@memberjunction/ng-markdown
MemberJunction: Lightweight Angular markdown component with Prism.js highlighting, Mermaid diagrams, and extensible features
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@memberjunction/markdown-core | AI (dependencies): First-party MemberJunction package, version-locked to same release, internal refactor. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is same-org sibling package replacing marked-* deps, not a third-party addition. | ai | |
| source-diff | obfuscated-file:dist/lib/components/markdown.component.js | AI (source-diff): File is standard Angular ngc-compiled output with long lines from inlined templates/metadata, not obfuscation. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publisher with SLSA provenance; consistent with MemberJunction monorepo automation. | ai | |
| dependencies | unvetted-dep:marked-alert | AI (dependencies): marked-alert is a legitimate marked.js plugin for GH-style alert blocks; appropriate for this markdown component. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is an Angular/TypeScript runtime implicit dep; stable false positive for Angular packages. | ai |
Versions (showing 51 of 82)
| Version | Deps | Published |
|---|---|---|
| 5.49.0 | 4 / 5 | |
| 5.48.0 | 4 / 5 | |
| 5.47.0 | 4 / 5 | |
| 5.46.0 | 4 / 5 | |
| 5.45.1 | 4 / 5 | |
| 5.45.0 | 4 / 5 | |
| 5.44.0 | 8 / 4 | |
| 5.43.0 | 8 / 3 | |
| 5.42.0 | 8 / 3 | |
| 5.41.0 | 8 / 3 | |
| 5.40.2 | 8 / 3 | |
| 5.40.1 | 8 / 3 | |
| 5.40.0 | 8 / 3 | |
| 5.39.0 | 8 / 3 | |
| 5.38.0 | 8 / 3 | |
| 5.37.0 | 8 / 3 | |
| 5.36.0 | 8 / 3 | |
| 5.35.0 | 8 / 3 | |
| 5.34.1 | 8 / 3 | |
| 5.34.0 | 8 / 3 | |
| 5.33.0 | 8 / 3 | |
| 5.32.0 | 8 / 3 | |
| 5.31.0 | 8 / 3 | |
| 5.30.1 | 8 / 3 | |
| 5.30.0 | 8 / 3 | |
| 5.29.0 | 8 / 3 | |
| 5.28.0 | 8 / 3 | |
| 5.27.1 | 8 / 3 | |
| 5.27.0 | 8 / 3 | |
| 5.26.0 | 8 / 3 | |
| 5.25.0 | 8 / 3 | |
| 5.24.0 | 8 / 3 | |
| 5.23.0 | 8 / 3 | |
| 5.22.0 | 8 / 3 | |
| 5.21.0 | 8 / 3 | |
| 5.20.0 | 8 / 3 | |
| 5.19.0 | 8 / 3 | |
| 5.18.0 | 8 / 3 | |
| 5.17.0 | 8 / 3 | |
| 5.16.0 | 8 / 3 | |
| 5.15.0 | 8 / 3 | |
| 5.14.0 | 8 / 3 | |
| 5.13.0 | 8 / 3 | |
| 5.12.0 | 8 / 3 | |
| 5.11.0 | 8 / 3 | |
| 5.10.1 | 8 / 3 | |
| 5.10.0 | 8 / 3 | |
| 5.9.0 | 8 / 3 | |
| 5.8.0 | 8 / 3 | |
| 5.7.0 | 8 / 3 | |
| 5.6.0 | 8 / 3 |
v5.49.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.48.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.47.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.46.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.45.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.45.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.44.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.