← Home

@sap-ux/ui-service-inquirer

Generator for creating UI Service

100
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): SAP open-ux-tools monorepo does not publish with Sigstore provenance; stable pattern across all versions. ai
dependencies unvetted-dep:@sap-ux/logger AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:yeoman-generator AI (dependencies): Well-known Yeoman scaffolding library; not a risk. ai
dependencies unvetted-dep:@sap-ux/btp-utils AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:@sap-ux/telemetry AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:@sap-ux/axios-extension AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:@sap-ux/inquirer-common AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:@sap-devx/yeoman-ui-types AI (dependencies): SAP org package; not a risk. ai
dependencies unvetted-dep:@sap-ux/guided-answers-helper AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:@sap-ux/odata-service-inquirer AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai
dependencies unvetted-dep:@sap-ux/abap-deploy-config-inquirer AI (dependencies): SAP org package from the same open-ux-tools ecosystem; not a risk. ai

Versions (showing 100 of 258)

Version Deps Published
1.0.36 11 / 14
1.0.34 11 / 14
1.0.33 11 / 14
1.0.32 11 / 14
1.0.31 11 / 14
1.0.30 11 / 14
1.0.29 11 / 14
1.0.28 11 / 14
1.0.27 11 / 14
0.2.172 11 / 13
0.2.171 11 / 13
0.2.170 11 / 13
0.2.169 11 / 13
0.2.168 11 / 13
0.2.167 11 / 13
0.2.166 11 / 13
0.2.165 11 / 13
0.2.156 11 / 13
0.2.144 11 / 13
0.2.143 11 / 13
0.2.142 11 / 13
0.2.141 11 / 13
0.2.140 11 / 13
0.2.139 11 / 13
0.2.138 11 / 13
0.2.137 11 / 13
0.2.136 11 / 13
0.2.135 11 / 13
0.2.134 11 / 13
0.2.133 11 / 13
0.2.132 11 / 13
0.2.131 11 / 13
0.2.130 11 / 13
0.2.128 11 / 13
0.2.126 11 / 13
0.2.125 11 / 13
0.2.124 11 / 13
0.2.123 11 / 13
0.2.121 11 / 13
0.2.120 11 / 13
0.2.119 11 / 13
0.2.118 11 / 13
0.2.117 11 / 13
0.2.116 11 / 13
0.2.115 11 / 13
0.2.114 11 / 13
0.2.113 11 / 13
0.2.112 11 / 13
0.2.111 11 / 13
0.2.110 11 / 13
0.2.109 11 / 13
0.2.108 11 / 13
0.2.107 11 / 13
0.2.106 11 / 13
0.2.105 11 / 13
0.2.104 11 / 13
0.2.103 11 / 13
0.2.102 11 / 13
0.2.101 11 / 13
0.2.100 11 / 13
0.2.99 11 / 13
0.2.98 11 / 13
0.2.96 11 / 13
0.2.95 11 / 13
0.2.94 11 / 13
0.2.93 11 / 13
0.2.92 11 / 13
0.2.91 11 / 13
0.2.90 11 / 13
0.2.89 11 / 13
0.2.88 11 / 13
0.2.87 11 / 13
0.2.86 11 / 13
0.2.85 11 / 13
0.2.84 11 / 13
0.2.83 11 / 13
0.2.82 11 / 13
0.2.81 11 / 13
0.2.80 11 / 13
0.2.79 11 / 13
0.2.78 11 / 13
0.2.77 11 / 13
0.2.76 11 / 13
0.2.75 11 / 13
0.2.74 11 / 13
0.2.73 11 / 13
0.2.72 11 / 13
0.2.71 11 / 13
0.2.70 11 / 13
0.2.69 11 / 13
0.2.68 11 / 13
0.2.67 11 / 13
0.2.66 11 / 13
0.2.65 11 / 13
0.2.64 11 / 13
0.2.63 11 / 13
0.2.61 11 / 13
0.2.60 11 / 13
0.2.59 11 / 13
0.2.58 11 / 13
Showing 100 of 258 Next page →

v1.0.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.28

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: devinea → GitHub Actions (on 2026-07-15, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (devinea) on 2026-07-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.0.27

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: devinea → GitHub Actions (on 2026-07-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (devinea) on 2026-07-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.