@sap-cloud-sdk/generator
SAP Cloud SDK for JavaScript OData client generator
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): SAP org admin rotation (sap-ospo-admin); SLSA provenance confirms CI/CD integrity. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Paired with maintainer-added; consistent with internal SAP org admin change, not a takeover. | ai | |
| dependencies | unvetted-dep:@sap-cloud-sdk/odata-v2 | AI (dependencies): First-party SAP Cloud SDK package published by the same org; expected dependency for OData generator. | ai | |
| dependencies | unvetted-dep:@sap-cloud-sdk/odata-v4 | AI (dependencies): First-party SAP Cloud SDK package published by the same org; expected dependency for OData generator. | ai | |
| dependencies | unvetted-dep:@sap-cloud-sdk/odata-common | AI (dependencies): First-party SAP Cloud SDK package published by the same org; expected dependency. | ai | |
| dependencies | unvetted-dep:@sap-cloud-sdk/generator-common | AI (dependencies): First-party SAP Cloud SDK package published by the same org; expected dependency. | ai | |
| dependencies | unvetted-dep:voca | AI (dependencies): voca is a well-known string manipulation library; stable dependency for this package across many versions. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Referenced in config files; typescript is a declared runtime dep used for compilation, not a phantom risk. | ai | |
| phantom-deps | phantom-dep:@types/fs-extra | AI (phantom-deps): Type definition package loaded by convention; not a security risk. | ai | |
| phantom-deps | phantom-dep:@sap-cloud-sdk/odata-v2 | AI (phantom-deps): Explicitly excluded from depcheck by maintainers; used as indirect/type dependency for OData generation. | ai | |
| phantom-deps | phantom-dep:@sap-cloud-sdk/odata-v4 | AI (phantom-deps): Explicitly excluded from depcheck by maintainers; used as indirect/type dependency for OData generation. | ai | |
| phantom-deps | phantom-dep:winston | AI (phantom-deps): Referenced in config files only, not directly imported; benign for a logging-aware generator tool. | ai | |
| dependencies | unvetted-dep:@sap-cloud-sdk/util | AI (dependencies): First-party SAP Cloud SDK package published by the same org; expected dependency. | ai |
Versions (showing 11 of 11)
| Version | Deps | Published |
|---|---|---|
| 4.7.0 | 12 / 6 | |
| 4.6.0 | 12 / 3 | |
| 4.5.1 | 12 / 3 | |
| 4.5.0 | 12 / 3 | |
| 4.4.0 | 12 / 3 | |
| 4.3.1 | 12 / 3 | |
| 4.3.0 | 12 / 3 | |
| 4.2.0 | 12 / 3 | |
| 4.1.2 | 12 / 3 | |
| 4.1.1 | 12 / 3 | |
| 4.1.0 | 12 / 3 |
v4.7.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.