← Home

@sap-ux/ui5-library-reference-sub-generator

Generator for adding reference libraries to a project

100
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@sap-ux/telemetry AI (phantom-deps): Same SAP org monorepo; phantom-dep heuristic fires on indirect usage patterns common in yeoman generators. ai
phantom-deps phantom-dep:@sap-ux/project-access AI (phantom-deps): Same SAP org monorepo; stable false positive for this package. ai

Versions (showing 100 of 201)

Version Deps Published
1.0.27 9 / 12
1.0.26 9 / 12
1.0.25 9 / 12
1.0.24 9 / 12
1.0.23 9 / 12
1.0.22 9 / 12
0.1.155 9 / 11
0.1.154 9 / 11
0.1.153 9 / 11
0.1.152 9 / 11
0.1.151 9 / 11
0.1.150 9 / 11
0.1.141 9 / 11
0.1.132 9 / 11
0.1.131 9 / 11
0.1.130 9 / 11
0.1.129 9 / 11
0.1.128 9 / 11
0.1.127 9 / 11
0.1.126 9 / 11
0.1.125 9 / 11
0.1.124 9 / 11
0.1.123 9 / 11
0.1.121 9 / 11
0.1.119 9 / 11
0.1.118 9 / 11
0.1.117 9 / 11
0.1.116 9 / 11
0.1.114 9 / 11
0.1.113 9 / 11
0.1.112 9 / 11
0.1.111 9 / 11
0.1.110 9 / 11
0.1.109 9 / 11
0.1.108 9 / 11
0.1.107 9 / 11
0.1.106 9 / 11
0.1.105 9 / 11
0.1.104 9 / 11
0.1.103 9 / 11
0.1.102 9 / 11
0.1.101 9 / 11
0.1.100 9 / 11
0.1.99 9 / 11
0.1.97 9 / 11
0.1.96 9 / 11
0.1.95 9 / 11
0.1.94 9 / 11
0.1.93 9 / 11
0.1.92 9 / 11
0.1.91 9 / 11
0.1.90 9 / 11
0.1.89 9 / 11
0.1.88 9 / 11
0.1.87 9 / 11
0.1.86 9 / 11
0.1.85 9 / 11
0.1.84 9 / 11
0.1.83 9 / 11
0.1.82 9 / 11
0.1.81 9 / 11
0.1.80 9 / 11
0.1.79 9 / 11
0.1.78 9 / 11
0.1.77 9 / 11
0.1.75 9 / 11
0.1.74 9 / 11
0.1.73 9 / 11
0.1.72 9 / 11
0.1.71 9 / 11
0.1.70 9 / 11
0.1.69 9 / 11
0.1.68 9 / 11
0.1.67 9 / 11
0.1.66 9 / 11
0.1.65 9 / 11
0.1.64 9 / 11
0.1.63 9 / 11
0.1.62 9 / 11
0.1.61 9 / 11
0.1.60 9 / 11
0.1.59 9 / 11
0.1.58 9 / 11
0.1.57 9 / 11
0.1.56 9 / 11
0.1.55 9 / 11
0.1.54 9 / 11
0.1.53 9 / 11
0.1.52 9 / 11
0.1.51 9 / 11
0.1.50 9 / 11
0.1.49 9 / 11
0.1.48 9 / 11
0.1.46 9 / 11
0.1.45 9 / 11
0.1.44 9 / 11
0.1.43 9 / 11
0.1.42 9 / 11
0.1.41 9 / 10
0.1.40 9 / 10
Showing 100 of 201 Next page →

v1.0.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.22

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: devinea → GitHub Actions (on 2026-07-07, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (devinea) on 2026-07-07, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.