@translate-local/tl
CLI-first translation tool with glossary enforcement and local models
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped translation CLI; no semantic or functional resemblance to 'pg'. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped translation CLI; no semantic or functional resemblance to 'qs'. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): CLI binary uses spawnSync to dispatch to platform-specific native binaries; expected pattern for this package. | ai |
v0.3.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.