full-icu
3
Versions
—
License
Yes
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
rmgsrl295jcemmonsobensource
Keywords
icu4c
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Established nodejs-org package; long release gaps are normal for ICU data updates tied to Node.js release cycles. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall downloads ICU data files; documented and expected for this package. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): env-spread passes process.env + NODE_ICU_DATA to child process; not exfiltration, standard pattern for this tool. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used to spawn ICU install; core functionality of this package. | ai |
v1.0.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.