← Home

@formatjs/ecma402-abstract

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

longlhoredonkuluspyrocat

Keywords

abstractecma262ecma402esformati18nintljavascriptrelative

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:NumberFormat/digit-mapping.generated.ts AI (source-diff): This is a generated Unicode digit mapping table for ECMA-402 NumberFormat — long lines are dense Unicode data, not obfuscation. Expected content for an i18n library. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a standard TypeScript runtime helper dependency; phantom-dep detection is a known false positive for this pattern. ai
source-diff source-size-tripled AI (source-diff): Size growth is consistent with expanding ECMA-402 spec implementation in this well-established formatjs package; no obfuscation or payload indicators present. ai
source-diff large-new-source-files AI (source-diff): formatjs/ecma402-abstract regularly expands spec coverage and locale data; large file additions are expected for this i18n library across versions. ai
source-diff obfuscated-file:NumberFormat/digit-mapping.generated.js AI (source-diff): CJS build of the same generated Unicode digit mapping table. Long lines are Unicode character literals in a data export, not obfuscation. Expected for this i18n package. ai
source-diff obfuscated-file:lib/NumberFormat/digit-mapping.generated.js AI (source-diff): Generated Unicode digit mapping table for ECMA-402 NumberFormat. Long lines are Unicode character literals in a data export, not obfuscation. Expected for this i18n package. ai
publish-pattern new-deps-added AI (publish-pattern): tslib is a standard Microsoft TypeScript runtime helper; its addition is a routine, benign change for TypeScript-compiled packages in the formatjs ecosystem. ai
provenance publisher-changed AI (provenance): formatjs/formatjs uses GitHub Actions for automated publishing with SLSA provenance attestation; the longlho→GitHub Actions transition is a legitimate CI/CD migration, not a compromise. ai

Versions (showing 51 of 94)

View all versions
Version Deps Published
3.2.0 3 / 0
3.1.2 3 / 0
3.1.1 4 / 0
3.1.0 4 / 0
3.0.8 4 / 0
3.0.7 4 / 0
3.0.6 4 / 0
3.0.5 4 / 0
3.0.4 4 / 0
3.0.3 4 / 0
3.0.2 4 / 0
3.0.1 4 / 0
3.0.0 4 / 0
2.3.6 4 / 0
2.3.5 4 / 0
2.3.4 4 / 0
2.3.3 4 / 0
2.3.2 4 / 0
2.3.1 4 / 0
2.3.0 4 / 0
2.2.5 3 / 0
2.2.4 3 / 0
2.2.3 3 / 0
2.2.2 3 / 0
2.2.1 3 / 0
2.2.0 3 / 0
2.1.0 3 / 0
2.0.0 2 / 0
1.18.3 2 / 0
1.18.2 2 / 0
1.18.1 2 / 0
1.18.0 2 / 0
1.17.4 2 / 0
1.17.3 2 / 0
1.17.2 2 / 0
1.17.1 2 / 0
1.17.0 2 / 0
1.16.0 2 / 0
1.15.0 2 / 0
1.14.3 2 / 0
1.14.2 2 / 0
1.14.0 2 / 0
1.13.0 2 / 0
1.12.0 2 / 0
1.11.10 2 / 0
1.11.9 2 / 0
1.11.8 2 / 0
1.11.7 2 / 0
1.11.6 2 / 0
1.11.4 2 / 0
1.11.3 2 / 0