@lingui/conf
Resolve and validate Lingui configuration
42
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
andrii.bodnarserhiydmytryshyn
Keywords
linguilingui-configconfigurationi18nschemavalidation
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from named maintainer to GitHub Actions is a documented CI/CD automation pattern for the js-lingui monorepo; SLSA provenance attestation confirms legitimate workflow origin. | ai | |
| phantom-deps | phantom-dep:lodash.get | AI (phantom-deps): lodash.get is declared in dependencies and legitimately used; phantom-dep rule is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): @babel/runtime is a framework-scoped package loaded by Babel convention; correctly declared in dependencies and not a real phantom-dep issue. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @lingui/conf is a scoped package in the official Lingui i18n monorepo; the Levenshtein match to 'cors' is a false positive with no plausible impersonation intent. | ai | |
| dependencies | unvetted-dep:jiti | AI (dependencies): jiti is a well-known TypeScript/ESM loader used widely in build tooling; its use in a config resolution package is appropriate and expected. | ai |
Versions (showing 42 of 42)
| Version | Deps | Published |
|---|---|---|
| 6.6.0 | 4 / 5 | |
| 6.5.0 | 4 / 5 | |
| 6.4.0 | 4 / 5 | |
| 6.3.0 | 4 / 5 | |
| 6.2.0 | 4 / 5 | |
| 6.1.0 | 4 / 4 | |
| 6.0.1 | 4 / 4 | |
| 6.0.0 | 4 / 4 | |
| 5.9.5 | 5 / 2 | |
| 5.9.4 | 5 / 2 | |
| 5.9.3 | 5 / 2 | |
| 5.9.2 | 5 / 2 | |
| 5.9.1 | 5 / 2 | |
| 5.9.0 | 5 / 2 | |
| 5.8.0 | 5 / 2 | |
| 5.7.0 | 5 / 2 | |
| 5.6.1 | 5 / 2 | |
| 5.6.0 | 5 / 2 | |
| 5.5.2 | 5 / 2 | |
| 5.5.1 | 5 / 2 | |
| 5.5.0 | 5 / 2 | |
| 5.4.1 | 5 / 2 | |
| 5.4.0 | 5 / 2 | |
| 5.3.3 | 5 / 2 | |
| 5.3.2 | 5 / 2 | |
| 5.3.1 | 5 / 3 | |
| 5.3.0 | 6 / 3 | |
| 5.2.0 | 6 / 3 | |
| 5.1.2 | 6 / 3 | |
| 5.1.1 | 6 / 3 | |
| 5.1.0 | 6 / 3 | |
| 5.0.0 | 6 / 3 | |
| 4.14.1 | 6 / 3 | |
| 4.14.0 | 6 / 3 | |
| 4.13.0 | 6 / 3 | |
| 4.12.0 | 6 / 3 | |
| 4.11.4 | 6 / 3 | |
| 4.11.3 | 6 / 3 | |
| 4.11.2 | 6 / 3 | |
| 4.11.1 | 6 / 3 | |
| 4.11.0 | 6 / 3 | |
| 4.10.1 | 6 / 3 |
v6.6.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.5.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.