← Home

iconv

Text recoding in JavaScript for fun and profit!

29
Versions
ISC
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

bnoordhuis

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): safer-buffer is a canonical, widely-trusted Buffer safety shim; its addition is a routine security improvement for native Node.js addon packages like iconv. ai
phantom-deps phantom-dep:nan AI (phantom-deps): nan is a compile-time C++ header dependency for native addons; it is not require()'d at runtime. This is the expected usage pattern for node-gyp-based packages. ai
install-scripts install-script:install AI (install-scripts): iconv is a native C addon; node-gyp rebuild is the standard and expected install script for compiling the binding. Stable for this package. ai
publish-pattern dormant-publish AI (publish-pattern): Publisher bnoordhuis is the original author with a 14+ year track record and 114 approved packages. Dormancy followed by a minor release is consistent with low-maintenance native addon upkeep, not a takeover. ai

Versions (showing 29 of 29)

Version Deps Published
3.0.1 0 / 0
2.3.5 2 / 0
2.3.2 2 / 0
2.3.1 2 / 0
2.2.2 1 / 1
2.1.11 1 / 1
2.1.10 1 / 1
2.1.8 1 / 1
2.1.7 1 / 1
2.1.3 1 / 1
2.1.1 1 / 1
2.1.0 1 / 1
2.0.7 0 / 0
2.0.5 0 / 0
2.0.4 0 / 0
2.0.3 0 / 0
2.0.1 0 / 0
2.0.0 0 / 0
1.2.4 0 / 0
1.2.3 0 / 0
1.2.2 0 / 0
1.2.1 0 / 0
1.2.0 0 / 0
1.1.3 0 / 0
1.1.2 0 / 0
1.1.1 0 / 0
1.1.0 0 / 0
1.0.1 0 / 0
1.0.0 0 / 0

v3.0.1

2 findings
HIGH Package has 'install' script install-scripts

Script: node-gyp rebuild

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.