cldr-core
Basic CLDR supplemental data
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): cldr-core is a legitimate Unicode Consortium CLDR data package. Templated sibling names, minimal README, no keywords, and no deps are all expected for a pure data distribution in the CLDR family. | ai | |
| license | uncommon-license:Unicode-3.0 | AI (license): Unicode-3.0 is the standard license for all Unicode/CLDR data packages; uncommon on npm but well-established and legitimate for this publisher. | ai |
Versions (showing 36 of 36)
| Version | Deps | Published |
|---|---|---|
| 48.2.0 | 0 / 0 | |
| 48.1.0 | 0 / 0 | |
| 48.0.0 | 0 / 0 | |
| 47.0.0 | 0 / 0 | |
| 46.1.0 | 0 / 0 | |
| 46.0.0 | 0 / 0 | |
| 45.0.0 | 0 / 0 | |
| 44.1.0 | 0 / 0 | |
| 44.0.1 | 0 / 0 | |
| 44.0.0 | 0 / 0 | |
| 43.1.0 | 0 / 0 | |
| 43.0.0 | 0 / 0 | |
| 42.0.0 | 0 / 0 | |
| 41.0.0 | 0 / 0 | |
| 40.0.0 | 0 / 0 | |
| 39.0.0 | 0 / 0 | |
| 38.1.0 | 0 / 0 | |
| 38.0.0 | 0 / 0 | |
| 37.0.0 | 0 / 0 | |
| 36.0.0 | 0 / 0 | |
| 35.1.0 | 0 / 0 | |
| 35.0.0 | 0 / 0 | |
| 34.0.0 | 0 / 0 | |
| 33.0.0 | 0 / 0 | |
| 32.0.0 | 0 / 0 | |
| 31.0.1 | 0 / 0 | |
| 31.0.0 | 0 / 0 | |
| 30.0.3 | 0 / 0 | |
| 30.0.2 | 0 / 0 | |
| 30.0.0 | 0 / 0 | |
| 29.0.0 | 0 / 0 | |
| 28.0.2 | 0 / 0 | |
| 28.0.0 | 0 / 0 | |
| 27.0.3 | 0 / 0 | |
| 27.0.1 | 0 / 0 | |
| 27.0.0 | 0 / 0 |
v48.2.0
2 findingsMatched 4 signal(s), weighted score 7: • [S_PUBLISHER_MASS_PRODUCTION] Maintainer 'srl295' owns 58 packages, ≥70% share a templated name shape. • [S_README_NO_CODE] Short README with no code block, no install instructions, and no usage/API section. • [S_NO_KEYWORDS] No keywords declared. • [S_NO_DEPS] No runtime, dev, peer, or optional dependencies declared.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v48.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v48.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.