@sap-ux/environment-check
SAP Fiori environment check
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:findit2 | AI (phantom-deps): Likely dynamic/indirect usage in a mature SAP tooling package; no malicious indicator. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from human publisher to GitHub Actions CI/CD is confirmed by SLSA provenance attestation; expected for SAP open-ux-tools repo. | ai | |
| dependencies | unvetted-dep:@sap/bas-sdk | AI (dependencies): First-party SAP SDK; expected dependency for SAP BAS environment checks in this package. | ai | |
| provenance | no-provenance | AI (provenance): SAP UX monorepo packages consistently lack Sigstore provenance; stable false positive for this package family. | ai | |
| phantom-deps | phantom-dep:@sap-ux/ui5-config | AI (phantom-deps): @sap-ux/ui5-config is a declared dep in the same SAP monorepo; phantom-dep heuristic is a stable false positive here. | ai |
Versions (showing 51 of 435)
| Version | Deps | Published |
|---|---|---|
| 1.0.17 | 15 / 5 | |
| 1.0.16 | 15 / 5 | |
| 1.0.15 | 15 / 5 | |
| 1.0.14 | 15 / 5 | |
| 1.0.13 | 15 / 5 | |
| 1.0.12 | 15 / 5 | |
| 1.0.11 | 15 / 5 | |
| 1.0.10 | 15 / 5 | |
| 1.0.9 | 15 / 5 | |
| 1.0.8 | 15 / 5 | |
| 1.0.7 | 15 / 5 | |
| 1.0.6 | 15 / 5 | |
| 1.0.5 | 15 / 5 | |
| 1.0.4 | 15 / 5 | |
| 1.0.2 | 15 / 5 | |
| 1.0.1 | 15 / 5 | |
| 1.0.0 | 15 / 5 | |
| 0.19.4 | 15 / 4 | |
| 0.19.3 | 15 / 4 | |
| 0.19.2 | 15 / 4 | |
| 0.19.1 | 15 / 4 | |
| 0.19.0 | 15 / 4 | |
| 0.18.126 | 15 / 4 | |
| 0.18.125 | 15 / 4 | |
| 0.18.124 | 15 / 4 | |
| 0.18.123 | 15 / 4 | |
| 0.18.122 | 15 / 4 | |
| 0.18.121 | 15 / 4 | |
| 0.18.120 | 15 / 4 | |
| 0.18.119 | 15 / 4 | |
| 0.18.118 | 15 / 4 | |
| 0.18.117 | 15 / 4 | |
| 0.18.116 | 15 / 4 | |
| 0.18.115 | 15 / 4 | |
| 0.18.114 | 15 / 4 | |
| 0.18.113 | 15 / 4 | |
| 0.18.112 | 15 / 4 | |
| 0.18.111 | 15 / 4 | |
| 0.18.110 | 15 / 4 | |
| 0.18.109 | 15 / 4 | |
| 0.18.108 | 15 / 4 | |
| 0.18.107 | 15 / 4 | |
| 0.18.106 | 15 / 4 | |
| 0.18.105 | 15 / 4 | |
| 0.18.104 | 15 / 4 | |
| 0.18.103 | 15 / 4 | |
| 0.18.102 | 15 / 4 | |
| 0.18.101 | 15 / 4 | |
| 0.18.100 | 15 / 4 | |
| 0.18.99 | 15 / 4 | |
| 0.18.98 | 15 / 4 |
v1.0.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.