← Home

@sap-ux/fiori-mcp-server

SAP Fiori - Model Context Protocol (MCP) server

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Keywords

SAP Fiori toolsSAP Fiori elementsSAP Fiori freestyleMCPAI

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata bundled-binaries AI (npm-metadata): Keyring native prebuilds + ONNX WASM binaries; expected for this SAP MCP server package. ai
source-diff net-exec-file:dist/ort-wasm-simd-threaded.jsep.mjs AI (source-diff): Standard ONNX Runtime WASM loader; not malicious. ai
provenance publisher-changed AI (provenance): devinea is an established SAP publisher with 1746 approved packages; transition appears to be a legitimate org account change. ai
phantom-deps phantom-dep:apache-arrow AI (phantom-deps): apache-arrow is a peer/transitive dep of @lancedb/lancedb; not directly imported is expected for this package. ai
dependencies unvetted-dep:mem-fs-editor AI (dependencies): mem-fs-editor is a well-established Yeoman file-system utility; stable false positive for this SAP tooling package. ai
phantom-deps phantom-dep:mem-fs AI (phantom-deps): Marked external in esbuild bundle; not directly imported in bundled output by design. ai
phantom-deps phantom-dep:@sap-ux/fiori-docs-embeddings AI (phantom-deps): Marked external in esbuild bundle; same SAP org scope, not directly imported in bundled output by design. ai
phantom-deps phantom-dep:mem-fs-editor AI (phantom-deps): Marked external in esbuild bundle; not directly imported in bundled output by design. ai
phantom-deps phantom-dep:@lancedb/lancedb AI (phantom-deps): Marked external in esbuild bundle; not directly imported in bundled output by design. ai
phantom-deps phantom-dep:@xenova/transformers AI (phantom-deps): Marked external in esbuild bundle; not directly imported in bundled output by design. ai
phantom-deps phantom-dep:@sap-ux/store AI (phantom-deps): Marked external in esbuild bundle; same SAP org scope, not directly imported in bundled output by design. ai

Versions (showing 51 of 122)

View all versions
Version Deps Published
1.9.3 0 / 40
1.9.2 0 / 40
1.9.1 0 / 40
1.9.0 0 / 40
1.8.9 0 / 40
1.8.8 0 / 40
1.8.7 0 / 40
1.8.6 0 / 40
1.8.5 0 / 40
1.8.4 0 / 40
1.8.3 0 / 40
1.8.2 0 / 40
1.8.1 0 / 40
1.8.0 0 / 40
1.7.1 0 / 40
1.7.0 0 / 40
1.6.0 0 / 40
1.5.1 0 / 40
1.5.0 0 / 40
1.4.1 0 / 40
1.4.0 0 / 40
1.3.0 0 / 40
1.2.0 0 / 40
1.1.4 0 / 40
1.1.3 0 / 39
1.0.3 6 / 34
1.0.2 6 / 34
1.0.1 6 / 34
1.0.0 6 / 33
0.7.2 7 / 32
0.7.1 7 / 32
0.7.0 7 / 32
0.6.58 7 / 32
0.6.57 7 / 32
0.6.56 7 / 32
0.6.55 7 / 32
0.6.54 6 / 32
0.6.53 6 / 32
0.6.52 6 / 32
0.6.51 6 / 32
0.6.50 6 / 32
0.6.49 6 / 32
0.6.48 6 / 32
0.6.47 6 / 32
0.6.46 6 / 33
0.6.45 6 / 33
0.6.44 6 / 33
0.6.43 6 / 33
0.6.42 6 / 33
0.6.41 6 / 33
0.6.40 6 / 33

v1.9.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.