@sapui5/sap.fe.templates
SAPUI5 Library sap.fe.templates
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/designtime/ObjectPage.designtime.js | AI (source-diff): SAP UI5 transpiled build artifact; standard framework patterns. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/view/fragments/TransportSelection.js | AI (source-diff): SAP UI5 transpiled build artifact; standard framework patterns. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/flexibility/StashControlAndDisconnect.js | AI (source-diff): SAP UI5 transpiled build artifact; standard framework patterns. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ListReport/overrides/SideEffects.js | AI (source-diff): SAP UI5 transpiled build artifact; standard framework patterns. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/components/CollaborationDraft.js | AI (source-diff): SAP UI5 transpiled build artifact; standard framework patterns. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/overrides/CollaborationManager.js | AI (source-diff): SAP UI5 transpiled build artifact; standard framework patterns. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/components/DraftToggle.js | AI (source-diff): SAP UI5 transpiled build artifact; standard framework patterns. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ListReport/designtime/ListReport.designtime.helper.js | AI (source-diff): SAP UI5 transpiled build artifact; standard framework patterns. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ListReport/designtime/ListReport.designtime.js | AI (source-diff): SAP UI5 transpiled build artifact; standard framework patterns. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/designtime/ObjectPage.designtime.helper.js | AI (source-diff): SAP UI5 transpiled build artifact; standard framework patterns. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/components/CollaborationDiscardDialog.js | AI (source-diff): SAP UI5 transpiled build output; readable collaboration dialog logic, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/card/BaseCardContentProvider.js | AI (source-diff): SAP UI5 transpiled build output; readable class structure, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/card/AdaptiveCardContent.js | AI (source-diff): SAP UI5 transpiled build output; sap.ui.define wrapper with readable JSDoc — not malicious obfuscation. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase attributable to new feature modules (Adaptive Cards, Collaboration); no injected payload indicators. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New Adaptive Cards and Collaboration Draft feature modules; legitimate feature addition from SAP. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ListReport/view/fragments/MultipleMode.block.js | AI (source-diff): SAP UI5 transpiled build output; consistent with package distribution pattern. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ListReport/LRMessageStrip.js | AI (source-diff): SAP UI5 transpiled build output; consistent with package distribution pattern. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/card/facets/HeaderTitle.js | AI (source-diff): SAP UI5 transpiled build output; readable header title facet, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/card/facets/HeaderContent.js | AI (source-diff): SAP UI5 transpiled build output; readable header content facet, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/card/actions/HeaderActions.js | AI (source-diff): SAP UI5 transpiled build output; readable header actions logic, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/card/Generator.js | AI (source-diff): SAP UI5 transpiled build output; readable adaptive card generator, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/ExtendPageDefinition.js | AI (source-diff): SAP UI5 transpiled build output; readable page definition logic, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/view/fragments/TransportSelection.block.js | AI (source-diff): SAP-copyrighted SAPUI5 bundled module; long-line format is standard for SAP's UI5 build output. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/helpers/SectionNavigationHelper.js | AI (source-diff): SAP UI5 build output with copyright header and readable logic; long lines from minification are normal for this package family. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ListReport/controls/MultipleModeControl.js | AI (source-diff): Babel-transpiled SAPUI5 AMD module with SAP copyright; long lines are transpiler artifacts, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ListReport/overrides/Share.js | AI (source-diff): Babel-transpiled SAPUI5 AMD module with SAP copyright; long lines are transpiler artifacts. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/ObjectPageTemplating.js | AI (source-diff): Babel-transpiled SAPUI5 AMD module with SAP copyright; long lines are transpiler artifacts. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/TableScroller.js | AI (source-diff): Babel-transpiled SAPUI5 AMD module with SAP copyright; long lines are transpiler artifacts. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/overrides/Share.js | AI (source-diff): Babel-transpiled SAPUI5 AMD module with SAP copyright; long lines are transpiler artifacts. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/templating/ObjectPageTemplating.js | AI (source-diff): SAPUI5 libraries ship minified/bundled JS with long lines as standard distribution format; SAP copyright header confirms legitimacy. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): SAP maintains multiple versioned branches of SAPUI5; older version publishes after gaps are expected for LTS/patch releases. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/types/sap.fe.templates-auto-ext.d.js | AI (source-diff): Inline base64 source map in autogenerated SAPUI5 build artifact; not obfuscation. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ListReport/view/fragments/MultipleMode.fragment.js | AI (source-diff): Babel-transpiled SAPUI5 module with SAP copyright; standard transpilation output. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/Feedback.js | AI (source-diff): Babel-transpiled SAPUI5 module with SAP copyright; standard transpilation output. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/components/DraftHandlerButton.js | AI (source-diff): Babel-transpiled SAPUI5 module with SAP copyright; long lines are inlined helper functions, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/card/MetaPath.js | AI (source-diff): Readable SAPUI5 AMD module with JSDoc comments; long-line flag is a false positive for this package. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/components/CollaborationDraft.block.js | AI (source-diff): Standard SAPUI5 Babel-transpiled AMD bundle with SAP copyright; long lines are decorator transforms, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/view/fragments/FooterContent.block.js | AI (source-diff): Same SAPUI5 transpiled bundle pattern; SAP copyright header present, no malicious indicators. | ai | |
| source-diff | obfuscated-file:src/sap/fe/templates/ObjectPage/components/DraftHandlerButton.block.js | AI (source-diff): Same SAPUI5 transpiled bundle pattern; SAP copyright header present, no malicious indicators. | ai |
Versions (showing 100 of 144)
v1.135.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.134.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.133.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.133.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.132.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.131.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.130.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.130.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.130.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.130.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.130.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.130.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.130.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.130.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.129.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.129.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.128.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.127.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.127.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.127.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.127.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.127.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.127.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.127.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.126.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.126.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.126.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.125.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.124.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.124.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.124.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.124.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.124.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.124.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.124.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.124.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.124.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.124.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.123.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.121.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.121.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.120.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.120.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.120.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.120.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.120.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.120.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.120.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.