← Home

@memberjunction/ng-entity-relationship-diagram

MemberJunction: Entity Relationship Diagram (ERD) component for visualizing entity relationships using D3.js force-directed graphs

51
Versions
ISC
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

craig.adam.bcethan-bcjordanfanapourms-bccaeleb.balanesiianzygmuntanag123hiltongrpranavrao-bcsdesai-bcjosue-garcia-bcrkihm-bc

Keywords

angularerdentity-relationship-diagramd3visualizationmemberjunction

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions CI/CD with SLSA provenance attestation; consistent with legitimate automation. ai
source-diff obfuscated-file:dist/lib/components/entity-details/entity-details.component.js AI (source-diff): Long lines are Angular ngc compiled template output, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:dist/lib/components/entity-filter-panel/entity-filter-panel.component.js AI (source-diff): Long lines are Angular ngc compiled template output, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:dist/lib/components/erd-composite/erd-composite.component.js AI (source-diff): Long lines are Angular ngc compiled template output, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:dist/lib/components/erd-diagram.component.js AI (source-diff): Long lines are Angular ngc compiled template output, not obfuscation. Stable pattern for this package. ai
publish-pattern new-deps-added AI (publish-pattern): angular-split is a legitimate Angular UI lib; @memberjunction/ng-ui-components is same-org. No malicious pattern. ai
dependencies unvetted-dep:angular-split AI (dependencies): angular-split is a well-known Angular UI library; its use here is legitimate and consistent with the package's UI component purpose. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a standard Angular/TypeScript runtime implicit dep; not directly imported by convention. ai
phantom-deps phantom-dep:@types/d3 AI (phantom-deps): Type-only package loaded by TypeScript framework convention, not directly imported. ai
phantom-deps phantom-dep:@memberjunction/ng-ui-components AI (phantom-deps): Same-org Angular library; may be used via Angular module imports rather than direct TS imports. ai

Versions (showing 51 of 74)

View all versions
Version Deps Published
5.48.0 11 / 5
5.47.0 11 / 5
5.46.0 11 / 5
5.45.1 11 / 5
5.45.0 11 / 5
5.44.0 11 / 5
5.43.0 11 / 4
5.42.0 11 / 4
5.41.0 11 / 4
5.40.2 11 / 4
5.40.1 11 / 4
5.40.0 11 / 4
5.39.0 11 / 4
5.38.0 11 / 4
5.37.0 11 / 4
5.36.0 11 / 4
5.35.0 11 / 4
5.34.1 11 / 4
5.34.0 11 / 4
5.33.0 11 / 4
5.32.0 11 / 4
5.31.0 11 / 4
5.30.1 10 / 4
5.27.1 10 / 4
5.27.0 10 / 4
5.26.0 10 / 4
5.25.0 9 / 4
5.24.0 9 / 4
5.23.0 9 / 4
5.22.0 8 / 4
5.21.0 8 / 4
5.20.0 8 / 4
5.19.0 8 / 4
5.18.0 8 / 4
5.17.0 8 / 4
5.16.0 8 / 4
5.15.0 8 / 4
5.14.0 8 / 4
5.13.0 8 / 4
5.12.0 8 / 4
5.11.0 8 / 4
5.10.1 8 / 4
5.10.0 8 / 4
5.9.0 8 / 4
5.8.0 8 / 4
5.7.0 8 / 4
5.6.0 8 / 4
5.5.0 8 / 4
5.4.1 8 / 4
5.4.0 8 / 4
5.3.1 8 / 4

v5.48.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.47.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.46.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.45.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.45.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.44.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.43.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.