.56 | 3 / 8 | |
| 0.1.55 | 3 / 8 | |
| 0.1.54 | 3 / 8 | |
| 0.1.53 | 3 / 8 | |
| 0.1.52 | 3 / 8 | |
| 0.1.51 | 3 / 8 | |
| 0.1.50 | 3 / 8 | |
| 0.1.49 | 3 / 8 | |
| 0.1.48 | 3 / 8 | |
| 0.1.47 | 3 / 8 | |
| 0.1.46 | 3 / 8 | |
| 0.1.45 | 3 / 8 | |
| 0.1.44 | 3 / 8 | |
| 0.1.43 | 3 / 8 | |
| 0.1.42 | 3 / 8 | |
| 0.1.40 | 3 / 8 | |
| 0.1.39 | 3 / 8 | |
| 0.1.38 | 3 / 8 | |
| 0.1.37 | 3 / 8 | |
| 0.1.36 | 3 / 8 | |
| 0.1.35 | 3 / 8 |
v0.1.86
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.85
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.84
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.83
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.82
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.81
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.80
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.79
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.78
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.77
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.