← Home

@openui5/sap.ui.integration

OpenUI5 UI Library sap.ui.integration

26
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

sap-ospo-adminopenui5-bot

Keywords

openui5sapui5ui5

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/cs-BVi3NBx2.js AI (source-diff): Minified CLDR locale data with Unicode license header; not obfuscated malware. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/de-DpMS1P9x.js AI (source-diff): Minified CLDR locale data with Unicode license header; not obfuscated malware. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/de_AT-DVWPcXpS.js AI (source-diff): Minified CLDR locale data with Unicode license header; not obfuscated malware. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/de_CH-CfU5U4in.js AI (source-diff): Minified CLDR locale data with Unicode license header; not obfuscated malware. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/cnr-jy3FEGQX.js AI (source-diff): Minified CLDR locale data with Unicode license header; not obfuscated malware. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/da-CeRjp7Gw.js AI (source-diff): Minified CLDR locale data with Unicode license header; not obfuscated malware. ai
source-diff net-exec-file:src/sap/ui/integration/designtime/thirdparty/ajv.js AI (source-diff): AJV JSON schema validator; new Function() is its documented schema-compilation mechanism, not malware. ai
semgrep semgrep:new-function-constructor AI (semgrep): AJV schema compiler pattern; stable false positive for this package. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ca-CkzsZJhe.js AI (source-diff): CLDR locale data file (Catalan) with explicit Unicode license header; minified data bundle. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar_EG-CGlHr-jg.js AI (source-diff): CLDR locale data file (Arabic Egypt) with explicit Unicode license header; minified data bundle, not malicious. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar_SA-D0iF05tg.js AI (source-diff): CLDR locale data file (Arabic Saudi Arabia) with explicit Unicode license header; minified data bundle. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar-gaI1v_KV.js AI (source-diff): CLDR locale data file (Arabic) with explicit Unicode license header; minified data bundle. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/bg-CJrwzo8x.js AI (source-diff): CLDR locale data file (Bulgarian) with explicit Unicode license header; minified data bundle. ai
phantom-deps phantom-dep:@openui5/sap.ui.table AI (phantom-deps): Same @openui5 org scope; OpenUI5 packages declare deps for module resolution without direct imports. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ca-432aede8.js AI (source-diff): CLDR locale data file (Unicode license); minified by design, not obfuscated malware. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar_EG-bec371f8.js AI (source-diff): CLDR locale data file (Unicode license); minified by design, not obfuscated malware. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/bg-c8a3d631.js AI (source-diff): CLDR locale data file (Unicode license); minified by design, not obfuscated malware. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar-3d86671f.js AI (source-diff): CLDR locale data file (Unicode license); minified by design, not obfuscated malware. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar_SA-013516b9.js AI (source-diff): CLDR locale data file (Unicode license); minified by design, not obfuscated malware. ai
source-diff large-new-source-files AI (source-diff): Size increase explained by addition of legitimate thirdparty bundles (AdaptiveCards, CLDR locale data); stable for this package. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar_SA-CVd8CQkH.js AI (source-diff): CLDR locale data file with explicit Unicode license header; minified by nature. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/adaptive-expressions.js AI (source-diff): Legitimate minified Microsoft adaptive-expressions library vendored as thirdparty dependency. ai
source-diff net-exec-file:src/sap/ui/integration/thirdparty/adaptive-expressions.js AI (source-diff): False positive on browserify UMD wrapper; no actual network calls or dynamic code execution in malicious sense. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar_EG-CsHsH5NB.js AI (source-diff): CLDR locale data file with explicit Unicode license header; minified by nature. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar-BBtO1xV9.js AI (source-diff): CLDR locale data file with explicit Unicode license header; minified by nature. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/bg-B1LO90TV.js AI (source-diff): CLDR locale data file with explicit Unicode license header; minified by nature. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ca-D59F9iL9.js AI (source-diff): CLDR locale data file with explicit Unicode license header; minified by nature. ai
source-diff source-size-tripled AI (source-diff): Size increase reflects addition of adaptive cards feature with vendored thirdparty libraries, not injected payload. ai
source-diff net-exec-file:src/sap/ui/integration/thirdparty/webcomponents/bundle.es5.js AI (source-diff): XHR calls are from css-vars-ponyfill polyfill fetching CSS; no dropper/loader behavior. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/adaptivecards.js AI (source-diff): Standard webpack bundle of Microsoft's AdaptiveCards library with MIT license header; not malicious obfuscation. ai
source-diff obfuscated-file:src/sap/ui/integration/thirdparty/adaptivecards-templating.js AI (source-diff): Standard webpack bundle of Microsoft's adaptivecards-templating library; not malicious obfuscation. ai
source-diff obfuscated-file:src/sap/ui/integration/designtime/cardEditor/util/CommonPatterns.js AI (source-diff): Long line is a complex email validation regex in an OpenUI5 SAP-licensed file, not obfuscated malware. ai
phantom-deps phantom-dep:@openui5/sap.m AI (phantom-deps): Sibling monorepo package; runtime-loaded via UI5 module system, not static import. ai
semgrep semgrep:eval-usage AI (semgrep): eval() used solely as a CSP capability probe (eval("") in try/catch); not an arbitrary code execution risk. ai
phantom-deps phantom-dep:@openui5/sap.f AI (phantom-deps): Sibling monorepo package; runtime-loaded via UI5 module system, not static import. ai
phantom-deps phantom-dep:@openui5/sap.ui.unified AI (phantom-deps): Sibling monorepo package; runtime-loaded via UI5 module system, not static import. ai
phantom-deps phantom-dep:@openui5/sap.ui.layout AI (phantom-deps): Sibling monorepo package; runtime-loaded via UI5 module system, not static import. ai
phantom-deps phantom-dep:@openui5/sap.ui.core AI (phantom-deps): Sibling monorepo package; runtime-loaded via UI5 module system, not static import. ai

