← Home

@ui5/webcomponents-tools

UI5 Web Components: webcomponents.tools

39
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

sap-ospo-adminui5-bot

Keywords

openui5sapui5ui5

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): SAP org consolidation to sap-ospo-admin; SLSA provenance confirms CI/CD publish pipeline integrity. ai
dependencies unvetted-dep:cypress-real-events AI (dependencies): Standard Cypress testing plugin; consistent with this build-tools package's test infrastructure. ai
phantom-deps phantom-dep:eslint-plugin-cypress AI (phantom-deps): Config-file reference pattern typical for this build-tools package. ai
phantom-deps phantom-dep:command-line-args AI (phantom-deps): Config-file reference pattern typical for this build-tools package. ai
dependencies unvetted-dep:@cypress/code-coverage AI (dependencies): Standard Cypress code coverage plugin; consistent with this build-tools package's test infrastructure. ai
maintainer-change maintainer-added AI (maintainer-change): ui5-bot addition is consistent with SAP's automation pipeline for this long-running package. ai
publish-pattern dormant-publish AI (publish-pattern): Package has 673 versions; dormancy signal is a false positive for this actively maintained SAP package. ai
provenance publisher-changed AI (provenance): Publisher change reflects CI/CD automation (GitHub Actions) for a well-established SAP/UI5 package with SLSA attestation. ai
source-diff large-new-source-files AI (source-diff): Major version bump (v1→v2) naturally adds many source files; SLSA provenance confirms CI/CD origin. ai
publish-pattern new-deps-added AI (publish-pattern): Major version bump with legitimate build tooling refactor; new deps are well-known utilities. ai
dependencies unvetted-dep:chokidar-cli AI (dependencies): Well-known file-watcher CLI; expected dev/build tooling dependency. ai
dependencies unvetted-dep:handlebars AI (dependencies): Established templating library; standard dependency for UI5 tooling across many versions. ai
phantom-deps phantom-dep:wdio-chromedriver-service AI (phantom-deps): Referenced in shipped WDIO config files; stable false positive. ai
phantom-deps phantom-dep:resolve AI (phantom-deps): Tooling package ships config files referencing deps not directly imported; stable pattern across versions. ai
phantom-deps phantom-dep:is-port-reachable AI (phantom-deps): Same tooling config pattern; stable false positive for this package. ai
phantom-deps phantom-dep:eslint-plugin-import AI (phantom-deps): ESLint plugin referenced in shipped config files; stable false positive. ai
phantom-deps phantom-dep:vite-plugin-istanbul AI (phantom-deps): Referenced in shipped config files; stable false positive for this tooling package. ai
phantom-deps phantom-dep:@typescript-eslint/parser AI (phantom-deps): Referenced in shipped ESLint config files; stable false positive. ai
phantom-deps phantom-dep:eslint-config-airbnb-base AI (phantom-deps): Referenced in shipped ESLint config files; stable false positive. ai
phantom-deps phantom-dep:@wdio/static-server-service AI (phantom-deps): Referenced in shipped WDIO config files; stable false positive. ai
phantom-deps phantom-dep:@typescript-eslint/eslint-plugin AI (phantom-deps): Referenced in shipped ESLint config files; stable false positive. ai
phantom-deps phantom-dep:@custom-elements-manifest/analyzer AI (phantom-deps): Referenced in shipped config files; stable false positive for this tooling package. ai
phantom-deps phantom-dep:eslint-plugin-jsx-no-leaked-values AI (phantom-deps): Referenced in shipped ESLint config files; stable false positive. ai
phantom-deps phantom-dep:cross-env AI (phantom-deps): CLI tool used in scripts; not directly imported in JS. ai
phantom-deps phantom-dep:postcss-cli AI (phantom-deps): CLI tool used in scripts; not directly imported in JS. ai
phantom-deps phantom-dep:eslint AI (phantom-deps): Config-referenced tool; stable false positive for this tooling package. ai
phantom-deps phantom-dep:mkdirp AI (phantom-deps): CLI tool used in scripts; not directly imported in JS. ai
phantom-deps phantom-dep:slash AI (phantom-deps): Utility referenced in config files; stable false positive. ai
phantom-deps phantom-dep:rimraf AI (phantom-deps): CLI tool used in scripts; not directly imported in JS. ai
phantom-deps phantom-dep:concurrently AI (phantom-deps): CLI tool used in scripts; not directly imported in JS. ai
phantom-deps phantom-dep:chokidar-cli AI (phantom-deps): CLI tool used in scripts; not directly imported in JS. ai
phantom-deps phantom-dep:nps AI (phantom-deps): CLI tool dependency referenced in config files; stable false positive for this tooling package. ai
phantom-deps phantom-dep:@wdio/mocha-framework AI (phantom-deps): Test runner plugin; referenced in config, not directly imported. ai
phantom-deps phantom-dep:chai AI (phantom-deps): Test framework referenced in config; not directly imported in main code. ai
phantom-deps phantom-dep:json-beautify AI (phantom-deps): Referenced in config/scripts; stable false positive for this tooling package. ai
phantom-deps phantom-dep:esprima AI (phantom-deps): Referenced in config files; stable false positive for this tooling package. ai
phantom-deps phantom-dep:escodegen AI (phantom-deps): Referenced in config files; stable false positive for this tooling package. ai
phantom-deps phantom-dep:@wdio/cli AI (phantom-deps): Test runner CLI; referenced in config, not directly imported. ai
phantom-deps phantom-dep:@wdio/dot-reporter AI (phantom-deps): Test runner plugin; referenced in config, not directly imported. ai
phantom-deps phantom-dep:@wdio/local-runner AI (phantom-deps): Test runner plugin; referenced in config, not directly imported. ai
phantom-deps phantom-dep:@wdio/spec-reporter AI (phantom-deps): Test runner plugin; referenced in config, not directly imported. ai
semgrep semgrep:child-process-import AI (semgrep): Build/dev tooling package; child_process use is core to its purpose of running build commands. ai
semgrep semgrep:env-spread AI (semgrep): Build tool passing env to child processes is standard; merges process.env with explicit envs for subprocess execution. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads user-defined package scripts by resolved path — standard plugin/script-runner pattern for this build tool. ai

Versions (showing 39 of 39)

Version Deps Published
2.23.3 45 / 2
2.22.0 45 / 2
2.21.2 45 / 2
2.21.1 45 / 2
2.21.0 45 / 2
2.19.4 45 / 2
2.18.2 45 / 2
2.17.2 45 / 2
2.16.2 47 / 2
2.16.0 47 / 2
2.15.5 47 / 2
2.15.2 47 / 2
2.10.0 47 / 2
2.9.0 47 / 2
2.8.0 52 / 4
2.7.5 52 / 4
2.7.4 52 / 4
2.7.3 52 / 4
2.7.2 52 / 4
2.7.1 52 / 4
2.7.0 52 / 4
2.6.3 49 / 4
2.6.2 48 / 4
2.6.1 48 / 4
2.6.0 48 / 4
2.5.3 48 / 4
2.5.2 48 / 4
2.5.1 48 / 4
2.5.0 48 / 4
2.4.0 48 / 4
2.3.0 48 / 4
2.2.0 48 / 4
2.1.2 47 / 4
2.1.1 47 / 4
2.1.0 47 / 4
2.0.1 47 / 4
2.0.0 47 / 4
1.24.29 46 / 2
1.24.27 46 / 2

v2.23.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.24.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.