@intlayer/config
Retrieve Intlayer configurations and manage environment variables for both server-side and client-side environments.
30
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
ay.pineau
Keywords
intlayerlayerabstractiondatainternationalizationi18ntypescriptjavascriptjsonfile
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Package has never had provenance attestation; consistent across versions. | ai | |
| source-diff | obfuscated-file:dist/cjs/configFile/configurationSchema.cjs | AI (source-diff): Minified rolldown build output; content is readable zod schema definitions, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/cjs/utils/cacheMemory.cjs | AI (source-diff): Minified rolldown build output; content is a cache/hashing utility using node:crypto, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/esm/configFile/configurationSchema.mjs | AI (source-diff): Minified rolldown build output; ESM equivalent of the CJS schema file, clearly legitimate. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Declared runtime dep used in config merging; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:json5 | AI (phantom-deps): Declared runtime dep for JSON5 config file parsing; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Declared runtime dep for env file loading; phantom-dep heuristic false positive. | ai | |
| source-diff | obfuscated-file:dist/esm/utils/cacheMemory.mjs | AI (source-diff): Minified rolldown build output; ESM equivalent of the CJS cache utility, clearly legitimate. | ai | |
| provenance | missing-githead | AI (provenance): Active monorepo with frequent releases; gitHead absence likely reflects a CI pipeline change, not a supply-chain risk. | ai |
Versions (showing 30 of 130)
| Version | Deps | Published |
|---|---|---|
| 7.3.11 | 4 / 8 | |
| 7.3.10 | 4 / 8 | |
| 7.3.9 | 4 / 8 | |
| 7.3.8 | 4 / 8 | |
| 7.3.7 | 4 / 8 | |
| 7.3.6 | 4 / 8 | |
| 7.3.5 | 4 / 8 | |
| 7.3.4 | 4 / 8 | |
| 7.3.3 | 4 / 8 | |
| 7.3.2 | 4 / 8 | |
| 7.3.1 | 4 / 8 | |
| 7.3.0 | 4 / 8 | |
| 7.2.3 | 4 / 8 | |
| 7.2.2 | 4 / 8 | |
| 7.2.0 | 4 / 8 | |
| 7.1.9 | 4 / 8 | |
| 7.1.8 | 4 / 8 | |
| 7.1.7 | 4 / 8 | |
| 7.1.6 | 4 / 8 | |
| 7.1.5 | 4 / 8 | |
| 7.1.4 | 4 / 8 | |
| 7.1.3 | 4 / 8 | |
| 7.1.2 | 4 / 8 | |
| 7.1.1 | 4 / 8 | |
| 7.1.0 | 4 / 8 | |
| 7.0.8 | 4 / 8 | |
| 7.0.7 | 4 / 8 | |
| 7.0.6 | 4 / 8 | |
| 7.0.5 | 4 / 8 | |
| 7.0.4 | 4 / 8 |