@sap-ux/odata-service-writer
Writer module allowing to add an OData service to a UI5 project.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): SAP org migrated publishing to GitHub Actions CI/CD with SLSA attestation; transition is legitimate and verifiable. | ai | |
| dependencies | unvetted-dep:mem-fs-editor | AI (dependencies): mem-fs-editor is a standard Yeoman/SAP tooling dependency; stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): SAP open-ux-tools monorepo consistently publishes without Sigstore provenance; stable pattern across all versions. | ai | |
| phantom-deps | phantom-dep:ejs | AI (phantom-deps): ejs is a declared runtime dep used via EJS templates; phantom-dep heuristic misfires on template-based usage. | ai |
Versions (showing 51 of 231)
| Version | Deps | Published |
|---|---|---|
| 1.0.15 | 12 / 10 | |
| 1.0.14 | 12 / 10 | |
| 1.0.13 | 12 / 10 | |
| 1.0.12 | 12 / 10 | |
| 1.0.11 | 12 / 10 | |
| 1.0.10 | 12 / 10 | |
| 1.0.9 | 12 / 10 | |
| 1.0.8 | 12 / 10 | |
| 1.0.7 | 12 / 10 | |
| 1.0.6 | 12 / 10 | |
| 1.0.5 | 12 / 10 | |
| 1.0.4 | 12 / 10 | |
| 1.0.2 | 12 / 9 | |
| 1.0.1 | 12 / 9 | |
| 1.0.0 | 12 / 9 | |
| 0.32.2 | 12 / 9 | |
| 0.32.1 | 12 / 9 | |
| 0.32.0 | 12 / 9 | |
| 0.31.13 | 12 / 9 | |
| 0.31.12 | 12 / 9 | |
| 0.31.11 | 12 / 9 | |
| 0.31.10 | 12 / 9 | |
| 0.31.9 | 12 / 9 | |
| 0.31.8 | 12 / 9 | |
| 0.31.7 | 12 / 9 | |
| 0.31.6 | 12 / 9 | |
| 0.31.5 | 12 / 9 | |
| 0.31.4 | 12 / 9 | |
| 0.31.3 | 12 / 9 | |
| 0.31.2 | 12 / 9 | |
| 0.31.1 | 12 / 9 | |
| 0.31.0 | 12 / 9 | |
| 0.30.1 | 12 / 9 | |
| 0.30.0 | 12 / 9 | |
| 0.29.34 | 12 / 9 | |
| 0.29.33 | 12 / 9 | |
| 0.29.32 | 12 / 9 | |
| 0.29.31 | 12 / 9 | |
| 0.29.30 | 12 / 9 | |
| 0.29.29 | 12 / 9 | |
| 0.29.28 | 12 / 9 | |
| 0.29.27 | 12 / 9 | |
| 0.29.26 | 12 / 9 | |
| 0.29.24 | 12 / 9 | |
| 0.29.22 | 12 / 9 | |
| 0.29.21 | 12 / 9 | |
| 0.29.20 | 12 / 9 | |
| 0.29.19 | 12 / 9 | |
| 0.29.18 | 12 / 9 | |
| 0.29.17 | 12 / 9 | |
| 0.29.16 | 12 / 9 |
v1.0.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.31.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.