@sap-cloud-sdk/generator
SAP Cloud SDK for JavaScript OData client generator
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): SAP org admin rotation (sap-ospo-admin); SLSA provenance confirms CI/CD integrity. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Paired with maintainer-added; consistent with internal SAP org admin change, not a takeover. | ai | |
| dependencies | unvetted-dep:@sap-cloud-sdk/odata-v2 | AI (dependencies): First-party SAP Cloud SDK package published by the same org; expected dependency for OData generator. | ai | |
| dependencies | unvetted-dep:@sap-cloud-sdk/odata-v4 | AI (dependencies): First-party SAP Cloud SDK package published by the same org; expected dependency for OData generator. | ai | |
| dependencies | unvetted-dep:@sap-cloud-sdk/odata-common | AI (dependencies): First-party SAP Cloud SDK package published by the same org; expected dependency. | ai | |
| dependencies | unvetted-dep:@sap-cloud-sdk/generator-common | AI (dependencies): First-party SAP Cloud SDK package published by the same org; expected dependency. | ai | |
| dependencies | unvetted-dep:voca | AI (dependencies): voca is a well-known string manipulation library; stable dependency for this package across many versions. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Referenced in config files; typescript is a declared runtime dep used for compilation, not a phantom risk. | ai | |
| phantom-deps | phantom-dep:@types/fs-extra | AI (phantom-deps): Type definition package loaded by convention; not a security risk. | ai | |
| phantom-deps | phantom-dep:@sap-cloud-sdk/odata-v2 | AI (phantom-deps): Explicitly excluded from depcheck by maintainers; used as indirect/type dependency for OData generation. | ai | |
| phantom-deps | phantom-dep:@sap-cloud-sdk/odata-v4 | AI (phantom-deps): Explicitly excluded from depcheck by maintainers; used as indirect/type dependency for OData generation. | ai | |
| phantom-deps | phantom-dep:winston | AI (phantom-deps): Referenced in config files only, not directly imported; benign for a logging-aware generator tool. | ai | |
| dependencies | unvetted-dep:@sap-cloud-sdk/util | AI (dependencies): First-party SAP Cloud SDK package published by the same org; expected dependency. | ai |
Versions (showing 14 of 14)
| Version | Deps | Published |
|---|---|---|
| 4.7.0 | 12 / 6 | |
| 4.6.0 | 12 / 3 | |
| 4.5.1 | 12 / 3 | |
| 4.5.0 | 12 / 3 | |
| 4.4.0 | 12 / 3 | |
| 4.3.1 | 12 / 3 | |
| 4.3.0 | 12 / 3 | |
| 4.2.0 | 12 / 3 | |
| 4.1.2 | 12 / 3 | |
| 4.1.1 | 12 / 3 | |
| 4.1.0 | 12 / 3 | |
| 4.0.2 | 12 / 3 | |
| 4.0.1 | 12 / 3 | |
| 4.0.0 | 12 / 3 |
v4.0.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marikaner) than the most recent previously approved version (deekshas8) on 2025-03-18, but marikaner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marikaner) than the most recent previously approved version (deekshas8) on 2025-03-05, but marikaner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.