@memberjunction/tag-engine-base
MemberJunction: Tag Engine Base - hierarchical tag registry with lookup helpers, usable on client and server
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from individual account to GitHub Actions CI/CD with SLSA attestation; expected for monorepo automation. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All new deps are same-org @memberjunction packages at matching version 5.24.0; consistent monorepo release pattern. | ai | |
| dependencies | unvetted-dep:@memberjunction/core | AI (dependencies): Internal monorepo sibling dependency; same versioned release from the same publisher. | ai | |
| dependencies | unvetted-dep:@memberjunction/global | AI (dependencies): Internal monorepo sibling dependency; same versioned release from the same publisher. | ai | |
| dependencies | unvetted-dep:@memberjunction/core-entities | AI (dependencies): Internal monorepo sibling dependency; same versioned release from the same publisher. | ai |
Versions (showing 33 of 33)
| Version | Deps | Published |
|---|---|---|
| 5.49.0 | 3 / 3 | |
| 5.48.0 | 3 / 3 | |
| 5.47.0 | 3 / 3 | |
| 5.46.0 | 3 / 3 | |
| 5.45.1 | 3 / 3 | |
| 5.45.0 | 3 / 3 | |
| 5.44.0 | 3 / 3 | |
| 5.43.0 | 3 / 3 | |
| 5.42.0 | 3 / 3 | |
| 5.41.0 | 3 / 3 | |
| 5.40.2 | 3 / 3 | |
| 5.40.1 | 3 / 3 | |
| 5.40.0 | 3 / 3 | |
| 5.39.0 | 3 / 3 | |
| 5.38.0 | 3 / 3 | |
| 5.37.0 | 3 / 3 | |
| 5.36.0 | 3 / 3 | |
| 5.35.0 | 3 / 3 | |
| 5.34.1 | 3 / 3 | |
| 5.34.0 | 3 / 3 | |
| 5.33.0 | 3 / 3 | |
| 5.32.0 | 3 / 3 | |
| 5.31.0 | 3 / 3 | |
| 5.30.1 | 3 / 3 | |
| 5.30.0 | 3 / 3 | |
| 5.29.0 | 3 / 3 | |
| 5.28.0 | 3 / 3 | |
| 5.27.1 | 3 / 3 | |
| 5.27.0 | 3 / 3 | |
| 5.26.0 | 3 / 3 | |
| 5.25.0 | 3 / 3 | |
| 5.24.0 | 3 / 3 | |
| 0.0.1 | 0 / 0 |
v5.49.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.48.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.47.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.46.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.45.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.45.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.44.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.