← Home

@alexlit/config-stylelint

Stylelint config

22
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

alex-lit

Keywords

stylelintconfig

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:stylelint-media-use-custom-media AI (dependencies): Stylelint plugin consistent with this config package's purpose. ai
dependencies unvetted-dep:stylelint-gamut AI (dependencies): Stylelint plugin consistent with this config package's purpose; no malicious indicators. ai
dependencies unvetted-dep:stylelint-use-nesting AI (dependencies): Stylelint plugin consistent with this config package's purpose. ai
dependencies unvetted-dep:stylelint-plugin-logical-css AI (dependencies): Stylelint plugin consistent with this config package's purpose. ai
dependencies unvetted-dep:stylelint-no-unresolved-module AI (dependencies): Stylelint plugin consistent with this config package's purpose. ai
dependencies unvetted-dep:stylelint-no-indistinguishable-colors AI (dependencies): Legitimate stylelint plugin dependency; stable pattern for this config package across many versions. ai
publish-pattern dormant-publish AI (publish-pattern): Long-lived config package with 355 versions and verified GitHub repo; gap likely reflects normal maintenance cadence. ai
dependencies unvetted-dep:@morev/stylelint-plugin AI (dependencies): Legitimate stylelint plugin consistent with this config package's purpose. ai
phantom-deps phantom-dep:stylelint-no-unsupported-browser-features AI (phantom-deps): Config-only package; plugins are referenced in config files, not imported directly. Stable pattern for this package. ai
phantom-deps phantom-dep:stylelint-declaration-block-no-ignored-properties AI (phantom-deps): Same config-only pattern; not a real phantom dep concern for this package. ai
phantom-deps phantom-dep:stylelint-no-nested-media AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-selector-no-empty AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:@double-great/stylelint-a11y AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-plugin-logical-css AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-config-standard-scss AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-config-recommended-vue AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-media-use-custom-media AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-high-performance-animation AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-no-indistinguishable-colors AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-no-unresolved-module AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:prettier AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:postcss-html AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-scss AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-gamut AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-order AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-prettier AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-use-nesting AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-color-format AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai
phantom-deps phantom-dep:stylelint-config-standard AI (phantom-deps): Config package; deps referenced in config files not via import — expected pattern. ai

Versions (showing 22 of 22)

Version Deps Published
60.15.0 23 / 0
60.14.1 23 / 0
60.14.0 23 / 0
60.13.4 23 / 0
60.13.3 23 / 0
60.13.2 23 / 0
60.13.1 24 / 0
60.13.0 24 / 0
60.12.2 24 / 0
60.12.1 24 / 0
60.12.0 24 / 0
60.11.0 24 / 0
60.10.0 24 / 0
60.9.3 24 / 0
60.9.2 24 / 0
60.9.1 24 / 0
60.9.0 24 / 0
60.8.1 24 / 0
60.6.0 24 / 0
60.0.0 24 / 0
56.5.0 23 / 0
56.2.0 23 / 0

v60.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.14.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.13.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.13.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.13.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.13.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.12.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.9.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v60.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v56.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v56.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.