← Home

@sap-ux/fiori-app-sub-generator

A yeoman (sub) generator that can generate Fiori applications. Not for standalone use.

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@sap-ux/fiori-freestyle-writer AI (dependencies): Same SAP/open-ux-tools monorepo scope; stable dependency. ai
dependencies unvetted-dep:@sap-ux/annotation-converter AI (dependencies): Same SAP/open-ux-tools monorepo scope; stable dependency. ai
dependencies unvetted-dep:@sap-ux/fiori-tools-settings AI (dependencies): Same SAP/open-ux-tools monorepo scope; stable dependency. ai
dependencies unvetted-dep:@sap-ux/fiori-elements-writer AI (dependencies): Same SAP/open-ux-tools monorepo scope; stable dependency. ai
provenance no-provenance AI (provenance): SAP open-ux-tools monorepo does not currently publish Sigstore provenance; stable pattern across all versions. ai
dependencies unvetted-dep:mem-fs-editor AI (dependencies): Well-known yeoman ecosystem dep; stable usage across many versions of this package. ai
dependencies unvetted-dep:@sap-ux/ui5-info AI (dependencies): Same SAP/open-ux-tools monorepo scope; stable dependency. ai
dependencies unvetted-dep:@sap-ux/btp-utils AI (dependencies): Same SAP/open-ux-tools monorepo scope; stable dependency. ai
dependencies unvetted-dep:@sap-ux/edmx-parser AI (dependencies): Same SAP/open-ux-tools monorepo scope; stable dependency. ai
dependencies unvetted-dep:@sap-ux/feature-toggle AI (dependencies): Same SAP/open-ux-tools monorepo scope; stable dependency. ai
dependencies unvetted-dep:@sap-ux/axios-extension AI (dependencies): Same SAP/open-ux-tools monorepo scope; stable dependency. ai
dependencies unvetted-dep:@sap/service-provider-apis AI (dependencies): SAP-published package; stable dependency in this package. ai
phantom-deps phantom-dep:@sap/service-provider-apis AI (phantom-deps): Used via config/type references in SAP monorepo; stable false positive. ai
phantom-deps phantom-dep:@sap-ux/annotation-generator AI (phantom-deps): Same-org sibling dep; phantom detection is a false positive for this monorepo package. ai
phantom-deps phantom-dep:mem-fs AI (phantom-deps): mem-fs is a peer/indirect dep used by mem-fs-editor; phantom detection is a false positive for this package. ai

Versions (showing 51 of 114)

View all versions
Version Deps Published
1.3.10 28 / 20
1.3.9 28 / 20
1.3.8 28 / 20
1.3.7 28 / 20
1.3.6 28 / 20
1.3.5 28 / 20
1.3.4 28 / 20
1.3.2 28 / 20
1.3.1 28 / 20
1.3.0 28 / 20
1.2.0 27 / 20
1.1.12 27 / 20
1.1.11 27 / 20
1.1.9 27 / 20
1.1.8 27 / 20
1.1.7 27 / 20
0.14.1 27 / 19
0.14.0 27 / 19
0.13.33 27 / 19
0.13.29 27 / 19
0.13.27 27 / 19
0.13.11 27 / 19
0.13.10 27 / 19
0.11.98 27 / 19
0.11.97 27 / 19
0.11.96 27 / 19
0.11.95 27 / 19
0.11.94 27 / 19
0.11.93 27 / 19
0.11.92 27 / 19
0.11.91 27 / 19
0.11.90 27 / 19
0.11.89 27 / 19
0.11.88 27 / 19
0.11.87 27 / 19
0.11.86 27 / 19
0.11.85 27 / 19
0.11.84 27 / 19
0.11.83 27 / 19
0.11.82 27 / 19
0.11.81 27 / 19
0.11.80 27 / 19
0.11.79 27 / 19
0.11.78 27 / 19
0.11.77 27 / 19
0.11.75 27 / 19
0.11.73 27 / 19
0.11.72 27 / 19
0.11.71 27 / 19
0.11.70 27 / 19
0.11.69 27 / 19

v1.3.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.7

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: devinea → GitHub Actions (on 2026-07-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (devinea) on 2026-07-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.