← Home

@formatjs/intl-relativetimeformat

Formats JavaScript dates to relative time strings.

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

longlhoredonkuluspyrocat

Keywords

dateformati18nintlmomentrelativetime

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance present; gitHead absence is a metadata quirk, not a supply-chain risk for this package. ai
source-diff obfuscated-file:lib/supported-locales.generated.js AI (source-diff): File is an auto-generated list of IETF locale tags on a single long line — standard pattern for i18n libraries, not obfuscation. Stable false positive for this package. ai
source-diff obfuscated-file:supported-locales.generated.js AI (source-diff): File is an auto-generated list of IETF locale tags on a single long line — standard pattern for i18n libraries, not obfuscation. Stable false positive for this package. ai
source-diff obfuscated-file:supported-locales.generated.ts AI (source-diff): Generated CLDR locale list file — long lines are locale code arrays, not obfuscation. Standard pattern for formatjs packages. ai
source-diff obfuscated-file:test262-main.ts AI (source-diff): Generated test262 locale data file with @generated header. Large JSON locale data injected via __addLocaleData — standard formatjs pattern, not malicious. ai
dependencies unvetted-dep:@formatjs/intl-localematcher AI (dependencies): @formatjs/intl-localematcher is a sibling package in the same FormatJS monorepo; its use here is expected and stable across versions. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a standard TypeScript runtime helper imported implicitly by compiled TS output; phantom-dep finding is a stable false positive for this package. ai
provenance publisher-changed AI (provenance): formatjs monorepo transitioned to GitHub Actions CI publishing; SLSA provenance attestation confirms builds originate from the official repo pipeline. Legitimate automation transition. ai
bogus-package bogus-package AI (bogus-package): This is a long-running package (2514 days, 210 versions) in the formatjs monorepo. Inflated semver and short README signals are false positives for this established ecosystem package. ai

Versions (showing 51 of 218)

View all versions
Version Deps Published
12.3.13 1 / 0
12.3.12 1 / 0
12.3.11 1 / 0
12.3.10 1 / 0
12.3.9 1 / 3
12.3.8 1 / 3
12.3.7 1 / 3
12.3.6 1 / 3
12.3.5 1 / 3
12.3.4 1 / 3
12.3.3 1 / 3
12.3.2 1 / 3
12.3.1 2 / 3
12.2.4 2 / 3
12.2.3 3 / 3
12.2.2 3 / 3
12.2.1 3 / 3
12.2.0 3 / 3
12.1.2 3 / 3
12.1.1 3 / 3
12.1.0 3 / 3
12.0.7 3 / 3
12.0.6 3 / 3
12.0.5 3 / 3
12.0.3 3 / 3
12.0.2 3 / 3
12.0.1 3 / 3
12.0.0 3 / 3
11.4.13 3 / 3
11.4.12 3 / 3
11.4.11 3 / 3
11.4.10 3 / 3
11.4.9 3 / 3
11.4.8 3 / 3
11.4.7 3 / 3
11.4.6 3 / 3
11.4.5 3 / 3
11.4.4 3 / 3
11.4.3 3 / 3
11.4.2 3 / 3
11.4.1 3 / 3
11.4.0 3 / 3
11.3.0 3 / 3
11.2.16 3 / 3
11.2.15 3 / 3
11.2.14 3 / 3
11.2.13 3 / 3
11.2.12 3 / 3
11.2.11 3 / 3
11.2.10 3 / 3
11.2.9 3 / 3

v12.3.13

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v12.3.12

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v12.3.11

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.