@sap/ux-specification
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Long-established SAP package; lack of Sigstore provenance is consistent across all 661 versions and is not a risk indicator here. | ai |
Versions (showing 100 of 109)
| Version | Deps | Published |
|---|---|---|
| 1.144.5 | 2 / 31 | |
| 1.144.4 | 2 / 31 | |
| 1.144.3 | 2 / 31 | |
| 1.144.2 | 2 / 31 | |
| 1.144.1 | 2 / 31 | |
| 1.144.0 | 2 / 31 | |
| 1.142.8 | 2 / 31 | |
| 1.142.7 | 2 / 31 | |
| 1.142.6 | 2 / 31 | |
| 1.142.5 | 2 / 31 | |
| 1.142.4 | 2 / 31 | |
| 1.142.3 | 2 / 31 | |
| 1.142.2 | 2 / 30 | |
| 1.142.1 | 2 / 30 | |
| 1.142.0 | 2 / 30 | |
| 1.139.13 | 2 / 31 | |
| 1.139.12 | 2 / 31 | |
| 1.139.11 | 2 / 31 | |
| 1.139.10 | 2 / 31 | |
| 1.139.9 | 2 / 31 | |
| 1.139.8 | 2 / 31 | |
| 1.139.7 | 2 / 30 | |
| 1.139.6 | 2 / 30 | |
| 1.139.5 | 2 / 30 | |
| 1.139.4 | 2 / 30 | |
| 1.139.2 | 2 / 30 | |
| 1.139.1 | 2 / 29 | |
| 1.139.0 | 2 / 26 | |
| 1.136.21 | 2 / 31 | |
| 1.136.20 | 2 / 31 | |
| 1.136.19 | 2 / 31 | |
| 1.136.18 | 2 / 31 | |
| 1.136.17 | 2 / 31 | |
| 1.136.16 | 2 / 31 | |
| 1.136.15 | 2 / 30 | |
| 1.136.14 | 2 / 30 | |
| 1.136.13 | 2 / 30 | |
| 1.136.12 | 2 / 30 | |
| 1.136.11 | 2 / 29 | |
| 1.136.10 | 2 / 26 | |
| 1.124.40 | 2 / 31 | |
| 1.124.38 | 2 / 31 | |
| 1.124.37 | 2 / 31 | |
| 1.124.36 | 2 / 31 | |
| 1.124.35 | 2 / 31 | |
| 1.124.34 | 2 / 30 | |
| 1.124.33 | 2 / 30 | |
| 1.124.32 | 2 / 30 | |
| 1.124.31 | 2 / 30 | |
| 1.124.30 | 2 / 29 | |
| 1.124.29 | 2 / 26 | |
| 1.120.58 | 2 / 31 | |
| 1.120.57 | 2 / 31 | |
| 1.120.56 | 2 / 31 | |
| 1.120.55 | 2 / 31 | |
| 1.120.54 | 2 / 31 | |
| 1.120.53 | 2 / 31 | |
| 1.120.52 | 2 / 30 | |
| 1.120.51 | 2 / 30 | |
| 1.120.50 | 2 / 30 | |
| 1.120.49 | 2 / 30 | |
| 1.120.48 | 2 / 29 | |
| 1.120.47 | 2 / 26 | |
| 1.108.77 | 2 / 31 | |
| 1.108.76 | 2 / 31 | |
| 1.108.75 | 2 / 31 | |
| 1.108.74 | 2 / 31 | |
| 1.108.73 | 2 / 31 | |
| 1.108.72 | 2 / 31 | |
| 1.108.71 | 2 / 30 | |
| 1.108.70 | 2 / 30 | |
| 1.108.69 | 2 / 30 | |
| 1.108.68 | 2 / 30 | |
| 1.108.67 | 2 / 29 | |
| 1.108.66 | 2 / 26 | |
| 1.96.110 | 2 / 31 | |
| 1.96.109 | 2 / 31 | |
| 1.96.108 | 2 / 31 | |
| 1.96.107 | 2 / 31 | |
| 1.96.106 | 2 / 31 | |
| 1.96.105 | 2 / 31 | |
| 1.96.104 | 2 / 30 | |
| 1.96.103 | 2 / 30 | |
| 1.96.102 | 2 / 30 | |
| 1.96.101 | 2 / 30 | |
| 1.96.100 | 2 / 29 | |
| 1.96.99 | 2 / 26 | |
| 1.84.134 | 2 / 31 | |
| 1.84.133 | 2 / 31 | |
| 1.84.132 | 1 / 31 | |
| 1.84.131 | 1 / 31 | |
| 1.84.130 | 1 / 29 | |
| 1.84.129 | 1 / 29 | |
| 1.84.128 | 1 / 29 | |
| 1.84.127 | 1 / 29 | |
| 1.84.126 | 1 / 28 | |
| 1.84.125 | 1 / 23 | |
| 1.71.156 | 2 / 30 | |
| 1.71.155 | 2 / 30 | |
| 1.71.154 | 2 / 30 |
v1.144.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.144.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.142.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.142.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.142.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.142.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.142.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.139.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.139.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.139.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.139.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.139.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.139.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.139.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.139.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.139.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.136.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.136.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.136.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.136.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.136.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.136.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.136.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.136.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.124.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.124.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.124.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.124.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.124.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.124.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.124.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.124.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.120.54
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.120.53
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.120.52
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.120.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.120.50
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.120.49
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.120.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.120.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.108.73
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.108.72
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.108.71
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.108.70
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.108.69
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.108.68
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.108.67
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.108.66
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.96.106
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.96.105
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.96.104
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.96.103
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.96.102
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.96.101
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.96.100
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.96.99
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.132
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.131
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.130
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.129
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.128
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.127
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.126
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.125
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.