ui5-tooling-modules
UI5 CLI extensions to load and convert node modules as UI5 AMD-like modules
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): Well-known deps used directly by the reviewed postinstall logic. | ai | |
| source-diff | net-exec-file:lib/polyfills.js | AI (source-diff): Bundled polyfill-node shim providing browser XHR/fetch polyfills, not a loader/dropper. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size jump from bundling rollup-plugin-polyfill-node's polyfills, not injected payload. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): Handlebars is a well-known templating library; stable dependency for this package across versions. | ai | |
| phantom-deps | phantom-dep:@rollup/pluginutils | AI (phantom-deps): @rollup/pluginutils is a listed runtime dependency in package.json; phantom-dep is a false positive here. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Long-standing postinstall for UI5 tooling setup; SLSA provenance confirms CI/CD origin. | ai | |
| bogus-package | bogus-package | AI (bogus-package): ui5-community-bot is a known automation publisher for the ui5-ecosystem-showcase monorepo; templated naming is expected. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require on pkgJsonPath is a package.json loader pattern, not arbitrary code execution. | ai |
Versions (showing 51 of 104)
| Version | Deps | Published |
|---|---|---|
| 3.36.0 | 22 / 2 | |
| 3.35.1 | 22 / 2 | |
| 3.34.4 | 21 / 2 | |
| 3.34.3 | 21 / 2 | |
| 3.33.1 | 21 / 2 | |
| 3.32.3 | 21 / 2 | |
| 3.32.1 | 21 / 2 | |
| 3.32.0 | 21 / 2 | |
| 3.31.1 | 21 / 2 | |
| 3.30.8 | 21 / 2 | |
| 3.30.6 | 21 / 2 | |
| 3.30.4 | 21 / 2 | |
| 3.30.2 | 21 / 2 | |
| 3.30.1 | 21 / 2 | |
| 3.29.1 | 21 / 2 | |
| 3.28.1 | 21 / 2 | |
| 3.28.0 | 21 / 2 | |
| 3.27.7 | 18 / 2 | |
| 3.27.6 | 18 / 2 | |
| 3.27.5 | 18 / 2 | |
| 3.27.4 | 18 / 2 | |
| 3.27.3 | 18 / 2 | |
| 3.27.2 | 18 / 2 | |
| 3.27.1 | 18 / 2 | |
| 3.27.0 | 18 / 2 | |
| 3.26.0 | 18 / 2 | |
| 3.25.1 | 18 / 2 | |
| 3.25.0 | 18 / 2 | |
| 3.24.17 | 18 / 2 | |
| 3.24.16 | 18 / 2 | |
| 3.24.15 | 18 / 2 | |
| 3.24.14 | 18 / 2 | |
| 3.24.13 | 18 / 2 | |
| 3.24.12 | 18 / 2 | |
| 3.24.11 | 18 / 2 | |
| 3.24.10 | 18 / 2 | |
| 3.24.9 | 18 / 2 | |
| 3.24.8 | 18 / 2 | |
| 3.24.7 | 18 / 2 | |
| 3.24.6 | 18 / 2 | |
| 3.24.5 | 18 / 2 | |
| 3.24.4 | 18 / 2 | |
| 3.24.3 | 18 / 2 | |
| 3.24.2 | 18 / 2 | |
| 3.24.1 | 18 / 2 | |
| 3.24.0 | 18 / 2 | |
| 3.23.2 | 18 / 2 | |
| 3.23.1 | 18 / 2 | |
| 3.23.0 | 18 / 2 | |
| 3.22.1 | 18 / 2 | |
| 3.22.0 | 18 / 2 |
v3.34.3
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ui5-community-bot) on 2026-01-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v3.28.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.27.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.27.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.27.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.25.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.23.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.23.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.22.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.