← Home

unicode-segmenter

42
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

cometkim

Keywords

unicodeuax29text-segmentationgraphemegrapheme-clusteremojiintlpolyfill

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file-transition:_general_table.js AI (source-diff): Generated Unicode range table; long lines are data. ai
source-diff obfuscated-file-transition:_grapheme_table.cjs AI (source-diff): Generated grapheme category table; data not obfuscation. ai
source-diff obfuscated-file-transition:_general_table.cjs AI (source-diff): Generated Unicode range table (JSON.parse of numeric arrays); long lines are data not obfuscation. ai
source-diff obfuscated-file-transition:src/_grapheme_table.js AI (source-diff): Source grapheme table generated by scripts/unicode.py; data not obfuscation. ai
source-diff obfuscated-file-transition:src/_general_table.js AI (source-diff): Source Unicode table generated by scripts/unicode.py; data not obfuscation. ai
source-diff obfuscated-file-transition:_grapheme_table.js AI (source-diff): Generated grapheme category table; data not obfuscation. ai
bogus-package bogus-package AI (bogus-package): Tiny/empty metadata is consistent with a root placeholder version, not spam, given publisher track record. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Established package with 40 versions and trusted publisher; 0.0.0 is a placeholder, not a throwaway. ai
source-diff obfuscated-file:_general_data.cjs AI (source-diff): Generated Unicode range data table; long lines are packed codepoint encoding, not obfuscation. ai
source-diff obfuscated-file:_general_data.js AI (source-diff): Generated Unicode data table per scripts/unicode.js; benign packed data. ai
source-diff obfuscated-file:_grapheme_data.cjs AI (source-diff): Generated grapheme category data table; benign packed data. ai
source-diff obfuscated-file:_grapheme_data.js AI (source-diff): Generated grapheme data table per scripts/unicode.js; benign. ai
source-diff obfuscated-file:src/_general_data.js AI (source-diff): Generated Unicode source data table; benign packed data. ai
source-diff obfuscated-file:src/_grapheme_data.js AI (source-diff): Generated grapheme source data table; benign packed data. ai
source-diff encoded-string-file:_emoji_data.cjs AI (source-diff): Generated Unicode Emoji property table, not a payload. ai
npm-metadata url-dep:unicode-segmentation-wasm AI (npm-metadata): devDependency to author's own repo, build-time only, not shipped. ai
source-diff encoded-string-file:_general_data.cjs AI (source-diff): Generated Unicode Letter/Numeric property table. ai
source-diff encoded-string-file:_general_data.js AI (source-diff): Generated Unicode property table. ai
source-diff encoded-string-file:_grapheme_data.d.ts AI (source-diff): Generated grapheme-break property tables. ai
source-diff encoded-string-file:_emoji_data.js AI (source-diff): Generated Unicode Emoji property table. ai
source-diff obfuscated-file:bundle/intl-adapter.js AI (source-diff): Bundle file is esbuild output with readable source comments; long lines are base-36 encoded Unicode range tables, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:bundle/index.js AI (source-diff): Bundle file is esbuild output with readable source comments; long lines are base-36 encoded Unicode range tables, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:bundle/grapheme.js AI (source-diff): Bundle file is esbuild output with readable source comments; long lines are base-36 encoded Unicode range tables, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:bundle/general.js AI (source-diff): Bundle file is esbuild output with readable source comments; long lines are base-36 encoded Unicode range tables, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:bundle/intl-polyfill.js AI (source-diff): Bundle file is esbuild output with readable source comments; long lines are base-36 encoded Unicode range tables, not obfuscation. Stable pattern for this package. ai
source-diff encoded-string-file:_grapheme_data.js AI (source-diff): Same as _grapheme_data.cjs: legitimate Unicode table encoding, not a malicious payload. Stable false positive for this package. ai
source-diff encoded-string-file:_grapheme_data.cjs AI (source-diff): The long string is a compact run-length encoding of Unicode grapheme category ranges passed to decodeUnicodeData(). This is the package's documented data format, not obfuscation. ai

Versions (showing 42 of 42)

Version Deps Published
0.17.2 0 / 28
0.17.1 0 / 28
0.17.0 0 / 28
0.16.0 0 / 28
0.15.0 0 / 27
0.14.5 0 / 27
0.14.4 0 / 27
0.14.3 0 / 27
0.14.2 0 / 27
0.14.1 0 / 27
0.14.0 0 / 28
0.13.2 0 / 26
0.13.1 0 / 26
0.13.0 0 / 26
0.12.0 0 / 26
0.11.3 0 / 25
0.11.2 0 / 22
0.11.1 0 / 21
0.11.0 0 / 21
0.10.1 0 / 22
0.10.0 0 / 23
0.9.2 0 / 23
0.9.1 0 / 20
0.9.0 0 / 20
0.8.0 0 / 18
0.7.0 0 / 18
0.6.1 0 / 18
0.6.0 0 / 18
0.5.0 0 / 14
0.4.0 0 / 14
0.3.2 0 / 14
0.3.1 0 / 14
0.3.0 0 / 14
0.2.0 0 / 12
0.1.6 0 / 10
0.1.5 0 / 10
0.1.4 0 / 10
0.1.3 0 / 9
0.1.2 0 / 8
0.1.1 0 / 8
0.1.0 0 / 8
0.0.0 0 / 0

v0.17.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.0

7 findings
HIGH SHA-pinned github dependency (devDependencies): unicode-segmentation-wasm npm-metadata

Dependency 'unicode-segmentation-wasm' in `devDependencies` points to 'github:cometkim/unicode-segmentation-wasm#230eb74d320ea2f31f95b74ddb2567186d496587' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.

HIGH Long encoded string in modified file: _emoji_data.cjs source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _emoji_data.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _general_data.cjs source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _general_data.js source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _grapheme_data.d.ts source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.0

5 findings
HIGH New obfuscated file: _general_data.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _general_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _grapheme_data.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _grapheme_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.3

5 findings
HIGH New obfuscated file: _general_data.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _general_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _grapheme_data.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _grapheme_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.2

7 findings
HIGH New obfuscated file: _general_data.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _general_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _grapheme_data.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _grapheme_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/_general_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/_grapheme_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.1

7 findings
HIGH New obfuscated file: _general_data.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _general_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _grapheme_data.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _grapheme_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/_general_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/_grapheme_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.0

7 findings
HIGH New obfuscated file: _general_data.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _general_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _grapheme_data.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _grapheme_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/_general_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/_grapheme_data.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.0

7 findings
HIGH Modified file became obfuscated: _general_table.cjs source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: _general_table.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: _grapheme_table.cjs source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: _grapheme_table.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: src/_general_table.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: src/_grapheme_table.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.