@2digits/oxlint-config
Minimal Oxlint config for 2digits projects.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/base-CMyOHmYR.mjs | AI (source-diff): Minified bundled config output, not true obfuscation; content is readable eslint config. | ai | |
| source-diff | obfuscated-file:dist/typescript-BXv5LB73.mjs | AI (source-diff): Minified build output, same as sibling file; no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/base-DRnTUBjM.mjs | AI (source-diff): Minified build output from vp pack --minify, not obfuscation; content is plain config data. | ai | |
| source-diff | obfuscated-file:dist/base-DCb68CkS.mjs | AI (source-diff): Minified build output from documented minify script, not obfuscation; no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/base-D_QHacx5.mjs | AI (source-diff): Minified build output from vp pack --minify, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/typescript-NUhH312y.mjs | AI (source-diff): Minified build output from vp pack --minify, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/typescript-CC7miX6k.mjs | AI (source-diff): Same minified build output pattern as base config file. | ai | |
| source-diff | obfuscated-file:dist/base-BSySiG3o.mjs | AI (source-diff): Minified build output from vp pack --minify, not obfuscation; content is plain config objects. | ai | |
| source-diff | obfuscated-file:dist/typescript-ChAHtxWD.mjs | AI (source-diff): Minified bundler output for config values, not obfuscation; matches build script. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-zod | AI (phantom-deps): Referenced only via string specifier for plugin resolution in minified config output. | ai | |
| dependencies | unvetted-dep:@oxlint-types/define-config | AI (dependencies): Config-builder helper used directly in source, consistent with package purpose. | ai | |
| source-diff | obfuscated-file:dist/base-BcgSuGNh.mjs | AI (source-diff): Minified bundler output for config values, not obfuscation; matches build script. | ai | |
| source-diff | obfuscated-file:dist/typescript-DfbtfaAy.mjs | AI (source-diff): Same minified build artifact pattern; content is ESLint/TypeScript config rules, not malicious code. | ai | |
| source-diff | obfuscated-file:dist/base-BARFyOjH.mjs | AI (source-diff): Minified ESM output from vp pack --minify; content is plainly readable ESLint config rules, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/base-VU2GwQZ2.mjs | AI (source-diff): Minified ESM build output from vite-plus --minify; content is plainly readable ESLint rule config, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/base-vN2IXLZC.mjs | AI (source-diff): Minified ESM build output from vite-plus; content is readable linting config, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/typescript-JohfbQYF.mjs | AI (source-diff): Same minified ESM build pattern; content is readable TypeScript/React linting config. | ai | |
| source-diff | obfuscated-file:dist/base-BWpaMSn8.mjs | AI (source-diff): Minified ESM bundle from documented `vp pack --minify` build; content is plaintext ESLint rule config, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/typescript-8FIHWB16.mjs | AI (source-diff): Same minified ESM bundle pattern; content is readable ESLint/React rule config, not obfuscated. | ai | |
| dependencies | unvetted-dep:eslint-plugin-react-compiler | AI (dependencies): RC dep used as a linting plugin in a config package; no code execution risk beyond lint tooling. | ai | |
| source-diff | obfuscated-file:dist/typescript-DfLVHeOZ.mjs | AI (source-diff): Minified build artifact from documented vite-plus bundler; content is plaintext ESLint config rules, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/typescript-_a50A5d0.mjs | AI (source-diff): Same as above; minified TypeScript lint rule config, no obfuscation or malicious payload. | ai | |
| source-diff | obfuscated-file:dist/base-CubgQYkc.mjs | AI (source-diff): Minified ESM bundle from documented `vp pack --minify` build step; content is readable lint rule config. | ai | |
| source-diff | obfuscated-file:dist/base-C5gwW2B4.mjs | AI (source-diff): Minified bundle output from vite-plus --minify; content is plaintext ESLint rule config, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/typescript-O3-OTkkO.mjs | AI (source-diff): Same as above — minified linting config bundle, no suspicious payload. | ai | |
| source-diff | obfuscated-file:dist/typescript-DTWkDXOd.mjs | AI (source-diff): Same as above — minified build output with readable lint rule config content. | ai | |
| source-diff | obfuscated-file:dist/base-Dj4ykcw8.mjs | AI (source-diff): Minified ESM bundle from vite-plus --minify; content is plainly readable lint rule config, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/base-DMlZWXG4.mjs | AI (source-diff): Minified build output of oxlint rule config; content is plainly readable ESLint/oxlint rules, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/typescript-ln2RdhN7.mjs | AI (source-diff): Minified build output of TypeScript oxlint rule config; no malicious content. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Config package re-exports/uses deps without direct JS imports; stable pattern for this package type. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react-compiler | AI (phantom-deps): ESLint plugin referenced in config files, not direct JS imports; expected for config packages. | ai | |
| phantom-deps | phantom-dep:@stylistic/eslint-plugin | AI (phantom-deps): ESLint plugin referenced in config files, not direct JS imports; expected for config packages. | ai | |
| phantom-deps | phantom-dep:@2digits/constants | AI (phantom-deps): Same-org dep used in config files, not direct JS imports; expected pattern. | ai |
Versions (showing 24 of 24)
| Version | Deps | Published |
|---|---|---|
| 0.6.16 | 6 / 10 | |
| 0.6.15 | 4 / 10 | |
| 0.6.14 | 4 / 10 | |
| 0.6.13 | 4 / 10 | |
| 0.6.12 | 4 / 10 | |
| 0.6.11 | 4 / 10 | |
| 0.6.10 | 4 / 10 | |
| 0.6.9 | 4 / 10 | |
| 0.6.8 | 4 / 10 | |
| 0.6.7 | 4 / 10 | |
| 0.6.6 | 4 / 10 | |
| 0.6.5 | 4 / 11 | |
| 0.6.4 | 4 / 11 | |
| 0.6.3 | 4 / 11 | |
| 0.6.2 | 4 / 11 | |
| 0.6.1 | 4 / 11 | |
| 0.6.0 | 4 / 11 | |
| 0.5.0 | 4 / 11 | |
| 0.4.0 | 2 / 11 | |
| 0.3.0 | 2 / 11 | |
| 0.2.0 | 2 / 11 | |
| 0.1.1 | 1 / 11 | |
| 0.1.0 | 1 / 11 | |
| 0.0.1 | 1 / 11 |
v0.6.16
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.15
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.14
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.13
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.12
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.11
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.