@memberjunction/server
MemberJunction: This project provides API access via GraphQL to the common data store.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:graphql-subscriptions | AI (phantom-deps): Used via config/framework convention, consistent across monorepo packages. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Monorepo release adding sibling internal packages, not injected code. | ai | |
| phantom-deps | phantom-dep:@memberjunction/record-comparison | AI (phantom-deps): Same-org monorepo package, loaded by convention. | ai | |
| dependencies | unvetted-dep:@memberjunction/ai-bridge-ringcentral | AI (dependencies): First-party monorepo sibling, version-locked. | ai | |
| dependencies | unvetted-dep:@memberjunction/ai-bridge-vonage | AI (dependencies): First-party monorepo sibling, version-locked. | ai | |
| dependencies | unvetted-dep:@memberjunction/ai-bridge-twilio | AI (dependencies): First-party monorepo sibling, version-locked. | ai | |
| dependencies | unvetted-dep:@memberjunction/ai-bridge-teams | AI (dependencies): First-party monorepo sibling, version-locked. | ai | |
| dependencies | unvetted-dep:@memberjunction/remote-browser-selfhost | AI (dependencies): Same-org sibling package released in lockstep; consistent with monorepo versioning pattern. | ai | |
| dependencies | unvetted-dep:@memberjunction/remote-browser-server | AI (dependencies): Same-org sibling package released in lockstep; consistent with monorepo versioning pattern. | ai | |
| dependencies | unvetted-dep:@memberjunction/remote-browser-base | AI (dependencies): Same-org sibling package released in lockstep; consistent with monorepo versioning pattern. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Used in auth/magic-link token decoding — standard pattern, not obfuscation. | ai | |
| dependencies | unvetted-dep:@memberjunction/integration-progress-artifacts | AI (dependencies): Same-org package pinned to matching monorepo version; consistent with normal MemberJunction release cadence. | ai | |
| dependencies | unvetted-dep:@memberjunction/lists | AI (dependencies): Same-org monorepo package pinned to matching version; consistent with all other @memberjunction/* deps in this package. | ai | |
| dependencies | unvetted-dep:type-graphql | AI (dependencies): type-graphql 2.0.0-beta.3 is a legitimate GraphQL framework beta; stable dependency for this package across many versions. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are same-org @memberjunction/* packages at matching version, consistent with monorepo release pattern. | ai | |
| phantom-deps | phantom-dep:@memberjunction/communication-sendgrid | AI (phantom-deps): Same-org plugin loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@memberjunction/tag-engine-base | AI (phantom-deps): Same-org plugin loaded by convention; consistent with this package's established pattern of convention-loaded MJ deps. | ai | |
| phantom-deps | phantom-dep:@memberjunction/computer-use-engine | AI (phantom-deps): Same-org plugin loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@memberjunction/data-context-server | AI (phantom-deps): Same-org plugin loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@memberjunction/scheduling-base-types | AI (phantom-deps): Same-org plugin loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@memberjunction/actions-bizapps-social | AI (phantom-deps): Same-org plugin loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@memberjunction/communication-ms-graph | AI (phantom-deps): Same-org plugin loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@memberjunction/scheduling-engine-base | AI (phantom-deps): Same-org plugin loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@memberjunction/ai-agent-manager-actions | AI (phantom-deps): Same-org plugin loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@memberjunction/actions-bizapps-accounting | AI (phantom-deps): Same-org plugin loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@memberjunction/actions-bizapps-formbuilders | AI (phantom-deps): Same-org plugin loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:graphql-scalars | AI (phantom-deps): Config-convention loaded plugin in this monorepo server package. | ai | |
| phantom-deps | phantom-dep:@types/cors | AI (phantom-deps): Framework-scoped @types package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): Framework-scoped @types package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/ws | AI (phantom-deps): Framework-scoped @types package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/pg | AI (phantom-deps): Framework-scoped @types package; stable false positive. | ai | |
