← Home

@lingui/macro

24
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

andrii.bodnarserhiydmytryshyn

Keywords

babel-plugin-macrosi18ninternationalizationi10nlocalizationi9ntranslationmultilingual

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publisher with SLSA attestation; legitimate automation, not a compromise. ai

Versions (showing 24 of 24)

Version Deps Published
5.9.5 2 / 0
5.9.4 2 / 0
5.9.3 2 / 0
5.9.2 2 / 0
5.9.1 2 / 0
5.9.0 2 / 0
5.8.0 2 / 0
5.7.0 2 / 0
5.6.1 2 / 0
5.6.0 2 / 0
5.5.2 2 / 0
5.5.1 2 / 0
5.5.0 2 / 0
5.4.1 2 / 0
5.4.0 2 / 0
5.3.3 2 / 0
5.3.2 2 / 0
5.3.1 2 / 0
5.3.0 2 / 0
5.2.0 2 / 0
5.1.2 2 / 0
5.1.1 2 / 0
5.1.0 2 / 0
5.0.0 2 / 0

v5.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.