@openui5/sap.ui.integration
OpenUI5 UI Library sap.ui.integration
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/de-db7ee200.js | AI (source-diff): CLDR locale-data JSON, not obfuscated code. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/de_CH-b2e7405d.js | AI (source-diff): CLDR locale-data JSON, not obfuscated code. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/cs-cb494530.js | AI (source-diff): CLDR locale-data JSON, not obfuscated code. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/da-b8216f78.js | AI (source-diff): CLDR locale-data JSON, not obfuscated code. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/de_AT-16212e69.js | AI (source-diff): CLDR locale-data JSON, not obfuscated code. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Same-org OpenUI5 sibling libraries pinned to identical version. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/de-DpMS1P9x.js | AI (source-diff): Minified CLDR locale data with Unicode license header; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/de_AT-DVWPcXpS.js | AI (source-diff): Minified CLDR locale data with Unicode license header; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/cnr-jy3FEGQX.js | AI (source-diff): Minified CLDR locale data with Unicode license header; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/cs-BVi3NBx2.js | AI (source-diff): Minified CLDR locale data with Unicode license header; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/da-CeRjp7Gw.js | AI (source-diff): Minified CLDR locale data with Unicode license header; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/de_CH-CfU5U4in.js | AI (source-diff): Minified CLDR locale data with Unicode license header; not obfuscated malware. | ai | |
| source-diff | net-exec-file:src/sap/ui/integration/designtime/thirdparty/ajv.js | AI (source-diff): AJV JSON schema validator; new Function() is its documented schema-compilation mechanism, not malware. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): AJV schema compiler pattern; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar_SA-D0iF05tg.js | AI (source-diff): CLDR locale data file (Arabic Saudi Arabia) with explicit Unicode license header; minified data bundle. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/bg-CJrwzo8x.js | AI (source-diff): CLDR locale data file (Bulgarian) with explicit Unicode license header; minified data bundle. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ca-CkzsZJhe.js | AI (source-diff): CLDR locale data file (Catalan) with explicit Unicode license header; minified data bundle. | ai | |
| phantom-deps | phantom-dep:@openui5/sap.ui.table | AI (phantom-deps): Same @openui5 org scope; OpenUI5 packages declare deps for module resolution without direct imports. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar_EG-CGlHr-jg.js | AI (source-diff): CLDR locale data file (Arabic Egypt) with explicit Unicode license header; minified data bundle, not malicious. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar-gaI1v_KV.js | AI (source-diff): CLDR locale data file (Arabic) with explicit Unicode license header; minified data bundle. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/bg-c8a3d631.js | AI (source-diff): CLDR locale data file (Unicode license); minified by design, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar_EG-bec371f8.js | AI (source-diff): CLDR locale data file (Unicode license); minified by design, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar-3d86671f.js | AI (source-diff): CLDR locale data file (Unicode license); minified by design, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar_SA-013516b9.js | AI (source-diff): CLDR locale data file (Unicode license); minified by design, not obfuscated malware. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Size increase explained by addition of legitimate thirdparty bundles (AdaptiveCards, CLDR locale data); stable for this package. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ca-432aede8.js | AI (source-diff): CLDR locale data file (Unicode license); minified by design, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ca-D59F9iL9.js | AI (source-diff): CLDR locale data file with explicit Unicode license header; minified by nature. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/adaptive-expressions.js | AI (source-diff): Legitimate minified Microsoft adaptive-expressions library vendored as thirdparty dependency. | ai | |
| source-diff | net-exec-file:src/sap/ui/integration/thirdparty/adaptive-expressions.js | AI (source-diff): False positive on browserify UMD wrapper; no actual network calls or dynamic code execution in malicious sense. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar_EG-CsHsH5NB.js | AI (source-diff): CLDR locale data file with explicit Unicode license header; minified by nature. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar_SA-CVd8CQkH.js | AI (source-diff): CLDR locale data file with explicit Unicode license header; minified by nature. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/ar-BBtO1xV9.js | AI (source-diff): CLDR locale data file with explicit Unicode license header; minified by nature. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/webcomponents/bg-B1LO90TV.js | AI (source-diff): CLDR locale data file with explicit Unicode license header; minified by nature. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase reflects addition of adaptive cards feature with vendored thirdparty libraries, not injected payload. | ai | |
