← Home

@sap-ux/project-integrity

Library to check the integrity of projects

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): SAP open-ux-tools migrated to GitHub Actions CI publishing with SLSA attestation; publisher change is expected and verifiable. ai
provenance no-provenance AI (provenance): SAP open-ux-tools monorepo does not publish with Sigstore provenance; stable pattern across all versions. ai

Versions (showing 100 of 114)

Version Deps Published
1.0.12 2 / 1
1.0.11 2 / 1
1.0.10 2 / 1
1.0.9 2 / 1
1.0.8 2 / 1
1.0.7 2 / 1
1.0.6 2 / 1
1.0.5 2 / 1
1.0.4 2 / 1
1.0.2 2 / 1
1.0.1 2 / 1
1.0.0 2 / 1
0.3.2 2 / 0
0.3.1 2 / 0
0.3.0 2 / 0
0.2.73 2 / 0
0.2.72 2 / 0
0.2.71 2 / 0
0.2.70 2 / 0
0.2.69 2 / 0
0.2.68 2 / 0
0.2.67 2 / 0
0.2.66 2 / 0
0.2.65 2 / 0
0.2.64 2 / 0
0.2.63 2 / 0
0.2.62 2 / 0
0.2.61 2 / 0
0.2.60 2 / 0
0.2.59 2 / 0
0.2.58 2 / 0
0.2.57 2 / 0
0.2.56 2 / 0
0.2.54 2 / 0
0.2.53 2 / 0
0.2.52 2 / 0
0.2.51 2 / 0
0.2.50 2 / 0
0.2.49 2 / 0
0.2.48 2 / 0
0.2.47 2 / 0
0.2.46 2 / 0
0.2.45 2 / 0
0.2.44 2 / 0
0.2.43 2 / 0
0.2.42 2 / 0
0.2.41 2 / 0
0.2.40 2 / 0
0.2.39 2 / 0
0.2.38 2 / 0
0.2.37 2 / 0
0.2.36 2 / 0
0.2.35 2 / 0
0.2.34 2 / 0
0.2.33 2 / 0
0.2.32 2 / 0
0.2.30 2 / 0
0.2.29 2 / 0
0.2.28 2 / 0
0.2.27 2 / 0
0.2.26 2 / 0
0.2.25 2 / 0
0.2.24 2 / 0
0.2.23 2 / 0
0.2.22 2 / 0
0.2.21 2 / 0
0.2.20 2 / 0
0.2.19 2 / 0
0.2.18 2 / 0
0.2.17 2 / 0
0.2.16 2 / 0
0.2.15 2 / 0
0.2.14 2 / 0
0.2.13 2 / 0
0.2.12 2 / 0
0.2.11 2 / 0
0.2.10 2 / 0
0.2.9 2 / 0
0.2.8 2 / 0
0.2.7 2 / 0
0.2.6 2 / 0
0.2.5 2 / 0
0.2.4 2 / 0
0.2.3 2 / 0
0.2.2 2 / 0
0.2.1 2 / 0
0.2.0 2 / 0
0.1.21 2 / 0
0.1.20 2 / 0
0.1.19 2 / 0
0.1.18 2 / 0
0.1.17 2 / 0
0.1.16 2 / 0
0.1.15 2 / 0
0.1.14 2 / 0
0.1.13 2 / 0
0.1.11 2 / 0
0.1.10 2 / 0
0.1.9 2 / 0
0.1.8 2 / 0
Showing 100 of 114 Next page →

v1.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.18

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.