← Home

ui5-tooling-modules

UI5 CLI extensions to load and convert node modules as UI5 AMD-like modules

51
Versions
Apache-2.0
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

ui5-community-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): Well-known deps used directly by the reviewed postinstall logic. ai
source-diff net-exec-file:lib/polyfills.js AI (source-diff): Bundled polyfill-node shim providing browser XHR/fetch polyfills, not a loader/dropper. ai
source-diff source-size-tripled AI (source-diff): Size jump from bundling rollup-plugin-polyfill-node's polyfills, not injected payload. ai
dependencies unvetted-dep:handlebars AI (dependencies): Handlebars is a well-known templating library; stable dependency for this package across versions. ai
phantom-deps phantom-dep:@rollup/pluginutils AI (phantom-deps): @rollup/pluginutils is a listed runtime dependency in package.json; phantom-dep is a false positive here. ai
install-scripts install-script:postinstall AI (install-scripts): Long-standing postinstall for UI5 tooling setup; SLSA provenance confirms CI/CD origin. ai
bogus-package bogus-package AI (bogus-package): ui5-community-bot is a known automation publisher for the ui5-ecosystem-showcase monorepo; templated naming is expected. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require on pkgJsonPath is a package.json loader pattern, not arbitrary code execution. ai

Versions (showing 51 of 104)

View all versions
Version Deps Published
3.36.0 22 / 2
3.35.1 22 / 2
3.34.4 21 / 2
3.34.3 21 / 2
3.33.1 21 / 2
3.32.3 21 / 2
3.32.1 21 / 2
3.32.0 21 / 2
3.31.1 21 / 2
3.30.8 21 / 2
3.30.6 21 / 2
3.30.4 21 / 2
3.30.2 21 / 2
3.30.1 21 / 2
3.29.1 21 / 2
3.28.1 21 / 2
3.28.0 21 / 2
3.27.7 18 / 2
3.27.6 18 / 2
3.27.5 18 / 2
3.27.4 18 / 2
3.27.3 18 / 2
3.27.2 18 / 2
3.27.1 18 / 2
3.27.0 18 / 2
3.26.0 18 / 2
3.25.1 18 / 2
3.25.0 18 / 2
3.24.17 18 / 2
3.24.16 18 / 2
3.24.15 18 / 2
3.24.14 18 / 2
3.24.13 18 / 2
3.24.12 18 / 2
3.24.11 18 / 2
3.24.10 18 / 2
3.24.9 18 / 2
3.24.8 18 / 2
3.24.7 18 / 2
3.24.6 18 / 2
3.24.5 18 / 2
3.24.4 18 / 2
3.24.3 18 / 2
3.24.2 18 / 2
3.24.1 18 / 2
3.24.0 18 / 2
3.23.2 18 / 2
3.23.1 18 / 2
3.23.0 18 / 2
3.22.1 18 / 2
3.22.0 18 / 2

v3.34.3

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ui5-community-bot → GitHub Actions (on 2026-01-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ui5-community-bot) on 2026-01-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.28.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.28.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.27.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.27.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.27.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.25.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.23.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.23.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.22.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.