← Home

@sap-devx/yeoman-ui-types

27
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

shaharsrima.sirichsap-ospo-admin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SAP org package published via GitHub Actions with SLSA provenance; gitHead absence is a benign CI change. ai
provenance publisher-changed AI (provenance): SAP migrated to GitHub Actions CI publishing with SLSA attestation; stable pattern for this org package. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy explained by SAP org CI migration; SLSA attestation confirms legitimate publish pipeline. ai

Versions (showing 27 of 27)

Version Deps Published
1.25.1 0 / 0
1.25.0 0 / 0
1.24.0 0 / 0
1.23.0 0 / 0
1.22.0 0 / 0
1.21.0 0 / 0
1.20.5 0 / 0
1.20.3 0 / 0
1.20.2 0 / 0
1.20.1 0 / 0
1.20.0 0 / 0
1.19.6 0 / 0
1.19.5 0 / 0
1.19.4 0 / 0
1.19.3 0 / 0
1.19.2 0 / 0
1.19.1 0 / 0
1.19.0 0 / 0
1.18.0 0 / 0
1.17.1 0 / 0
1.17.0 0 / 0
1.16.9 0 / 0
1.16.8 0 / 0
1.16.7 0 / 0
1.16.6 0 / 0
1.16.5 0 / 0
1.16.4 0 / 0

v1.19.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.17.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.