← Home

@sap-ux/ui5-library-writer

Writer module to generate a new ui5 library

100
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Established SAP UX tooling package; lack of provenance is consistent across all 235 versions and is not a risk indicator here. ai

Versions (showing 100 of 241)

Version Deps Published
1.0.14 8 / 8
1.0.13 8 / 8
1.0.12 8 / 8
0.6.85 8 / 8
0.6.84 8 / 8
0.6.83 8 / 8
0.6.82 8 / 8
0.6.81 8 / 8
0.6.80 8 / 8
0.6.79 8 / 8
0.6.78 8 / 8
0.6.77 8 / 8
0.6.76 8 / 8
0.6.75 8 / 8
0.6.74 8 / 8
0.6.73 8 / 8
0.6.72 8 / 8
0.6.71 8 / 8
0.6.70 8 / 8
0.6.69 8 / 8
0.6.68 8 / 8
0.6.67 8 / 8
0.6.66 8 / 8
0.6.65 8 / 8
0.6.64 8 / 8
0.6.63 8 / 8
0.6.62 8 / 8
0.6.60 8 / 8
0.6.59 8 / 8
0.6.58 8 / 8
0.6.57 8 / 8
0.6.56 8 / 8
0.6.55 8 / 8
0.6.54 8 / 8
0.6.53 8 / 8
0.6.52 8 / 8
0.6.51 8 / 8
0.6.50 8 / 8
0.6.49 8 / 8
0.6.48 8 / 8
0.6.47 8 / 8
0.6.46 8 / 8
0.6.45 8 / 8
0.6.44 8 / 8
0.6.43 8 / 8
0.6.42 8 / 8
0.6.41 8 / 8
0.6.40 8 / 8
0.6.39 8 / 8
0.6.38 8 / 8
0.6.37 8 / 8
0.6.36 8 / 8
0.6.35 8 / 8
0.6.34 8 / 8
0.6.33 8 / 8
0.6.31 8 / 8
0.6.30 8 / 8
0.6.29 8 / 8
0.6.28 8 / 8
0.6.27 8 / 8
0.6.26 8 / 8
0.6.25 8 / 8
0.6.24 8 / 8
0.6.23 8 / 8
0.6.22 8 / 8
0.6.21 8 / 8
0.6.20 8 / 8
0.6.19 8 / 8
0.6.18 8 / 8
0.6.17 8 / 8
0.6.16 8 / 8
0.6.15 8 / 8
0.6.14 8 / 8
0.6.13 8 / 8
0.6.12 8 / 8
0.6.11 8 / 8
0.6.10 8 / 8
0.6.9 8 / 8
0.6.8 8 / 8
0.6.7 8 / 8
0.6.6 8 / 8
0.6.5 8 / 8
0.6.4 8 / 8
0.6.3 8 / 8
0.6.2 8 / 8
0.6.1 8 / 8
0.6.0 8 / 8
0.5.65 8 / 8
0.5.64 8 / 8
0.5.63 8 / 8
0.5.62 8 / 8
0.5.61 8 / 8
0.5.60 8 / 8
0.5.59 8 / 8
0.5.58 8 / 8
0.5.57 8 / 8
0.5.56 8 / 8
0.5.55 8 / 8
0.5.54 8 / 8
0.5.53 8 / 8
Showing 100 of 241 Next page →

v1.0.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.13

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: devinea → GitHub Actions (on 2026-07-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (devinea) on 2026-07-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.0.12

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: devinea → GitHub Actions (on 2026-07-21, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (devinea) on 2026-07-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.5.64

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.63

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.62

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.61

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.60

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.59

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.58

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.57

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.56

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.55

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.54

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.53

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.