← Home

@sap-ux/ui-service-inquirer

Generator for creating UI Service

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): SAP open-ux-tools monorepo does not publish with Sigstore provenance; stable pattern across all versions. ai
dependencies unvetted-dep:@sap-ux/logger AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:yeoman-generator AI (dependencies): Well-known Yeoman scaffolding library; not a risk. ai
dependencies unvetted-dep:@sap-ux/btp-utils AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:@sap-ux/telemetry AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:@sap-ux/axios-extension AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:@sap-ux/inquirer-common AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:@sap-devx/yeoman-ui-types AI (dependencies): SAP org package; not a risk. ai
dependencies unvetted-dep:@sap-ux/guided-answers-helper AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:@sap-ux/odata-service-inquirer AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:@sap-ux/abap-deploy-config-inquirer AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai

Versions (showing 51 of 258)

View all versions
Version Deps Published
1.0.36 11 / 14
1.0.34 11 / 14
1.0.33 11 / 14
1.0.32 11 / 14
1.0.31 11 / 14
1.0.30 11 / 14
1.0.29 11 / 14
1.0.28 11 / 14
1.0.27 11 / 14
0.2.172 11 / 13
0.2.171 11 / 13
0.2.170 11 / 13
0.2.169 11 / 13
0.2.168 11 / 13
0.2.167 11 / 13
0.2.166 11 / 13
0.2.165 11 / 13
0.2.156 11 / 13
0.2.144 11 / 13
0.2.143 11 / 13
0.2.142 11 / 13
0.2.141 11 / 13
0.2.140 11 / 13
0.2.139 11 / 13
0.2.138 11 / 13
0.2.137 11 / 13
0.2.136 11 / 13
0.2.135 11 / 13
0.2.134 11 / 13
0.2.133 11 / 13
0.2.132 11 / 13
0.2.131 11 / 13
0.2.130 11 / 13
0.2.128 11 / 13
0.2.126 11 / 13
0.2.125 11 / 13
0.2.124 11 / 13
0.2.123 11 / 13
0.2.121 11 / 13
0.2.120 11 / 13
0.2.119 11 / 13
0.2.118 11 / 13
0.2.117 11 / 13
0.2.116 11 / 13
0.2.115 11 / 13
0.2.114 11 / 13
0.2.113 11 / 13
0.2.112 11 / 13
0.2.111 11 / 13
0.2.110 11 / 13
0.2.109 11 / 13

v1.0.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.28

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: devinea → GitHub Actions (on 2026-07-15, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (devinea) on 2026-07-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.0.27

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: devinea → GitHub Actions (on 2026-07-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (devinea) on 2026-07-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.