← Home

cjk-conv

convert chinese, japanese 簡繁日漢字轉換 ( merge/split submodule from node-novel, regexp-cjk, str-util )

1
Versions
ISC
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

bluelovers

Keywords

charcharactercharacterschinesecjkcjk-convregexp-cjkcncn2twconvconversionconvertgreedyhanjahanzijapanesejp2zhsjp2zhtkanjinode-novelregexregexpregularregular expressionsimplifiedslugifystr-utiltabletraditionaltransformtwtw2cnunicodeutilwordszhzh-cnzh-twzh2jpzhszht

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:uni-string AI (dependencies): Stable dependency of this CJK utility package; same publisher ecosystem, no malware indicators. ai
dependencies unvetted-dep:@lazy-cjk/util AI (dependencies): Internal @lazy-cjk scoped dep from same author; stable pattern across versions. ai
dependencies unvetted-dep:@lazy-cjk/zh-convert AI (dependencies): Internal @lazy-cjk scoped dep from same author; stable pattern across versions. ai
dependencies unvetted-dep:@lazy-cjk/zh-slugify AI (dependencies): Internal @lazy-cjk scoped dep from same author; stable pattern across versions. ai
dependencies unvetted-dep:@lazy-cjk/zh-table-list AI (dependencies): Internal @lazy-cjk scoped dep from same author; stable pattern across versions. ai
dependencies unvetted-dep:@lazy-cjk/jp-table-alias AI (dependencies): Internal @lazy-cjk scoped dep from same author; stable pattern across versions. ai
dependencies unvetted-dep:@lazy-cjk/jp-table-voice AI (dependencies): Internal @lazy-cjk scoped dep from same author; stable pattern across versions. ai
dependencies unvetted-dep:@lazy-cjk/novel-filename AI (dependencies): Internal @lazy-cjk scoped dep from same author; stable pattern across versions. ai
dependencies unvetted-dep:@lazy-cjk/zh-table-alias AI (dependencies): Internal @lazy-cjk scoped dep from same author; stable pattern across versions. ai
dependencies unvetted-dep:@lazy-cjk/zh-table-greedy AI (dependencies): Internal @lazy-cjk scoped dep from same author; stable pattern across versions. ai
dependencies unvetted-dep:@lazy-cjk/jp-table-convert AI (dependencies): Internal @lazy-cjk scoped dep from same author; stable pattern across versions. ai
dependencies unvetted-dep:@lazy-cjk/zh-convert-table AI (dependencies): Internal @lazy-cjk scoped dep from same author; stable pattern across versions. ai
provenance no-provenance AI (provenance): Long-established package predating Sigstore provenance; consistent with publisher's other packages. ai

Versions (showing 1 of 1)

Version Deps Published
1.2.150 14 / 0

v1.2.150

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.