← Home

@sap-ux/repo-app-import-sub-generator

Generator to download LROP Fiori applications deployed from an ABAP repository.

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD with SLSA attestation; provenance direction is IMPROVED, not a risk signal. ai
publish-pattern new-deps-added AI (publish-pattern): @sap-ux/fiori-freestyle-writer is a same-org SAP UX package, consistent with this generator's function. ai
dependencies unvetted-dep:@sap-ux/feature-toggle AI (dependencies): SAP monorepo sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@sap-devx/yeoman-ui-types AI (dependencies): SAP DevX companion dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@sap-ux/fiori-tools-settings AI (dependencies): SAP monorepo sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@sap-ux/fiori-elements-writer AI (dependencies): SAP monorepo sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@sap-ux/guided-answers-helper AI (dependencies): SAP monorepo sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@sap-ux/ui5-info AI (dependencies): SAP monorepo sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@sap-ux/btp-utils AI (dependencies): SAP monorepo sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@sap-ux/system-access AI (dependencies): SAP monorepo sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@sap-ux/axios-extension AI (dependencies): SAP monorepo sibling dep; stable pattern across all versions of this package. ai
phantom-deps phantom-dep:inquirer AI (phantom-deps): inquirer is a declared runtime dep; phantom-dep false positive for this package. ai
phantom-deps phantom-dep:@sap-ux/store AI (phantom-deps): Same-org monorepo sibling; phantom-dep heuristic is a stable false positive for this package. ai
phantom-deps phantom-dep:@sap-ux/logger AI (phantom-deps): Same-org monorepo sibling; phantom-dep heuristic is a stable false positive for this package. ai
phantom-deps phantom-dep:@sap-ux/system-access AI (phantom-deps): Same-org monorepo sibling; phantom-dep heuristic is a stable false positive for this package. ai

Versions (showing 51 of 435)

View all versions
Version Deps Published
1.2.13 23 / 25
1.2.12 23 / 25
1.2.11 23 / 25
1.2.10 23 / 25
1.2.9 23 / 25
1.2.8 23 / 25
1.2.7 23 / 25
1.2.6 23 / 25
1.2.4 23 / 25
1.2.3 23 / 25
1.2.1 23 / 25
1.2.0 23 / 25
1.1.44 23 / 25
1.1.43 23 / 25
1.1.42 23 / 25
1.1.41 23 / 25
1.1.40 24 / 25
1.1.39 24 / 25
1.1.38 24 / 25
1.1.37 24 / 25
1.1.36 24 / 25
1.1.35 24 / 25
1.1.34 24 / 25
1.1.33 24 / 25
1.1.32 24 / 25
1.1.31 23 / 25
1.1.30 23 / 25
1.1.29 23 / 25
1.1.28 23 / 25
1.1.27 23 / 25
1.1.26 23 / 25
1.1.25 23 / 25
1.1.24 23 / 25
1.1.23 23 / 25
1.1.22 23 / 25
1.1.21 22 / 25
1.1.20 22 / 25
1.1.19 22 / 25
1.1.18 22 / 25
1.1.17 22 / 25
1.1.16 22 / 25
1.1.15 22 / 25
1.1.14 22 / 25
1.1.13 22 / 25
1.1.12 22 / 25
1.1.11 22 / 25
1.1.9 22 / 25
1.1.8 22 / 25
1.1.7 22 / 25
1.1.6 22 / 25
1.1.4 22 / 25

v1.2.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.28

2 findings
HIGH Publisher changed: devinea → GitHub Actions (on 2026-07-03) provenance

This version was published by a different npm account than previous versions on 2026-07-03. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.27

2 findings
HIGH Publisher changed: devinea → GitHub Actions (on 2026-07-01) provenance

This version was published by a different npm account than previous versions on 2026-07-01. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.26

2 findings
HIGH Publisher changed: devinea → GitHub Actions (on 2026-07-01) provenance

This version was published by a different npm account than previous versions on 2026-07-01. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.25

2 findings
HIGH Publisher changed: devinea → GitHub Actions (on 2026-06-30) provenance

This version was published by a different npm account than previous versions on 2026-06-30. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.24

2 findings
HIGH Publisher changed: devinea → GitHub Actions (on 2026-06-30) provenance

This version was published by a different npm account than previous versions on 2026-06-30. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.23

2 findings
HIGH Publisher changed: devinea → GitHub Actions (on 2026-06-29) provenance

This version was published by a different npm account than previous versions on 2026-06-29. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.