@sap-ux/ui5-library-reference-sub-generator
Generator for adding reference libraries to a project
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@sap-ux/telemetry | AI (phantom-deps): Same SAP org monorepo; phantom-dep heuristic fires on indirect usage patterns common in yeoman generators. | ai | |
| phantom-deps | phantom-dep:@sap-ux/project-access | AI (phantom-deps): Same SAP org monorepo; stable false positive for this package. | ai |
Versions (showing 51 of 201)
| Version | Deps | Published |
|---|---|---|
| 1.0.27 | 9 / 12 | |
| 1.0.26 | 9 / 12 | |
| 1.0.25 | 9 / 12 | |
| 1.0.24 | 9 / 12 | |
| 1.0.23 | 9 / 12 | |
| 1.0.22 | 9 / 12 | |
| 0.1.155 | 9 / 11 | |
| 0.1.154 | 9 / 11 | |
| 0.1.153 | 9 / 11 | |
| 0.1.152 | 9 / 11 | |
| 0.1.151 | 9 / 11 | |
| 0.1.150 | 9 / 11 | |
| 0.1.141 | 9 / 11 | |
| 0.1.132 | 9 / 11 | |
| 0.1.131 | 9 / 11 | |
| 0.1.130 | 9 / 11 | |
| 0.1.129 | 9 / 11 | |
| 0.1.128 | 9 / 11 | |
| 0.1.127 | 9 / 11 | |
| 0.1.126 | 9 / 11 | |
| 0.1.125 | 9 / 11 | |
| 0.1.124 | 9 / 11 | |
| 0.1.123 | 9 / 11 | |
| 0.1.121 | 9 / 11 | |
| 0.1.119 | 9 / 11 | |
| 0.1.118 | 9 / 11 | |
| 0.1.117 | 9 / 11 | |
| 0.1.116 | 9 / 11 | |
| 0.1.114 | 9 / 11 | |
| 0.1.113 | 9 / 11 | |
| 0.1.112 | 9 / 11 | |
| 0.1.111 | 9 / 11 | |
| 0.1.110 | 9 / 11 | |
| 0.1.109 | 9 / 11 | |
| 0.1.108 | 9 / 11 | |
| 0.1.107 | 9 / 11 | |
| 0.1.106 | 9 / 11 | |
| 0.1.105 | 9 / 11 | |
| 0.1.104 | 9 / 11 | |
| 0.1.103 | 9 / 11 | |
| 0.1.102 | 9 / 11 | |
| 0.1.101 | 9 / 11 | |
| 0.1.100 | 9 / 11 | |
| 0.1.99 | 9 / 11 | |
| 0.1.97 | 9 / 11 | |
| 0.1.96 | 9 / 11 | |
| 0.1.95 | 9 / 11 | |
| 0.1.94 | 9 / 11 | |
| 0.1.93 | 9 / 11 | |
| 0.1.92 | 9 / 11 | |
| 0.1.91 | 9 / 11 |
v1.0.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.22
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (devinea) on 2026-07-07, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.