← Home

@formatjs/intl-numberformat

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

longlhoredonkuluspyrocat

Keywords

Intl.NumberFormati18nintlnumberformatpolyfill

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Attested CI publish; gitHead omission is benign metadata, not a supply-chain signal. ai
phantom-deps phantom-dep:@formatjs/bigdecimal AI (phantom-deps): Same-org dep likely consumed transitively; stable pattern for this package. ai
source-diff obfuscated-file:locale-data/ar.js AI (source-diff): Auto-generated locale data file; long lines are structured JSON with human-readable i18n strings, not obfuscation. ai
source-diff large-new-source-files AI (source-diff): Large number of new files is expected for a locale data polyfill adding comprehensive locale coverage across hundreds of locales. ai
source-diff source-size-tripled AI (source-diff): Size increase is entirely due to addition of locale data files for all supported locales — expected behavior for this polyfill package. ai
source-diff obfuscated-file:locale-data/af-NA.js AI (source-diff): Auto-generated locale data files with single-line JSON are not obfuscated; this is the standard formatjs pattern for all locale-data/*.js files. ai
provenance no-provenance AI (provenance): Established formatjs package with strong publisher track record; lack of provenance attestation is a minor concern, not a security risk. ai
source-diff obfuscated-file:locale-data/af.js AI (source-diff): Auto-generated locale data file; long lines are structured JSON with human-readable i18n strings, not obfuscation. ai
provenance publisher-changed AI (provenance): formatjs/formatjs monorepo transitioned to GitHub Actions CI/CD publishing with SLSA provenance attestation — a legitimate and expected automation transition for this established org. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a known implicit TypeScript runtime dependency; stable false positive for this package. ai
phantom-deps phantom-dep:@formatjs/intl-localematcher AI (phantom-deps): Same-org sibling dependency used implicitly; stable false positive for this formatjs package. ai
bogus-package bogus-package AI (bogus-package): Empty index.js and short README are expected for this modular formatjs package which exposes functionality via named ESM exports, not a default entry point. ai
phantom-deps phantom-dep:decimal.js AI (phantom-deps): decimal.js is a legitimate dependency for arbitrary-precision arithmetic in this Intl.NumberFormat polyfill; used across polyfill entry points not fully traversed by the analyzer. ai

Versions (showing 51 of 74)

View all versions
Version Deps Published
9.3.14 2 / 0
9.3.13 2 / 0
9.3.12 2 / 0
9.3.11 2 / 0
9.3.10 2 / 3
9.3.9 2 / 3
9.3.8 2 / 3
9.3.7 2 / 3
9.3.4 2 / 3
9.3.3 2 / 3
9.3.2 2 / 3
9.3.1 3 / 3
9.2.4 3 / 3
9.2.3 4 / 3
9.2.2 4 / 3
9.2.1 4 / 3
9.2.0 4 / 3
9.1.2 4 / 3
9.1.1 4 / 3
9.1.0 4 / 3
9.0.7 4 / 3
9.0.6 4 / 3
9.0.5 4 / 3
9.0.3 4 / 3
9.0.2 4 / 3
9.0.1 4 / 3
9.0.0 4 / 3
8.15.6 4 / 3
8.15.5 4 / 3
8.15.4 4 / 3
8.15.3 4 / 3
8.15.2 4 / 3
8.15.1 4 / 3
8.15.0 4 / 3
8.14.6 3 / 3
8.14.5 3 / 3
8.14.4 3 / 3
8.14.3 3 / 3
8.14.2 3 / 3
8.14.1 3 / 3
8.14.0 3 / 3
8.13.0 3 / 3
8.12.0 3 / 3
8.11.0 3 / 3
8.10.3 3 / 3
8.10.2 3 / 3
8.10.1 3 / 3
8.10.0 3 / 3
8.9.2 3 / 3
8.9.1 3 / 3
8.9.0 3 / 3

v9.3.14

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v9.3.13

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v9.3.12

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.