@sap-ux/ui5-library-sub-generator
Generator for creating UI5 libraries
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@sap-ux/ui5-info | AI (dependencies): First-party SAP UX tooling dep from the same open-ux-tools monorepo. | ai | |
| dependencies | unvetted-dep:yeoman-generator | AI (dependencies): Well-known Yeoman core package; expected for a Yeoman-based generator. | ai | |
| dependencies | unvetted-dep:@sap-ux/nodejs-utils | AI (dependencies): First-party SAP UX tooling dep from the same open-ux-tools monorepo. | ai | |
| dependencies | unvetted-dep:@sap-devx/yeoman-ui-types | AI (dependencies): SAP DevX type definitions for Yeoman UI; expected for this generator. | ai | |
| dependencies | unvetted-dep:@sap-ux/ui5-library-writer | AI (dependencies): First-party SAP UX tooling dep from the same open-ux-tools monorepo. | ai | |
| dependencies | unvetted-dep:@sap-ux/fiori-tools-settings | AI (dependencies): First-party SAP UX tooling dep from the same open-ux-tools monorepo. | ai | |
| dependencies | unvetted-dep:@sap-ux/ui5-library-inquirer | AI (dependencies): First-party SAP UX tooling dep from the same open-ux-tools monorepo. | ai | |
| dependencies | unvetted-dep:@sap-ux/fiori-generator-shared | AI (dependencies): First-party SAP UX tooling dep from the same open-ux-tools monorepo. | ai | |
| provenance | no-provenance | AI (provenance): Large SAP monorepo; lack of Sigstore provenance is common for enterprise npm packages. | ai |
Versions (showing 51 of 237)
| Version | Deps | Published |
|---|---|---|
| 1.0.26 | 9 / 12 | |
| 1.0.25 | 9 / 12 | |
| 1.0.24 | 9 / 12 | |
| 1.0.23 | 9 / 12 | |
| 1.0.22 | 9 / 12 | |
| 0.1.168 | 9 / 11 | |
| 0.1.167 | 9 / 11 | |
| 0.1.166 | 9 / 11 | |
| 0.1.165 | 9 / 11 | |
| 0.1.164 | 9 / 11 | |
| 0.1.163 | 9 / 11 | |
| 0.1.162 | 9 / 11 | |
| 0.1.152 | 9 / 11 | |
| 0.1.143 | 9 / 11 | |
| 0.1.142 | 9 / 11 | |
| 0.1.141 | 9 / 11 | |
| 0.1.140 | 9 / 11 | |
| 0.1.139 | 9 / 11 | |
| 0.1.138 | 9 / 11 | |
| 0.1.137 | 9 / 11 | |
| 0.1.136 | 9 / 11 | |
| 0.1.135 | 9 / 11 | |
| 0.1.134 | 9 / 11 | |
| 0.1.132 | 9 / 11 | |
| 0.1.130 | 9 / 11 | |
| 0.1.129 | 9 / 11 | |
| 0.1.128 | 9 / 11 | |
| 0.1.127 | 9 / 11 | |
| 0.1.125 | 9 / 11 | |
| 0.1.124 | 9 / 11 | |
| 0.1.123 | 9 / 11 | |
| 0.1.122 | 9 / 11 | |
| 0.1.121 | 9 / 11 | |
| 0.1.120 | 9 / 11 | |
| 0.1.119 | 9 / 11 | |
| 0.1.118 | 9 / 11 | |
| 0.1.117 | 9 / 11 | |
| 0.1.116 | 9 / 11 | |
| 0.1.115 | 9 / 11 | |
| 0.1.114 | 9 / 11 | |
| 0.1.113 | 9 / 11 | |
| 0.1.112 | 9 / 11 | |
| 0.1.111 | 9 / 11 | |
| 0.1.110 | 9 / 11 | |
| 0.1.109 | 9 / 11 | |
| 0.1.107 | 9 / 11 | |
| 0.1.106 | 9 / 11 | |
| 0.1.105 | 9 / 11 | |
| 0.1.104 | 9 / 11 | |
| 0.1.103 | 9 / 11 | |
| 0.1.102 | 9 / 11 |
v1.0.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.22
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (devinea) on 2026-07-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.