← Home

@sap-ux/fiori-elements-writer

SAP Fiori elements application writer

7
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:mem-fs AI (phantom-deps): Same-org toolchain dependency; phantom-dep heuristic fires on config-file references, not a real risk. ai
phantom-deps phantom-dep:@sap-ux/ui5-config AI (phantom-deps): Same @sap-ux org scope; phantom-dep heuristic is a stable false positive for this package family. ai

Versions (showing 7 of 7)

Version Deps Published
2.8.138 16 / 9
2.8.137 16 / 9
2.8.136 16 / 9
2.8.135 16 / 9
2.8.134 16 / 9
2.8.133 16 / 9
2.8.115 16 / 9

v2.8.138

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.137

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.136

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.135

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.134

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.133

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.8.115

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.