← Home

@sap-ux/system-access

100
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): SAP open-ux-tools migrated to GitHub Actions CI publishing; SLSA attestation confirms official repo origin. Stable for this package. ai
provenance no-provenance AI (provenance): SAP open-ux-tools monorepo consistently publishes without Sigstore provenance; stable pattern across all versions. ai

Versions (showing 100 of 149)

Version Deps Published
1.0.8 5 / 5
1.0.7 5 / 5
1.0.6 5 / 5
1.0.5 5 / 5
1.0.4 5 / 5
1.0.3 5 / 5
1.0.2 5 / 5
1.0.1 5 / 5
1.0.0 5 / 5
0.8.2 5 / 4
0.8.1 5 / 4
0.8.0 5 / 4
0.7.12 5 / 4
0.7.11 5 / 4
0.7.10 5 / 4
0.7.9 5 / 4
0.7.8 5 / 4
0.7.7 5 / 4
0.7.6 5 / 4
0.7.5 5 / 4
0.7.4 5 / 4
0.7.3 5 / 4
0.7.2 5 / 4
0.7.1 5 / 4
0.7.0 5 / 4
0.6.66 5 / 4
0.6.65 5 / 4
0.6.64 5 / 4
0.6.63 5 / 4
0.6.62 5 / 4
0.6.61 5 / 4
0.6.60 5 / 4
0.6.59 5 / 4
0.6.58 5 / 4
0.6.57 5 / 4
0.6.56 5 / 4
0.6.55 5 / 4
0.6.54 5 / 4
0.6.53 5 / 4
0.6.51 5 / 4
0.6.50 5 / 4
0.6.49 5 / 4
0.6.48 5 / 4
0.6.47 5 / 4
0.6.46 5 / 4
0.6.45 5 / 4
0.6.44 5 / 4
0.6.43 5 / 4
0.6.42 5 / 4
0.6.41 5 / 4
0.6.40 5 / 4
0.6.39 5 / 4
0.6.38 5 / 4
0.6.37 5 / 4
0.6.36 5 / 4
0.6.35 5 / 4
0.6.34 5 / 4
0.6.33 5 / 4
0.6.32 5 / 4
0.6.31 5 / 4
0.6.30 5 / 4
0.6.29 5 / 4
0.6.28 5 / 4
0.6.27 5 / 4
0.6.26 5 / 4
0.6.25 5 / 4
0.6.24 5 / 4
0.6.23 5 / 4
0.6.22 5 / 4
0.6.21 5 / 4
0.6.20 5 / 4
0.6.19 5 / 4
0.6.18 5 / 4
0.6.17 5 / 4
0.6.16 5 / 4
0.6.15 5 / 4
0.6.14 5 / 4
0.6.13 5 / 4
0.6.12 5 / 4
0.6.11 5 / 4
0.6.10 5 / 4
0.6.9 5 / 4
0.6.8 5 / 4
0.6.7 5 / 4
0.6.6 5 / 4
0.6.5 5 / 4
0.6.4 5 / 4
0.6.3 5 / 4
0.6.2 5 / 4
0.6.1 5 / 4
0.6.0 5 / 4
0.5.39 5 / 4
0.5.38 5 / 4
0.5.37 5 / 4
0.5.36 5 / 4
0.5.35 5 / 4
0.5.34 5 / 4
0.5.33 5 / 4
0.5.32 5 / 4
0.5.31 5 / 4
Showing 100 of 149 Next page →

v1.0.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.37

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.36

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.35

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.34

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.33

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.32

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.31

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.