← Home

@sap-ux/cf-deploy-config-sub-generator

Generators for configuring Cloud Foundry deployment configuration

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): SAP monorepo migrated to GitHub Actions CI publishing with SLSA attestation; stable pattern for this package going forward. ai
maintainer-change maintainer-added AI (maintainer-change): sap-ospo-admin addition consistent with SAP OSS admin governance; not a hostile takeover signal. ai
dependencies unvetted-dep:@sap-ux/btp-utils AI (dependencies): SAP open-ux-tools sibling package; expected internal dependency. ai
dependencies unvetted-dep:@sap-ux/feature-toggle AI (dependencies): SAP open-ux-tools sibling package; expected internal dependency. ai
dependencies unvetted-dep:@sap-ux/project-access AI (dependencies): SAP open-ux-tools sibling package; expected internal dependency. ai
dependencies unvetted-dep:@sap-ux/inquirer-common AI (dependencies): SAP open-ux-tools sibling package; expected internal dependency. ai
dependencies unvetted-dep:@sap-devx/yeoman-ui-types AI (dependencies): SAP DevX type definitions for Yeoman UI; expected in SAP generator toolchain. ai
dependencies unvetted-dep:hasbin AI (dependencies): Standard utility for checking binary availability; expected in a Yeoman generator context. ai
dependencies unvetted-dep:@sap-ux/cf-deploy-config-writer AI (dependencies): SAP open-ux-tools sibling package; expected internal dependency. ai
dependencies unvetted-dep:@sap-ux/cf-deploy-config-inquirer AI (dependencies): SAP open-ux-tools sibling package; expected internal dependency. ai
dependencies unvetted-dep:@sap-ux/deploy-config-generator-shared AI (dependencies): SAP open-ux-tools sibling package; expected internal dependency. ai
provenance no-provenance AI (provenance): Large SAP monorepo; lack of Sigstore provenance is common and not a risk signal here. ai
dependencies unvetted-dep:@sap-ux/fiori-generator-shared AI (dependencies): SAP open-ux-tools sibling package; expected internal dependency. ai
dependencies unvetted-dep:yeoman-generator AI (dependencies): Core Yeoman framework dependency; expected for this generator package. ai

Versions (showing 51 of 280)

View all versions
Version Deps Published
1.0.33 12 / 14
1.0.31 12 / 14
1.0.30 12 / 14
1.0.29 12 / 14
1.0.28 12 / 14
1.0.27 12 / 14
1.0.26 12 / 14
1.0.25 12 / 14
1.0.24 12 / 14
1.0.23 12 / 14
1.0.22 12 / 14
1.0.21 12 / 14
1.0.20 12 / 14
1.0.19 12 / 14
1.0.18 12 / 14
1.0.17 12 / 14
1.0.16 12 / 14
1.0.15 12 / 14
1.0.14 12 / 14
1.0.13 12 / 14
1.0.12 12 / 14
1.0.11 12 / 14
1.0.10 12 / 14
1.0.9 12 / 14
1.0.8 12 / 14
1.0.7 12 / 14
1.0.6 12 / 14
1.0.5 12 / 14
1.0.3 12 / 14
1.0.2 12 / 14
1.0.1 12 / 14
1.0.0 12 / 14
0.3.7 12 / 13
0.3.6 12 / 13
0.3.4 12 / 13
0.3.3 12 / 13
0.3.2 12 / 13
0.3.1 12 / 13
0.2.181 12 / 13
0.2.180 12 / 13
0.2.179 12 / 13
0.2.178 12 / 13
0.2.177 12 / 13
0.2.176 12 / 13
0.2.175 12 / 13
0.2.174 12 / 13
0.2.173 12 / 13
0.2.172 12 / 13
0.2.171 12 / 13
0.2.170 12 / 13
0.2.169 12 / 13

v1.0.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.