wink-nlp-utils
NLP Functions for amplifying negations, managing elisions, creating ngrams, stems, phonetic codes to tokens and more.
1
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
sanjayar4chn4prtksxna
Keywords
TokenizeStemNGramsBag of WordsPhonetizeSoundexStop WordsSentence BreakingRegexNLPNatural Language Processing
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:wink-tokenizer | AI (phantom-deps): wink-tokenizer is a sibling winkjs package listed as a runtime dependency; phantom detection is a packaging quirk, not a security concern for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established package (3270 days old) from a known publisher; lack of Sigstore provenance is expected for packages predating the feature. | ai |
Versions (showing 1 of 1)
| Version | Deps | Published |
|---|---|---|
| 2.1.0 | 6 / 8 |
v2.1.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.