Versions (showing 26 of 26)

Version Deps Published
1.148.0 5 / 0
1.147.1 5 / 0
1.147.0 5 / 0
1.145.3 5 / 0
1.145.2 5 / 0
1.145.1 5 / 0
1.142.9 5 / 0
1.142.8 5 / 0
1.142.7 5 / 0
1.136.17 6 / 0
1.136.16 6 / 0
1.136.15 6 / 0
1.120.44 5 / 0
1.120.43 5 / 0
1.108.50 2 / 0
1.96.46 2 / 0
1.96.45 2 / 0
1.84.56 2 / 0
1.84.55 2 / 0
1.71.78 2 / 0
1.71.77 2 / 0
1.71.76 2 / 0
1.71.75 2 / 0
1.71.74 2 / 0
1.71.73 2 / 0
1.71.72 2 / 0

v1.148.0

7 findings
HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/cnr-jy3FEGQX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/cs-BVi3NBx2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/da-CeRjp7Gw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/de_AT-DVWPcXpS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/de_CH-CfU5U4in.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/de-DpMS1P9x.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.147.0

10 findings
HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards-templating.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_EG-CsHsH5NB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_SA-CVd8CQkH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar-BBtO1xV9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/bg-B1LO90TV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ca-D59F9iL9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.145.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.145.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.145.1

10 findings
HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards-templating.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_EG-CsHsH5NB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_SA-CVd8CQkH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar-BBtO1xV9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/bg-B1LO90TV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ca-D59F9iL9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.142.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.142.8

10 findings
HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards-templating.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_EG-CsHsH5NB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_SA-CVd8CQkH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar-BBtO1xV9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/bg-B1LO90TV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ca-D59F9iL9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.142.7

10 findings
HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards-templating.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_EG-CsHsH5NB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_SA-CVd8CQkH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar-BBtO1xV9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/bg-B1LO90TV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ca-D59F9iL9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.136.17

46 findings
HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/cnr-DbKJTxGN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/cs-BaB3d9Av.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/da-CTDYg05i.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/de_AT-C0Q-I35O.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/de_CH-V6zqRGuT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/de-BPAvOyho.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/el_CY-DM-mftU_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/el-CE6EdnmY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/en_AU-DdpdhNc9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/en_GB-DR37sckE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/en_HK-C3ORwL4y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/en_IE-CImesKWm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/en_IN-BnP0Xsux.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/en_NZ-D-XmB6sh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/en_PG-k1g6MW0k.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/en_SG-CH-OueZe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/en_ZA-De7Q7wq-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/en-BV_fMYiZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/es_AR-bphqT9e8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/es_BO-9iWEF7Cs.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/es_CL-Cma-TrGh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/es_CO-Co5-6aNz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/es_MX-DOMSkspG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/es_PE-Thtj5270.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/es_UY-B6Fj2AOa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/es_VE-BIY0wat6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/es-CUYgeeV2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/et-h7DaePYx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/fa-BSumtYoR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/fi-CY8p4VYP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/fr_BE-fS0pUgwn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/fr_CA-HJakdL_2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/fr_CH-CsYAhWeP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/fr_LU-CHqDsjpc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/fr-c7VTGFC1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/he-DvqV-7FS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/hi-DtIyTix1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/hr-DO7SyOn5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/hu-CXT-q6md.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/id-D7Ji1Vol.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/it_CH-DXNpHhgj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/it-B30H1Zn6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ja-HOZtY2HT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/kk-CyER5Yfk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ko-CCOZRLOI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.136.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.136.15

10 findings
HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards-templating.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_EG-CGlHr-jg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_SA-D0iF05tg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar-gaI1v_KV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/bg-CJrwzo8x.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ca-CkzsZJhe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.120.44

10 findings
HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards-templating.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_EG-bec371f8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_SA-013516b9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar-3d86671f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/bg-c8a3d631.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ca-432aede8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.120.43

10 findings
HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards-templating.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_EG-bec371f8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_SA-013516b9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar-3d86671f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/bg-c8a3d631.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ca-432aede8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.108.50

11 findings
HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: src/sap/ui/integration/thirdparty/adaptive-expressions.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards-templating.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_EG-bec371f8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar_SA-013516b9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ar-3d86671f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/bg-c8a3d631.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/webcomponents/ca-432aede8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/designtime/cardEditor/util/CommonPatterns.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.96.46

5 findings
HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards-templating.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: src/sap/ui/integration/thirdparty/webcomponents/bundle.es5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: src/sap/ui/integration/designtime/cardEditor/util/CommonPatterns.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.96.45

5 findings
HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards-templating.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: src/sap/ui/integration/thirdparty/webcomponents/bundle.es5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: src/sap/ui/integration/designtime/cardEditor/util/CommonPatterns.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.84.56

3 findings
HIGH New file with network + code execution: src/sap/ui/integration/designtime/thirdparty/ajv.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: src/sap/ui/integration/thirdparty/webcomponents/bundle.es5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.84.55

6 findings
HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards-templating.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/sap/ui/integration/thirdparty/adaptivecards.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: src/sap/ui/integration/designtime/thirdparty/ajv.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: src/sap/ui/integration/thirdparty/webcomponents/bundle.es5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: src/sap/ui/integration/designtime/cardEditor/util/CommonPatterns.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.71.78

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.71.77

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.71.76

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.71.75

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.71.74

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.71.73

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.71.72

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.