← Home

@sap-ux/ui5-config

63
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): SAP org migrated to GitHub Actions CI publishing with SLSA attestation; stable pattern for this package going forward. ai
maintainer-change maintainer-added AI (maintainer-change): sap-ospo-admin is SAP's open-source program office admin account; expected for SAP OSS governance. ai
phantom-deps phantom-dep:axios AI (phantom-deps): axios is explicitly declared as a runtime dependency in package.json; phantom-dep is a false positive here. ai

Versions (showing 63 of 63)

Version Deps Published
1.0.5 6 / 4
1.0.4 6 / 4
1.0.3 6 / 4
1.0.2 6 / 4
1.0.1 6 / 4
1.0.0 6 / 4
0.31.1 6 / 4
0.31.0 6 / 4
0.30.4 6 / 4
0.30.3 6 / 4
0.30.2 6 / 4
0.30.1 6 / 4
0.30.0 6 / 4
0.29.21 6 / 4
0.29.20 6 / 4
0.29.19 6 / 4
0.29.18 6 / 4
0.29.17 6 / 4
0.29.16 6 / 4
0.29.15 6 / 4
0.29.14 6 / 4
0.29.13 6 / 4
0.29.12 6 / 4
0.29.11 6 / 4
0.29.10 6 / 4
0.29.9 6 / 4
0.29.8 6 / 4
0.29.7 6 / 4
0.29.6 6 / 4
0.29.5 6 / 4
0.29.4 6 / 4
0.29.3 6 / 4
0.29.2 6 / 4
0.29.1 6 / 4
0.29.0 6 / 4
0.28.3 6 / 4
0.28.2 6 / 4
0.28.1 6 / 4
0.28.0 6 / 4
0.27.2 6 / 4
0.27.1 6 / 4
0.27.0 6 / 4
0.26.5 6 / 4
0.26.4 6 / 4
0.26.3 6 / 4
0.26.2 6 / 4
0.26.1 6 / 4
0.26.0 3 / 3
0.25.2 3 / 3
0.25.1 3 / 3
0.25.0 3 / 3
0.24.1 3 / 3
0.24.0 3 / 3
0.23.1 3 / 3
0.23.0 3 / 3
0.22.10 3 / 3
0.22.9 3 / 3
0.22.8 4 / 2
0.22.7 4 / 2
0.22.6 4 / 2
0.22.5 4 / 2
0.22.4 3 / 2
0.22.3 3 / 2

v1.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.27.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.27.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.24.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.23.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.