Installations
npm install @ui5/cli
Developer Guide
Typescript
No
Module System
ESM
Min. Node Version
^20.11.0 || >=22.0.0
Node Version
20.11.0
NPM Version
10.2.4
Score
65.5
Supply Chain
67.3
Quality
93.1
Maintenance
100
Vulnerability
94.3
License
Releases
Contributors
Unable to fetch Contributors
Languages
JavaScript (99.12%)
Shell (0.81%)
Dockerfile (0.07%)
Developer
Download Statistics
Total Downloads
11,408,623
Last Day
19,595
Last Week
82,889
Last Month
358,361
Last Year
4,249,281
GitHub Statistics
101 Stars
1,290 Commits
22 Forks
21 Watching
11 Branches
606 Contributors
Package Meta Information
Latest Version
4.0.13
Package Id
@ui5/cli@4.0.13
Unpacked Size
369.77 kB
Size
99.01 kB
File Count
31
NPM Version
10.2.4
Node Version
20.11.0
Publised On
22 Jan 2025
Total Downloads
Cumulative downloads
Total Downloads
11,408,623
Last day
-2%
19,595
Compared to previous day
Last week
-15.1%
82,889
Compared to previous week
Last month
3.7%
358,361
Compared to previous month
Last year
18.5%
4,249,281
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Dependencies
14
ui5-cli
ui5
Command Line Interface
Part of the UI5 Tooling
Documentation
UI5 CLI documentation can be found here: sap.github.io/ui5-tooling
Contributing
Please check our Contribution Guidelines.
Support
Please follow our Contribution Guidelines on how to report an issue.
Please report issues in the main UI5 Tooling repository.
Release History
See CHANGELOG.md. A consolidated changelog (including changes from the other UI5 Tooling modules) is available on the Releases tab.
No vulnerabilities found.
Reason
no dangerous workflow patterns detected
Reason
28 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Reason
no binaries found in the repo
Reason
0 existing vulnerabilities detected
Reason
license file detected
Details
- Info: project has a license file: LICENSE.txt:0
- Info: FSF or OSI recognized license: Apache License 2.0: LICENSE.txt:0
Reason
security policy file detected
Details
- Info: security policy file detected: github.com/SAP/.github/SECURITY.md:1
- Info: Found linked content: github.com/SAP/.github/SECURITY.md:1
- Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/SAP/.github/SECURITY.md:1
- Info: Found text in security policy: github.com/SAP/.github/SECURITY.md:1
Reason
SAST tool is run on all commits
Details
- Info: all commits (8) are checked with a SAST tool
Reason
dependency not pinned by hash detected -- score normalized to 1
Details
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/dependabot-auto-merge.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/SAP/ui5-cli/dependabot-auto-merge.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/github-ci.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/SAP/ui5-cli/github-ci.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/github-ci.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/SAP/ui5-cli/github-ci.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/github-ci.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/SAP/ui5-cli/github-ci.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reuse-compliance.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/SAP/ui5-cli/reuse-compliance.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/reuse-compliance.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/SAP/ui5-cli/reuse-compliance.yml/main?enable=pin
- Warn: containerImage not pinned by hash: test/e2e/Dockerfile:1: pin your Docker image by updating node:current-slim to node:current-slim@sha256:f817b97de45c6e8046441c5ecef2f1c4fe45d31c3d2052fe82058ebe50fe7a94
- Warn: npmCommand not pinned by hash: test/e2e/test.sh:9
- Warn: npmCommand not pinned by hash: test/e2e/test.sh:33
- Info: 0 out of 3 GitHub-owned GitHubAction dependencies pinned
- Info: 0 out of 3 third-party GitHubAction dependencies pinned
- Info: 1 out of 3 npmCommand dependencies pinned
- Info: 0 out of 1 containerImage dependencies pinned
Reason
Found 2/24 approved changesets -- score normalized to 0
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Warn: topLevel 'contents' permission set to 'write': .github/workflows/dependabot-auto-merge.yml:8
- Warn: no topLevel permission defined: .github/workflows/github-ci.yml:1
- Warn: no topLevel permission defined: .github/workflows/reuse-compliance.yml:1
- Info: no jobLevel write permissions found
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Score
6.3
/10
Last Scanned on 2025-01-27
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More