@formatjs/intl
Internationalize JS apps. This library provides an API to format dates, numbers, and strings, including pluralization and handling translations.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Established package with 3.1M weekly downloads and 2000+ day history; lack of provenance attestation is not a meaningful risk signal here. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard TypeScript runtime helper implicitly required by compiled output; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@formatjs/intl-listformat | AI (dependencies): First-party formatjs monorepo package published by the same trusted author (longlho); not a third-party risk. | ai | |
| dependencies | unvetted-dep:@formatjs/intl-displaynames | AI (dependencies): First-party formatjs monorepo package published by the same trusted author (longlho); not a third-party risk. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from individual (longlho) to GitHub Actions CI/CD with SLSA provenance. This is a legitimate and security-improving transition for the formatjs project. | ai | |
| dependencies | unvetted-dep:@formatjs/fast-memoize | AI (dependencies): @formatjs/fast-memoize is a first-party formatjs ecosystem package published by the same maintainer team in the same monorepo. | ai | |
| dependencies | unvetted-dep:@formatjs/icu-messageformat-parser | AI (dependencies): @formatjs/icu-messageformat-parser is a first-party formatjs ecosystem package published by the same maintainer team in the same monorepo. | ai | |
| dependencies | unvetted-dep:intl-messageformat | AI (dependencies): intl-messageformat is a first-party formatjs ecosystem package published by the same maintainer team in the same monorepo. | ai | |
| dependencies | unvetted-dep:@formatjs/ecma402-abstract | AI (dependencies): Sibling package in the same @formatjs monorepo (formatjs/formatjs); legitimate and well-known dependency used throughout the FormatJS ecosystem. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Package has 183 versions, 2070 days of history, and 3.1M weekly downloads. The inflated-semver signal is a false positive triggered by first review, not a new package. | ai |
Versions (showing 56 of 156)
| Version | Deps | Published |
|---|---|---|
| 1.9.5 | 7 / 0 | |
| 1.9.4 | 7 / 0 | |
| 1.9.3 | 7 / 0 | |
| 1.9.2 | 7 / 0 | |
| 1.9.1 | 7 / 0 | |
| 1.9.0 | 7 / 0 | |
| 1.8.5 | 7 / 0 | |
| 1.8.4 | 7 / 0 | |
| 1.8.3 | 9 / 0 | |
| 1.8.2 | 9 / 0 | |
| 1.8.1 | 9 / 0 | |
| 1.8.0 | 9 / 0 | |
| 1.7.1 | 9 / 0 | |
| 1.7.0 | 9 / 0 | |
| 1.6.8 | 9 / 0 | |
| 1.6.7 | 9 / 0 | |
| 1.6.6 | 9 / 0 | |
| 1.6.5 | 9 / 0 | |
| 1.6.4 | 9 / 0 | |
| 1.6.3 | 9 / 0 | |
| 1.6.2 | 9 / 0 | |
| 1.6.1 | 9 / 0 | |
| 1.6.0 | 9 / 0 | |
| 1.5.1 | 9 / 0 | |
| 1.5.0 | 9 / 0 | |
| 1.4.16 | 9 / 0 | |
| 1.4.15 | 9 / 0 | |
| 1.4.14 | 9 / 0 | |
| 1.4.13 | 9 / 0 | |
| 1.4.12 | 9 / 0 | |
| 1.4.11 | 9 / 0 | |
| 1.4.10 | 9 / 0 | |
| 1.4.9 | 9 / 0 | |
| 1.4.8 | 9 / 0 | |
| 1.4.7 | 9 / 0 | |
| 1.4.6 | 9 / 0 | |
| 1.4.5 | 9 / 0 | |
| 1.4.4 | 9 / 0 | |
| 1.4.3 | 9 / 0 | |
| 1.4.2 | 9 / 0 | |
| 1.4.1 | 9 / 0 | |
| 1.4.0 | 9 / 0 | |
| 1.3.9 | 8 / 0 | |
| 1.3.8 | 8 / 0 | |
| 1.3.6 | 8 / 0 | |
| 1.3.5 | 8 / 0 | |
| 1.3.4 | 8 / 0 | |
| 1.3.3 | 7 / 0 | |
| 1.3.2 | 7 / 0 | |
| 1.3.1 | 7 / 0 | |
| 1.3.0 | 7 / 0 | |
| 1.2.2 | 7 / 0 | |
| 1.2.1 | 7 / 0 | |
| 1.2.0 | 9 / 0 | |
| 1.1.0 | 9 / 0 | |
| 1.0.0 | 9 / 0 |
v1.9.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.6.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.6.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.6.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.6.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.6.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.6.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.6.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.