@formatjs/intl
Internationalize JS apps. This library provides an API to format dates, numbers, and strings, including pluralization and handling translations.
51
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
longlhoredonkuluspyrocat
Keywords
formatformattingglobalizationi18ninternationalizationintllocalelocalizationreact-intltranslatetranslation
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Established package with 3.1M weekly downloads and 2000+ day history; lack of provenance attestation is not a meaningful risk signal here. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard TypeScript runtime helper implicitly required by compiled output; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@formatjs/intl-listformat | AI (dependencies): First-party formatjs monorepo package published by the same trusted author (longlho); not a third-party risk. | ai | |
| dependencies | unvetted-dep:@formatjs/intl-displaynames | AI (dependencies): First-party formatjs monorepo package published by the same trusted author (longlho); not a third-party risk. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from individual (longlho) to GitHub Actions CI/CD with SLSA provenance. This is a legitimate and security-improving transition for the formatjs project. | ai | |
| dependencies | unvetted-dep:@formatjs/fast-memoize | AI (dependencies): @formatjs/fast-memoize is a first-party formatjs ecosystem package published by the same maintainer team in the same monorepo. | ai | |
| dependencies | unvetted-dep:@formatjs/icu-messageformat-parser | AI (dependencies): @formatjs/icu-messageformat-parser is a first-party formatjs ecosystem package published by the same maintainer team in the same monorepo. | ai | |
| dependencies | unvetted-dep:intl-messageformat | AI (dependencies): intl-messageformat is a first-party formatjs ecosystem package published by the same maintainer team in the same monorepo. | ai | |
| dependencies | unvetted-dep:@formatjs/ecma402-abstract | AI (dependencies): Sibling package in the same @formatjs monorepo (formatjs/formatjs); legitimate and well-known dependency used throughout the FormatJS ecosystem. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Package has 183 versions, 2070 days of history, and 3.1M weekly downloads. The inflated-semver signal is a false positive triggered by first review, not a new package. | ai |
Versions (showing 51 of 161)
| Version | Deps | Published |
|---|---|---|
| 4.1.17 | 3 / 0 | |
| 4.1.16 | 3 / 0 | |
| 4.1.15 | 3 / 0 | |
| 4.1.14 | 3 / 0 | |
| 4.1.13 | 3 / 0 | |
| 4.1.12 | 3 / 0 | |
| 4.1.11 | 3 / 0 | |
| 4.1.10 | 3 / 0 | |
| 4.1.9 | 3 / 0 | |
| 4.1.8 | 3 / 0 | |
| 4.1.7 | 3 / 0 | |
| 4.1.6 | 3 / 0 | |
| 4.1.5 | 4 / 0 | |
| 4.1.4 | 4 / 0 | |
| 4.1.3 | 4 / 0 | |
| 4.1.2 | 5 / 0 | |
| 4.1.1 | 5 / 0 | |
| 4.1.0 | 5 / 0 | |
| 4.0.9 | 5 / 0 | |
| 4.0.8 | 5 / 0 | |
| 4.0.7 | 5 / 0 | |
| 4.0.6 | 5 / 0 | |
| 4.0.5 | 5 / 0 | |
| 4.0.4 | 5 / 0 | |
| 4.0.2 | 5 / 0 | |
| 4.0.1 | 5 / 0 | |
| 4.0.0 | 5 / 0 | |
| 3.1.8 | 5 / 0 | |
| 3.1.7 | 5 / 0 | |
| 3.1.6 | 5 / 0 | |
| 3.1.5 | 5 / 0 | |
| 3.1.4 | 5 / 0 | |
| 3.1.3 | 5 / 0 | |
| 3.1.2 | 5 / 0 | |
| 3.1.1 | 5 / 0 | |
| 3.1.0 | 5 / 0 | |
| 3.0.4 | 5 / 0 | |
| 3.0.3 | 5 / 0 | |
| 3.0.2 | 5 / 0 | |
| 3.0.1 | 4 / 0 | |
| 3.0.0 | 5 / 0 | |
| 2.10.15 | 7 / 2 | |
| 2.10.14 | 7 / 2 | |
| 2.10.13 | 7 / 2 | |
| 2.10.12 | 7 / 2 | |
| 2.10.11 | 7 / 2 | |
| 2.10.10 | 7 / 2 | |
| 2.10.9 | 7 / 2 | |
| 2.10.8 | 7 / 2 | |
| 2.10.7 | 7 / 2 | |
| 2.10.6 | 7 / 2 |
v4.1.17
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.1.16
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.1.15
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.