← Home

@sap-ux/ui5-library-sub-generator

Generator for creating UI5 libraries

51
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@sap-ux/ui5-info AI (dependencies): First-party SAP UX tooling dep from the same open-ux-tools monorepo. ai
dependencies unvetted-dep:yeoman-generator AI (dependencies): Well-known Yeoman core package; expected for a Yeoman-based generator. ai
dependencies unvetted-dep:@sap-ux/nodejs-utils AI (dependencies): First-party SAP UX tooling dep from the same open-ux-tools monorepo. ai
dependencies unvetted-dep:@sap-devx/yeoman-ui-types AI (dependencies): SAP DevX type definitions for Yeoman UI; expected for this generator. ai
dependencies unvetted-dep:@sap-ux/ui5-library-writer AI (dependencies): First-party SAP UX tooling dep from the same open-ux-tools monorepo. ai
dependencies unvetted-dep:@sap-ux/fiori-tools-settings AI (dependencies): First-party SAP UX tooling dep from the same open-ux-tools monorepo. ai
dependencies unvetted-dep:@sap-ux/ui5-library-inquirer AI (dependencies): First-party SAP UX tooling dep from the same open-ux-tools monorepo. ai
dependencies unvetted-dep:@sap-ux/fiori-generator-shared AI (dependencies): First-party SAP UX tooling dep from the same open-ux-tools monorepo. ai
provenance no-provenance AI (provenance): Large SAP monorepo; lack of Sigstore provenance is common for enterprise npm packages. ai

Versions (showing 51 of 237)

View all versions
Version Deps Published
1.0.26 9 / 12
1.0.25 9 / 12
1.0.24 9 / 12
1.0.23 9 / 12
1.0.22 9 / 12
0.1.168 9 / 11
0.1.167 9 / 11
0.1.166 9 / 11
0.1.165 9 / 11
0.1.164 9 / 11
0.1.163 9 / 11
0.1.162 9 / 11
0.1.152 9 / 11
0.1.143 9 / 11
0.1.142 9 / 11
0.1.141 9 / 11
0.1.140 9 / 11
0.1.139 9 / 11
0.1.138 9 / 11
0.1.137 9 / 11
0.1.136 9 / 11
0.1.135 9 / 11
0.1.134 9 / 11
0.1.132 9 / 11
0.1.130 9 / 11
0.1.129 9 / 11
0.1.128 9 / 11
0.1.127 9 / 11
0.1.125 9 / 11
0.1.124 9 / 11
0.1.123 9 / 11
0.1.122 9 / 11
0.1.121 9 / 11
0.1.120 9 / 11
0.1.119 9 / 11
0.1.118 9 / 11
0.1.117 9 / 11
0.1.116 9 / 11
0.1.115 9 / 11
0.1.114 9 / 11
0.1.113 9 / 11
0.1.112 9 / 11
0.1.111 9 / 11
0.1.110 9 / 11
0.1.109 9 / 11
0.1.107 9 / 11
0.1.106 9 / 11
0.1.105 9 / 11
0.1.104 9 / 11
0.1.103 9 / 11
0.1.102 9 / 11

v1.0.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.22

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: devinea → GitHub Actions (on 2026-07-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (devinea) on 2026-07-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.