← Home

@sap-ux/ui5-library-reference-writer

Writer module to add library/component references to an existing Fiori application

100
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publisher is confirmed by SLSA/Sigstore attestation from the official SAP org repo. ai
dependencies unvetted-dep:mem-fs-editor AI (dependencies): mem-fs-editor is a well-known Yeoman ecosystem package; stable dependency for this SAP tooling package. ai
dependencies unvetted-dep:@sap-ux/ui5-config AI (dependencies): Sibling SAP UX package from the same open-ux-tools monorepo; no independent risk. ai
provenance no-provenance AI (provenance): SAP open-ux-tools monorepo; provenance not yet configured but package is well-established and repo URL is verifiable. ai

Versions (showing 100 of 170)

Version Deps Published
1.0.13 4 / 4
1.0.12 4 / 4
1.0.11 4 / 4
1.0.10 4 / 4
1.0.9 4 / 4
1.0.8 4 / 4
1.0.7 4 / 4
1.0.6 4 / 4
1.0.5 4 / 4
1.0.4 4 / 4
1.0.2 4 / 4
1.0.1 4 / 4
1.0.0 4 / 4
0.3.2 4 / 4
0.3.1 4 / 4
0.3.0 4 / 4
0.2.73 4 / 4
0.2.72 4 / 4
0.2.71 4 / 4
0.2.70 4 / 4
0.2.69 4 / 4
0.2.68 4 / 4
0.2.67 4 / 4
0.2.66 4 / 4
0.2.65 4 / 4
0.2.64 4 / 4
0.2.63 4 / 4
0.2.62 4 / 4
0.2.61 4 / 4
0.2.60 4 / 4
0.2.59 4 / 4
0.2.58 4 / 4
0.2.57 4 / 4
0.2.56 4 / 4
0.2.55 4 / 4
0.2.54 4 / 4
0.2.52 4 / 4
0.2.51 4 / 4
0.2.50 4 / 4
0.2.49 4 / 4
0.2.48 4 / 4
0.2.47 4 / 4
0.2.46 4 / 4
0.2.45 4 / 4
0.2.44 4 / 4
0.2.43 4 / 4
0.2.42 4 / 4
0.2.41 4 / 4
0.2.40 4 / 4
0.2.39 4 / 4
0.2.38 4 / 4
0.2.37 4 / 4
0.2.36 4 / 4
0.2.35 4 / 4
0.2.34 4 / 4
0.2.33 4 / 4
0.2.32 4 / 4
0.2.31 4 / 4
0.2.30 4 / 4
0.2.28 4 / 4
0.2.27 4 / 4
0.2.26 4 / 4
0.2.25 4 / 4
0.2.24 4 / 4
0.2.23 4 / 4
0.2.22 4 / 4
0.2.21 4 / 4
0.2.20 4 / 4
0.2.19 4 / 4
0.2.18 4 / 4
0.2.17 4 / 4
0.2.16 4 / 4
0.2.15 4 / 4
0.2.14 4 / 4
0.2.13 4 / 4
0.2.12 4 / 4
0.2.11 4 / 4
0.2.10 4 / 4
0.2.9 4 / 4
0.2.8 4 / 4
0.2.7 4 / 4
0.2.6 4 / 4
0.2.5 4 / 4
0.2.4 4 / 4
0.2.3 4 / 4
0.2.2 4 / 4
0.2.1 4 / 4
0.2.0 4 / 4
0.1.61 4 / 4
0.1.60 4 / 4
0.1.59 4 / 4
0.1.58 4 / 4
0.1.57 4 / 4
0.1.56 4 / 4
0.1.55 4 / 4
0.1.54 4 / 4
0.1.53 4 / 4
0.1.52 4 / 4
0.1.51 4 / 4
0.1.50 4 / 4
Showing 100 of 170 Next page →

v1.0.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.60

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.59

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.58

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.57

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.56

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.55

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.54

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.53

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.52

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.51

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.50

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.