← Home

@sap-ux/launch-config

SAP Fiori tools launch config administration

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): SAP org migrated to GitHub Actions CI publishing with SLSA attestation; stable pattern for this package going forward. ai
dependencies unvetted-dep:mem-fs-editor AI (dependencies): mem-fs-editor is a well-known Yeoman/generator utility; stable false positive for this SAP UX tooling package. ai
provenance no-provenance AI (provenance): SAP open-ux-tools monorepo; no provenance is consistent across all versions of this package family. ai
dependencies unvetted-dep:@sap-ux/ui5-info AI (dependencies): Same SAP UX org scope; expected sibling dependency in this monorepo. ai
dependencies unvetted-dep:@sap-ux/ui5-config AI (dependencies): Same SAP UX org scope; expected sibling dependency in this monorepo. ai
phantom-deps phantom-dep:@sap-ux/ui5-info AI (phantom-deps): Same-org sibling dep; declared but may be re-exported or used indirectly — stable false positive for this package. ai

Versions (showing 100 of 140)

Version Deps Published
1.0.16 8 / 5
1.0.15 8 / 5
1.0.14 8 / 5
1.0.13 8 / 5
1.0.12 8 / 5
1.0.11 8 / 5
1.0.10 8 / 5
1.0.9 8 / 5
1.0.8 8 / 5
1.0.7 8 / 5
1.0.6 8 / 5
1.0.5 8 / 5
1.0.4 8 / 5
1.0.2 8 / 5
1.0.1 8 / 5
1.0.0 8 / 5
0.11.2 8 / 4
0.11.1 8 / 4
0.11.0 8 / 4
0.10.91 8 / 4
0.10.90 8 / 4
0.10.89 8 / 4
0.10.88 8 / 4
0.10.87 8 / 4
0.10.86 8 / 4
0.10.83 8 / 4
0.10.82 8 / 4
0.10.81 8 / 4
0.10.79 8 / 4
0.10.71 8 / 4
0.10.69 8 / 4
0.10.67 8 / 4
0.10.64 8 / 4
0.10.63 8 / 4
0.10.59 8 / 4
0.10.58 8 / 4
0.10.56 8 / 4
0.10.52 8 / 4
0.10.51 8 / 4
0.10.48 8 / 4
0.10.47 8 / 4
0.10.46 8 / 4
0.10.44 8 / 4
0.10.43 8 / 4
0.10.39 8 / 4
0.10.38 8 / 4
0.10.33 8 / 4
0.10.32 8 / 4
0.10.30 8 / 4
0.10.29 8 / 4
0.10.24 8 / 4
0.10.23 8 / 4
0.10.22 8 / 4
0.10.21 8 / 4
0.10.19 8 / 4
0.10.17 8 / 4
0.10.16 8 / 4
0.10.15 8 / 4
0.10.14 8 / 4
0.10.10 8 / 4
0.10.8 8 / 4
0.10.5 8 / 4
0.10.4 8 / 4
0.10.3 8 / 4
0.10.0 8 / 4
0.9.6 8 / 4
0.9.5 8 / 4
0.9.4 8 / 4
0.9.3 8 / 4
0.9.2 8 / 4
0.9.1 8 / 4
0.9.0 8 / 4
0.8.1 8 / 4
0.8.0 8 / 4
0.7.37 8 / 4
0.7.36 8 / 4
0.7.35 8 / 4
0.7.34 8 / 4
0.7.33 8 / 4
0.7.32 8 / 4
0.7.31 8 / 4
0.7.30 8 / 4
0.7.29 8 / 4
0.7.27 8 / 4
0.7.26 8 / 4
0.7.25 8 / 4
0.7.24 8 / 4
0.7.23 8 / 4
0.7.22 8 / 4
0.7.21 8 / 4
0.7.20 8 / 4
0.7.19 8 / 4
0.7.18 8 / 4
0.7.17 8 / 4
0.7.16 8 / 4
0.7.15 8 / 4
0.7.14 8 / 4
0.7.13 8 / 4
0.7.12 8 / 4
0.7.11 8 / 4
Showing 100 of 140 Next page →

v1.0.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.37

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.36

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.35

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.34

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.33

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.32

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.31

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.30

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.29

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.27

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.26

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.25

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.24

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.23

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.22

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.21

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.18

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.