← Home

@sap-ux/fiori-annotation-api

Library that provides API for reading and writing annotations in SAP Fiori elements projects.

100
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): SAP org migrated to GitHub Actions CI/CD publishing; SLSA provenance attestation confirms legitimate automated pipeline. ai
provenance no-provenance AI (provenance): SAP UX monorepo packages consistently lack Sigstore provenance; stable false positive for this package family. ai
dependencies unvetted-dep:@xml-tools/ast AI (dependencies): Standard XML tooling dependency; expected for annotation parsing. ai
dependencies unvetted-dep:@sap-ux/odata-entity-model AI (dependencies): SAP-scoped sibling package; stable dependency in this monorepo. ai
dependencies unvetted-dep:@sap-ux/odata-vocabularies AI (dependencies): SAP-scoped sibling package; stable dependency in this monorepo. ai
dependencies unvetted-dep:@sap-ux/vocabularies-types AI (dependencies): SAP-scoped sibling package; stable dependency in this monorepo. ai
dependencies unvetted-dep:@sap/ux-cds-compiler-facade AI (dependencies): SAP-scoped CDS compiler facade; expected dependency for this annotation API. ai
dependencies unvetted-dep:@sap-ux/cds-annotation-parser AI (dependencies): SAP-scoped sibling package; stable dependency in this monorepo. ai
dependencies unvetted-dep:@sap-ux/odata-annotation-core AI (dependencies): SAP-scoped sibling package; stable dependency in this monorepo. ai
dependencies unvetted-dep:@sap-ux/odata-annotation-core-types AI (dependencies): SAP-scoped sibling package; stable dependency in this monorepo. ai
dependencies unvetted-dep:@sap-ux/cds-odata-annotation-converter AI (dependencies): SAP-scoped sibling package; stable dependency in this monorepo. ai
dependencies unvetted-dep:@sap-ux/xml-odata-annotation-converter AI (dependencies): SAP-scoped sibling package; stable dependency in this monorepo. ai
dependencies unvetted-dep:@sap-ux/annotation-converter AI (dependencies): SAP-scoped sibling package; stable dependency in this monorepo. ai
dependencies unvetted-dep:mem-fs-editor AI (dependencies): Well-known mem-fs-editor package; stable dependency for this SAP tooling package. ai
phantom-deps phantom-dep:@sap-ux/annotation-converter AI (phantom-deps): Same-org SAP package; declared as dep and used transitively. Stable false positive for this monorepo package. ai

Versions (showing 100 of 177)

Version Deps Published
1.0.20 17 / 5
1.0.19 17 / 5
1.0.18 17 / 5
1.0.17 17 / 5
1.0.16 17 / 5
1.0.15 17 / 5
1.0.14 17 / 5
1.0.13 17 / 5
1.0.12 17 / 5
1.0.11 17 / 5
1.0.10 17 / 5
1.0.9 17 / 5
1.0.8 17 / 5
1.0.7 17 / 5
1.0.6 17 / 5
1.0.5 17 / 5
1.0.4 17 / 5
1.0.2 17 / 5
1.0.1 17 / 5
1.0.0 17 / 5
0.11.1 17 / 4
0.11.0 17 / 4
0.10.1 17 / 4
0.10.0 17 / 4
0.9.49 17 / 4
0.9.48 17 / 4
0.9.47 17 / 4
0.9.46 17 / 4
0.9.45 17 / 4
0.9.43 17 / 4
0.9.39 17 / 4
0.9.38 17 / 4
0.9.35 17 / 4
0.9.34 17 / 4
0.9.31 17 / 4
0.9.30 17 / 4
0.9.29 17 / 4
0.9.27 17 / 4
0.9.26 17 / 4
0.9.23 17 / 4
0.9.22 17 / 4
0.9.18 17 / 4
0.9.16 17 / 4
0.9.15 17 / 4
0.9.13 17 / 4
0.9.11 17 / 4
0.9.9 17 / 4
0.9.7 17 / 4
0.9.5 17 / 4
0.9.4 17 / 4
0.9.1 17 / 4
0.8.6 17 / 4
0.8.5 17 / 4
0.8.2 17 / 4
0.8.1 17 / 4
0.7.23 17 / 4
0.7.22 17 / 4
0.7.18 17 / 4
0.7.17 17 / 4
0.7.16 17 / 4
0.7.14 17 / 4
0.7.13 17 / 4
0.7.10 17 / 4
0.7.9 17 / 4
0.7.8 17 / 4
0.7.7 17 / 4
0.7.4 17 / 4
0.7.2 17 / 4
0.7.1 17 / 4
0.6.23 17 / 4
0.6.21 17 / 4
0.6.19 17 / 4
0.6.18 17 / 4
0.6.15 17 / 4
0.6.12 17 / 4
0.6.11 17 / 4
0.6.10 17 / 4
0.6.9 17 / 4
0.6.8 17 / 4
0.6.7 17 / 4
0.6.3 17 / 4
0.6.2 17 / 4
0.6.0 17 / 4
0.5.4 17 / 4
0.5.2 17 / 4
0.5.0 17 / 4
0.4.27 17 / 4
0.4.26 17 / 4
0.4.25 17 / 4
0.4.24 17 / 4
0.4.22 17 / 4
0.4.21 17 / 4
0.4.20 17 / 4
0.4.19 17 / 4
0.4.18 17 / 4
0.4.17 17 / 4
0.4.16 17 / 4
0.4.15 17 / 4
0.4.14 17 / 4
0.4.13 17 / 4
Showing 100 of 177 Next page →

v1.0.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.27

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.26

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.25

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.24

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.22

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.21

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.18

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.