| source-diff | net-exec-file:src/sap/ui/integration/thirdparty/webcomponents/bundle.es5.js | AI (source-diff): XHR calls are from css-vars-ponyfill polyfill fetching CSS; no dropper/loader behavior. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/adaptivecards.js | AI (source-diff): Standard webpack bundle of Microsoft's AdaptiveCards library with MIT license header; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/thirdparty/adaptivecards-templating.js | AI (source-diff): Standard webpack bundle of Microsoft's adaptivecards-templating library; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:src/sap/ui/integration/designtime/cardEditor/util/CommonPatterns.js | AI (source-diff): Long line is a complex email validation regex in an OpenUI5 SAP-licensed file, not obfuscated malware. | ai | |
| phantom-deps | phantom-dep:@openui5/sap.m | AI (phantom-deps): Sibling monorepo package; runtime-loaded via UI5 module system, not static import. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() used solely as a CSP capability probe (eval("") in try/catch); not an arbitrary code execution risk. | ai | |
| phantom-deps | phantom-dep:@openui5/sap.f | AI (phantom-deps): Sibling monorepo package; runtime-loaded via UI5 module system, not static import. | ai | |
| phantom-deps | phantom-dep:@openui5/sap.ui.unified | AI (phantom-deps): Sibling monorepo package; runtime-loaded via UI5 module system, not static import. | ai | |
| phantom-deps | phantom-dep:@openui5/sap.ui.layout | AI (phantom-deps): Sibling monorepo package; runtime-loaded via UI5 module system, not static import. | ai | |
| phantom-deps | phantom-dep:@openui5/sap.ui.core | AI (phantom-deps): Sibling monorepo package; runtime-loaded via UI5 module system, not static import. | ai |
Versions (showing 51 of 65)
| Version | Deps | Published |
|---|---|---|
| 1.150.0 | 5 / 0 | |
| 1.149.1 | 5 / 0 | |
| 1.148.4 | 5 / 0 | |
| 1.148.3 | 5 / 0 | |
| 1.148.2 | 5 / 0 | |
| 1.148.1 | 5 / 0 | |
| 1.148.0 | 5 / 0 | |
| 1.147.1 | 5 / 0 | |
| 1.147.0 | 5 / 0 | |
| 1.146.0 | 5 / 0 | |
| 1.145.3 | 5 / 0 | |
| 1.145.2 | 5 / 0 | |
| 1.145.1 | 5 / 0 | |
| 1.145.0 | 5 / 0 | |
| 1.144.0 | 5 / 0 | |
| 1.143.0 | 5 / 0 | |
| 1.142.10 | 5 / 0 | |
| 1.142.9 | 5 / 0 | |
| 1.142.8 | 5 / 0 | |
| 1.142.7 | 5 / 0 | |
| 1.142.6 | 5 / 0 | |
| 1.142.5 | 5 / 0 | |
| 1.142.4 | 5 / 0 | |
| 1.142.3 | 5 / 0 | |
| 1.139.3 | 5 / 0 | |
| 1.136.18 | 6 / 0 | |
| 1.136.17 | 6 / 0 | |
| 1.136.16 | 6 / 0 | |
| 1.136.15 | 6 / 0 | |
| 1.136.14 | 6 / 0 | |
| 1.136.12 | 6 / 0 | |
| 1.136.11 | 6 / 0 | |
| 1.136.10 | 6 / 0 | |
| 1.136.9 | 6 / 0 | |
| 1.120.47 | 5 / 0 | |
| 1.120.46 | 5 / 0 | |
| 1.120.44 | 5 / 0 | |
| 1.120.43 | 5 / 0 | |
| 1.108.51 | 2 / 0 | |
| 1.108.50 | 2 / 0 | |
| 1.96.47 | 2 / 0 | |
| 1.96.46 | 2 / 0 | |
| 1.96.45 | 2 / 0 | |
| 1.96.44 | 2 / 0 | |
| 1.96.43 | 2 / 0 | |
| 1.84.57 | 2 / 0 | |
| 1.84.56 | 2 / 0 | |
| 1.84.55 | 2 / 0 | |
| 1.84.54 | 2 / 0 | |
| 1.71.80 | 2 / 0 | |
| 1.71.79 | 2 / 0 |
v1.150.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.149.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.148.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.148.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.148.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.146.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.145.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.144.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.143.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.142.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.142.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.142.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.142.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.142.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.139.3
24 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.136.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.136.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.136.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.136.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.136.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.120.47
45 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.96.44
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.96.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.54
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.71.80
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.71.79
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.