← Home

@ui5/webcomponents

47
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

sap-ospo-adminui5-bot

Keywords

openui5sapui5ui5

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/generated/themes/SliderScale.css.js AI (source-diff): Generated CSS theme bundle; long lines are inlined CSS, benign for this package. ai
source-diff obfuscated-file:dist/CalendarTemplate.js AI (source-diff): Compiled JSX template output with long lines; not obfuscation. ai
source-diff obfuscated-file:dist/generated/templates/ComboBoxPopoverTemplate.lit.js AI (source-diff): Generated Lit template output; benign build artifact. ai
source-diff obfuscated-file:dist/generated/themes/FormLabelSpan.css.js AI (source-diff): Generated CSS-in-JS theme bundle; benign build artifact. ai
source-diff obfuscated-file:dist/generated/templates/DateTimePickerTemplate.lit.js AI (source-diff): Generated Lit template output; benign build artifact. ai
source-diff obfuscated-file:dist/generated/templates/DateRangePickerTemplate.lit.js AI (source-diff): Generated Lit template output; benign build artifact. ai
source-diff obfuscated-file:dist/generated/templates/DatePickerTemplate.lit.js AI (source-diff): Generated Lit template output; benign build artifact. ai
source-diff obfuscated-file:dist/generated/templates/ListTemplate.lit.js AI (source-diff): Generated Lit template output; benign build artifact. ai
source-diff obfuscated-file:dist/generated/templates/ComboBoxTemplate.lit.js AI (source-diff): Generated Lit template output; benign build artifact. ai
source-diff obfuscated-file:dist/generated/templates/BreadcrumbsTemplate.lit.js AI (source-diff): Generated Lit template render output; long lines are build artifacts, benign for this package. ai
source-diff obfuscated-file:dist/generated/themes/sap_horizon_hc_auto/parameters-bundle.css.d.ts AI (source-diff): Same generated CSS theme bundle pattern; not obfuscation. Stable for this package. ai
source-diff obfuscated-file:dist/generated/themes/sap_horizon_auto/parameters-bundle.css.d.ts AI (source-diff): Generated .d.ts files with inlined CSS theme bundles; long lines are CSS custom properties, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:dist/generated/templates/DateTimePickerPopoverTemplate.lit.js AI (source-diff): LitElement template bundle; standard build artifact for @ui5/webcomponents. ai
source-diff obfuscated-file:dist/generated/templates/ColorPickerTemplate.lit.js AI (source-diff): LitElement template bundle; standard build artifact for @ui5/webcomponents. ai
source-diff obfuscated-file:dist/generated/templates/CalendarTemplate.lit.js AI (source-diff): LitElement template bundle; standard build artifact for @ui5/webcomponents. ai
source-diff obfuscated-file:dist/generated/templates/CalendarHeaderTemplate.lit.js AI (source-diff): LitElement template bundle; standard build artifact for @ui5/webcomponents. ai
source-diff obfuscated-file:dist/generated/themes/Badge.css.js AI (source-diff): Minified CSS-in-JS theme bundle; standard build artifact for @ui5/webcomponents. ai
source-diff obfuscated-file:dist/generated/templates/DatePickerPopoverTemplate.lit.js AI (source-diff): LitElement template bundle; standard build artifact for @ui5/webcomponents. ai
maintainer-change maintainer-added AI (maintainer-change): ui5-bot is SAP's automation account; stable addition for this package. ai
provenance publisher-changed AI (provenance): SAP UI5 migrated publishing to GitHub Actions CI; consistent with org-wide automation change. ai
source-diff large-new-source-files AI (source-diff): New files are theme CSS bundles (sap_horizon_auto variants); expected growth for a UI component library. ai
dependencies unvetted-dep:@ui5/webcomponents-icons-tnt AI (dependencies): Sibling monorepo package from SAP; always released in lockstep with this package. ai
dependencies unvetted-dep:@ui5/webcomponents-icons-business-suite AI (dependencies): Sibling monorepo package from SAP; always released in lockstep with this package. ai
dependencies unvetted-dep:@ui5/webcomponents-localization AI (dependencies): Sibling monorepo package from SAP; always released in lockstep with this package. ai
dependencies unvetted-dep:@ui5/webcomponents-base AI (dependencies): Sibling monorepo package from SAP; always released in lockstep with this package. ai
dependencies unvetted-dep:@ui5/webcomponents-theming AI (dependencies): Sibling monorepo package from SAP; always released in lockstep with this package. ai
dependencies unvetted-dep:@ui5/webcomponents-icons AI (dependencies): Sibling monorepo package from SAP; always released in lockstep with this package. ai
provenance no-provenance AI (provenance): Established SAP OSS package; provenance absence is common and not a risk signal here. ai

