← Home

@lokalise/universal-ts-utils

Isomorphic general-purpose TS utils

18
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

bodrovismarcocardosolokbotlokalisekibertoadcarlos_gameroaplokalisefilippos.mikropoulosandrew_lokalisedariacmbezlydmitrycasamitjanabartoszdrozd-lokalisejhfedzerikapalillontrpilot-lokalise

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Lokalise org package; maintainer list cleanup within same org, not a takeover signal. ai
provenance missing-githead AI (provenance): SLSA provenance attestation present; missing gitHead is a minor env change, not a supply chain risk. ai
npm-metadata no-description AI (npm-metadata): Established package with clear repo and homepage; missing description is cosmetic. ai

Versions (showing 18 of 18)

Version Deps Published
4.11.0 0 / 7
4.10.0 0 / 7
4.9.0 0 / 7
4.8.0 0 / 7
4.7.0 0 / 7
4.6.0 0 / 7
4.5.1 0 / 7
4.5.0 0 / 7
4.4.1 0 / 7
4.4.0 0 / 7
4.3.0 0 / 7
4.2.3 0 / 7
4.2.2 0 / 6
4.2.1 0 / 6
4.2.0 0 / 6
4.1.1 0 / 6
4.1.0 0 / 6
4.0.0 0 / 6

v4.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.