| phantom-deps | phantom-dep:jwks-rsa | AI (phantom-deps): Auth library loaded by convention; stable false positive for this server package. | ai | |
| phantom-deps | phantom-dep:typedi | AI (phantom-deps): Same-ecosystem plugin loaded by convention in this monorepo server package. | ai | |
| phantom-deps | phantom-dep:@memberjunction/actions-apollo | AI (phantom-deps): Same-org monorepo package loaded by convention. | ai | |
| phantom-deps | phantom-dep:@memberjunction/core-actions | AI (phantom-deps): Same-org monorepo package loaded by convention. | ai | |
| phantom-deps | phantom-dep:@memberjunction/sql-dialect | AI (phantom-deps): Same-org monorepo package loaded by convention. | ai | |
| phantom-deps | phantom-dep:@memberjunction/doc-utils | AI (phantom-deps): Same-org monorepo package loaded by convention. | ai | |
| phantom-deps | phantom-dep:@memberjunction/ai-agent-manager | AI (phantom-deps): Same-org monorepo package loaded by convention. | ai | |
| phantom-deps | phantom-dep:@memberjunction/ai-provider-bundle | AI (phantom-deps): Same-org monorepo package loaded by convention. | ai | |
| phantom-deps | phantom-dep:@memberjunction/scheduling-actions | AI (phantom-deps): Same-org monorepo package loaded by convention. | ai | |
| phantom-deps | phantom-dep:@memberjunction/actions-bizapps-crm | AI (phantom-deps): Same-org monorepo package loaded by convention. | ai | |
| phantom-deps | phantom-dep:@memberjunction/actions-bizapps-lms | AI (phantom-deps): Same-org monorepo package loaded by convention. | ai | |
| phantom-deps | phantom-dep:@memberjunction/ai-vectors-pinecone | AI (phantom-deps): Same-org monorepo package loaded by convention. | ai | |
| phantom-deps | phantom-dep:@memberjunction/queue | AI (phantom-deps): Same-org monorepo package loaded by convention. | ai | |
| phantom-deps | phantom-dep:@types/jsonwebtoken | AI (phantom-deps): Framework-scoped @types package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/compression | AI (phantom-deps): Framework-scoped @types package; stable false positive. | ai | |
| typosquat | typosquat.levenshtein:semver | AI (typosquat): Scoped @memberjunction/server is a legitimate monorepo server package, not a typosquat of semver. | ai |
Versions (showing 51 of 95)
| Version | Deps | Published |
|---|---|---|
| 5.49.0 | 128 / 3 | |
| 5.48.0 | 128 / 3 | |
| 5.47.0 | 128 / 3 | |
| 5.46.0 | 128 / 3 | |
| 5.45.1 | 128 / 3 | |
| 5.45.0 | 128 / 3 | |
| 5.44.0 | 123 / 3 | |
| 5.43.0 | 122 / 3 | |
| 5.42.0 | 122 / 3 | |
| 5.41.0 | 117 / 3 | |
| 5.40.2 | 113 / 3 | |
| 5.40.1 | 113 / 3 | |
| 5.40.0 | 113 / 3 | |
| 5.39.0 | 109 / 3 | |
| 5.38.0 | 108 / 3 | |
| 5.37.0 | 108 / 3 | |
| 5.36.0 | 108 / 3 | |
| 5.35.0 | 106 / 3 | |
| 5.34.1 | 106 / 3 | |
| 5.34.0 | 106 / 3 | |
| 5.33.0 | 106 / 3 | |
| 5.32.0 | 106 / 3 | |
| 5.31.0 | 106 / 3 | |
| 5.30.1 | 104 / 3 | |
| 5.30.0 | 104 / 3 | |
| 5.29.0 | 104 / 3 | |
| 5.28.0 | 102 / 3 | |
| 5.27.1 | 102 / 3 | |
| 5.27.0 | 102 / 3 | |
| 5.26.0 | 102 / 3 | |
| 5.25.0 | 99 / 3 | |
| 5.24.0 | 99 / 3 | |
| 5.23.0 | 99 / 3 | |
| 5.22.0 | 99 / 3 | |
| 5.21.0 | 98 / 3 | |
| 5.20.0 | 98 / 3 | |
| 5.19.0 | 98 / 3 | |
| 5.18.0 | 98 / 3 | |
| 5.17.0 | 98 / 3 | |
| 5.16.0 | 96 / 3 | |
| 5.15.0 | 95 / 3 | |
| 5.14.0 | 95 / 3 | |
| 5.13.0 | 95 / 3 | |
| 5.12.0 | 95 / 3 | |
| 5.11.0 | 95 / 3 | |
| 5.10.1 | 95 / 3 | |
| 5.10.0 | 95 / 3 | |
| 5.9.0 | 95 / 3 | |
| 5.8.0 | 91 / 3 | |
| 5.7.0 | 91 / 3 | |
| 5.6.0 | 91 / 3 |
v5.49.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.48.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.47.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.46.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.45.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.45.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.44.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.43.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.20.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.19.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.18.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.17.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.16.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.15.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.14.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.