← Home

@sap-ux/odata-service-writer

Writer module allowing to add an OData service to a UI5 project.

51
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): SAP org migrated publishing to GitHub Actions CI/CD with SLSA attestation; transition is legitimate and verifiable. ai
dependencies unvetted-dep:mem-fs-editor AI (dependencies): mem-fs-editor is a standard Yeoman/SAP tooling dependency; stable false positive for this package. ai
provenance no-provenance AI (provenance): SAP open-ux-tools monorepo consistently publishes without Sigstore provenance; stable pattern across all versions. ai
phantom-deps phantom-dep:ejs AI (phantom-deps): ejs is a declared runtime dep used via EJS templates; phantom-dep heuristic misfires on template-based usage. ai

Versions (showing 51 of 231)

View all versions
Version Deps Published
1.0.15 12 / 10
1.0.14 12 / 10
1.0.13 12 / 10
1.0.12 12 / 10
1.0.11 12 / 10
1.0.10 12 / 10
1.0.9 12 / 10
1.0.8 12 / 10
1.0.7 12 / 10
1.0.6 12 / 10
1.0.5 12 / 10
1.0.4 12 / 10
1.0.2 12 / 9
1.0.1 12 / 9
1.0.0 12 / 9
0.32.2 12 / 9
0.32.1 12 / 9
0.32.0 12 / 9
0.31.13 12 / 9
0.31.12 12 / 9
0.31.11 12 / 9
0.31.10 12 / 9
0.31.9 12 / 9
0.31.8 12 / 9
0.31.7 12 / 9
0.31.6 12 / 9
0.31.5 12 / 9
0.31.4 12 / 9
0.31.3 12 / 9
0.31.2 12 / 9
0.31.1 12 / 9
0.31.0 12 / 9
0.30.1 12 / 9
0.30.0 12 / 9
0.29.34 12 / 9
0.29.33 12 / 9
0.29.32 12 / 9
0.29.31 12 / 9
0.29.30 12 / 9
0.29.29 12 / 9
0.29.28 12 / 9
0.29.27 12 / 9
0.29.26 12 / 9
0.29.24 12 / 9
0.29.22 12 / 9
0.29.21 12 / 9
0.29.20 12 / 9
0.29.19 12 / 9
0.29.18 12 / 9
0.29.17 12 / 9
0.29.16 12 / 9

v1.0.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.31.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.31.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.30.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.34

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.33

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.32

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.31

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.30

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.29

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.28

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.24

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.21

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.