← Home

@sap-ux/fiori-tools-settings

8
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): SAP org migrated publishing to GitHub Actions CI/CD with SLSA attestation; stable pattern for this package going forward. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers (sap-ospo-admin, devinea) align with SAP OSS governance; consistent with org-level CI/CD transition. ai
bogus-package bogus-package AI (bogus-package): SAP monorepo utility; sparse README/keywords are typical for internal tooling packages. ai

Versions (showing 8 of 8)

Version Deps Published
1.0.1 2 / 2
1.0.0 2 / 2
0.3.0 2 / 2
0.2.3 2 / 2
0.2.2 2 / 2
0.2.1 2 / 2
0.2.0 2 / 2
0.1.0 2 / 2

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.