@alexlit/config-eslint
Sharable ESLint configuration
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:eslint | AI (phantom-deps): ESLint is a peer/config dependency referenced in config files, not directly imported — expected pattern for ESLint config packages. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Long-lived package with 868 versions and clean diff; dormancy pattern consistent with periodic batch releases. | ai | |
| dependencies | unvetted-dep:eslint-plugin-vitest | AI (dependencies): eslint-plugin-vitest is a well-known ESLint plugin for Vitest; stable false positive for this config package. | ai | |
| dependencies | unvetted-dep:@vitest/eslint-plugin | AI (dependencies): Official Vitest ESLint plugin; expected dependency for this ESLint config package. | ai | |
| dependencies | unvetted-dep:@unocss/eslint-config | AI (dependencies): Well-known UnoCSS ESLint plugin; stable dependency for this ESLint config package. | ai | |
| dependencies | unvetted-dep:@intlify/eslint-plugin-vue-i18n | AI (dependencies): Official intlify Vue i18n ESLint plugin; expected dependency for this ESLint config package. | ai | |
| provenance | no-provenance | AI (provenance): Long-lived package with 868 versions; no provenance has been a stable characteristic, not a new regression. | ai | |
| phantom-deps | phantom-dep:yaml-eslint-parser | AI (phantom-deps): Parser referenced in ESLint config rules, not imported directly; stable false positive. | ai | |
| phantom-deps | phantom-dep:jsonc-eslint-parser | AI (phantom-deps): Parser referenced in ESLint config rules, not imported directly; stable false positive. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): ESLint config packages reference typescript via config, not direct import; stable false positive. | ai |
Versions (showing 51 of 68)
| Version | Deps | Published |
|---|---|---|
| 151.4.0 | 25 / 1 | |
| 151.3.2 | 25 / 1 | |
| 151.3.1 | 25 / 1 | |
| 151.3.0 | 25 / 1 | |
| 151.2.0 | 25 / 1 | |
| 151.1.0 | 25 / 1 | |
| 151.0.1 | 25 / 1 | |
| 151.0.0 | 25 / 1 | |
| 150.1.0 | 24 / 1 | |
| 150.0.1 | 24 / 1 | |
| 150.0.0 | 24 / 1 | |
| 149.3.0 | 24 / 1 | |
| 149.2.1 | 24 / 1 | |
| 149.2.0 | 24 / 1 | |
| 149.1.0 | 24 / 1 | |
| 149.0.0 | 24 / 1 | |
| 148.0.2 | 24 / 1 | |
| 148.0.1 | 24 / 1 | |
| 148.0.0 | 24 / 1 | |
| 147.1.1 | 24 / 1 | |
| 147.1.0 | 24 / 1 | |
| 147.0.2 | 24 / 1 | |
| 147.0.1 | 24 / 1 | |
| 147.0.0 | 24 / 1 | |
| 146.1.1 | 24 / 1 | |
| 146.1.0 | 24 / 1 | |
| 146.0.1 | 24 / 1 | |
| 146.0.0 | 24 / 1 | |
| 145.0.0 | 24 / 0 | |
| 144.0.0 | 24 / 0 | |
| 143.1.0 | 23 / 0 | |
| 143.0.2 | 23 / 0 | |
| 143.0.1 | 23 / 0 | |
| 143.0.0 | 23 / 0 | |
| 142.0.1 | 23 / 0 | |
| 142.0.0 | 23 / 0 | |
| 141.1.0 | 23 / 0 | |
| 141.0.0 | 23 / 0 | |
| 140.0.0 | 23 / 0 | |
| 139.3.0 | 23 / 0 | |
| 139.2.2 | 23 / 0 | |
| 139.2.1 | 23 / 0 | |
| 139.2.0 | 23 / 0 | |
| 139.1.1 | 23 / 0 | |
| 139.1.0 | 23 / 0 | |
| 139.0.0 | 23 / 0 | |
| 138.9.1 | 23 / 0 | |
| 138.9.0 | 23 / 0 | |
| 138.8.5 | 23 / 0 | |
| 138.8.4 | 23 / 0 | |
| 138.8.3 | 23 / 0 |
v151.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v151.3.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v151.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v151.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v151.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v151.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v151.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v151.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v150.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v150.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v150.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v149.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v149.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v149.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v149.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v149.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v148.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v148.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v148.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v147.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v147.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v139.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v139.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v139.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v138.9.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v138.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v138.8.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v138.8.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v138.8.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.