← Home

@sap-ux/axios-extension

100
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): SAP open-ux-tools migrated to GitHub Actions CI publishing with SLSA attestation; this is the expected new publisher for this package. ai
maintainer-change maintainer-added AI (maintainer-change): sap-ospo-admin is SAP's org-level admin account; addition is consistent with SAP's CI/CD transition, not a takeover. ai
phantom-deps phantom-dep:@sap-ux/feature-toggle AI (phantom-deps): Declared runtime dep in same SAP org scope; phantom-dep heuristic is unreliable here. ai

Versions (showing 100 of 119)

Version Deps Published
2.0.8 14 / 7
2.0.7 14 / 7
2.0.6 14 / 7
2.0.5 14 / 7
2.0.4 14 / 7
2.0.3 14 / 7
2.0.2 14 / 7
2.0.1 14 / 7
2.0.0 14 / 7
1.26.1 14 / 6
1.26.0 14 / 6
1.25.35 14 / 6
1.25.34 14 / 6
1.25.33 14 / 6
1.25.32 14 / 6
1.25.31 14 / 6
1.25.30 14 / 6
1.25.29 14 / 6
1.25.28 14 / 6
1.25.27 14 / 6
1.25.26 14 / 6
1.25.25 14 / 6
1.25.24 14 / 6
1.25.23 14 / 6
1.25.22 14 / 6
1.25.21 14 / 6
1.25.20 14 / 6
1.25.19 14 / 6
1.25.18 14 / 6
1.25.17 14 / 6
1.25.16 14 / 6
1.25.15 14 / 6
1.25.14 14 / 6
1.25.13 14 / 6
1.25.11 14 / 6
1.25.10 14 / 6
1.25.9 14 / 6
1.25.8 14 / 6
1.25.7 14 / 6
1.25.6 14 / 6
1.25.5 14 / 6
1.25.4 14 / 6
1.25.3 14 / 6
1.25.2 14 / 6
1.25.1 14 / 6
1.25.0 14 / 6
1.24.6 14 / 6
1.24.5 14 / 6
1.24.4 14 / 6
1.24.3 14 / 6
1.24.2 14 / 5
1.24.1 14 / 5
1.24.0 14 / 5
1.23.1 14 / 5
1.23.0 14 / 5
1.22.10 14 / 5
1.22.9 14 / 5
1.22.8 14 / 5
1.22.7 14 / 5
1.22.6 14 / 5
1.22.5 14 / 5
1.22.4 14 / 5
1.22.3 14 / 5
1.22.2 14 / 5
1.22.1 14 / 5
1.22.0 14 / 5
1.21.4 14 / 5
1.21.3 14 / 5
1.21.2 14 / 5
1.21.1 14 / 5
1.21.0 14 / 5
1.20.3 14 / 5
1.20.2 14 / 5
1.20.1 14 / 5
1.20.0 14 / 5
1.19.3 14 / 5
1.19.2 14 / 5
1.19.1 14 / 5
1.19.0 14 / 5
1.18.6 14 / 5
1.18.5 14 / 5
1.18.4 14 / 5
1.18.3 14 / 5
1.18.2 14 / 5
1.18.1 14 / 5
1.18.0 14 / 5
1.17.8 14 / 5
1.17.7 14 / 5
1.17.6 14 / 5
1.17.4 14 / 5
1.17.3 14 / 5
1.17.2 14 / 5
1.17.1 14 / 5
1.17.0 14 / 5
1.16.7 10 / 4
1.16.6 10 / 4
1.16.5 10 / 4
1.16.4 10 / 4
1.16.3 10 / 4
1.16.2 10 / 4
Showing 100 of 119 Next page →

v2.0.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.19.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.19.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.19.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.16.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.16.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.16.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.16.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.16.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.16.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.