Versions (showing 47 of 47)

Version Deps Published
2.24.0 6 / 8
2.23.3 6 / 8
2.23.2 6 / 8
2.23.1 6 / 8
2.23.0 6 / 8
2.22.1 6 / 8
2.22.0 6 / 8
2.21.2 6 / 8
2.21.1 6 / 8
2.21.0 6 / 8
2.20.5 6 / 8
2.20.4 6 / 8
2.20.3 6 / 8
2.20.2 6 / 8
2.20.1 6 / 8
2.20.0 6 / 8
2.19.4 6 / 8
2.19.3 6 / 8
2.19.2 6 / 8
2.19.1 6 / 8
2.19.0 6 / 8
2.18.2 6 / 8
2.18.1 6 / 8
2.18.0 6 / 8
2.17.2 6 / 8
2.17.1 6 / 8
2.17.0 6 / 8
2.16.3 6 / 10
2.16.2 6 / 10
2.16.1 6 / 10
2.16.0 6 / 10
2.15.5 6 / 10
2.15.4 6 / 10
2.15.3 6 / 10
2.15.2 6 / 10
2.14.1 6 / 6
2.13.8 6 / 6
2.13.7 6 / 6
2.12.0 6 / 6
2.10.1 6 / 6
2.4.2 6 / 3
2.4.1 6 / 3
1.24.29 6 / 2
1.24.28 6 / 2
1.24.27 6 / 2
1.24.26 6 / 2
1.24.25 6 / 2

v2.24.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.23.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.20.2

2 findings
HIGH New obfuscated file: dist/CalendarTemplate.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.20.1

2 findings
HIGH New obfuscated file: dist/CalendarTemplate.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.20.0

2 findings
HIGH New obfuscated file: dist/CalendarTemplate.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.19.3

2 findings
HIGH New obfuscated file: dist/CalendarTemplate.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.19.2

2 findings
HIGH New obfuscated file: dist/CalendarTemplate.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.19.1

2 findings
HIGH New obfuscated file: dist/CalendarTemplate.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.19.0

2 findings
HIGH New obfuscated file: dist/CalendarTemplate.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.18.1

2 findings
HIGH New obfuscated file: dist/CalendarTemplate.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.18.0

2 findings
HIGH New obfuscated file: dist/CalendarTemplate.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.17.1

2 findings
HIGH New obfuscated file: dist/CalendarTemplate.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.17.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.16.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.16.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.16.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.15.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.15.2

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ui5-webc-bot → GitHub Actions (on 2025-11-17, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ui5-webc-bot) on 2025-11-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.13.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.13.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.2

10 findings
HIGH New obfuscated file: dist/generated/templates/BreadcrumbsTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/templates/ComboBoxPopoverTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/templates/ComboBoxTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/templates/DatePickerTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/templates/DateRangePickerTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/templates/DateTimePickerTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/themes/FormLabelSpan.css.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/templates/ListTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ui5-webc-bot → GitHub Actions (on 2025-11-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ui5-webc-bot) on 2025-11-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.4.1

9 findings
HIGH New obfuscated file: dist/generated/templates/BreadcrumbsTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/templates/ComboBoxPopoverTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/templates/ComboBoxTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/templates/DatePickerTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/templates/DateRangePickerTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/templates/DateTimePickerTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/themes/FormLabelSpan.css.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/templates/ListTemplate.lit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.24.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.24.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.24.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.