All @camunda/linting versions

@camunda/linting @3.49.0

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
43
Risk Score
MIT
License
No
Install Scripts
12
Dependencies
21
Dev Dependencies
16.8 KB
Package Size
Published

Linting for Camunda

Maintainers

nikkubarmacmaxtruphilippfrommebarinalijarekdanielakalekseymanetovsimon-steinruecken-camunda

Keywords

bpmnlintcamunda

Dependencies (12)

PackageConstraintRegistry Status
clsx ^2.0.0 auto_approved
min-dom ^5.2.0 auto_approved
bpmnlint ^11.12.1 auto_approved
min-dash ^5.0.0 auto_approved
bpmn-moddle ^10.0.0 auto_approved
bpmnlint-utils ^1.0.2 auto_approved
modeler-moddle ^0.2.0 auto_approved
semver-compare ^1.0.0 auto_approved
zeebe-bpmn-moddle ^1.13.0 auto_approved
camunda-bpmn-moddle ^7.0.1 auto_approved
@bpmn-io/diagram-js-ui ^0.2.3 auto_approved
bpmnlint-plugin-camunda-compat ^2.49.2 auto_approved

Dev Dependencies (21)

PackageConstraintRegistry Status
chai ^4.5.0 auto_approved
karma ^6.4.4 auto_approved
mocha ^11.7.1 auto_approved
sinon ^17.0.1 auto_approved
eslint ^8.57.1 auto_approved
bpmn-js ^18.14.0 auto_approved
webpack ^5.101.2 auto_approved
cross-env ^7.0.3 auto_approved
puppeteer ^24.16.2 auto_approved
sinon-chai ^3.7.0 auto_approved
karma-mocha ^2.0.1 auto_approved
karma-webpack ^5.0.1 auto_approved
karma-sinon-chai ^2.0.2 Not imported
karma-debug-launcher 0.0.5 Not imported
eslint-plugin-bpmn-io ^1.0.1 Not imported
karma-env-preprocessor ^0.1.1 Not imported
karma-chrome-launcher-2 ^3.3.0 auto_approved
bpmn-js-properties-panel ^5.54.0 auto_approved
bpmn-js-element-templates ^2.23.1 auto_approved
camunda-bpmn-js-behaviors ^1.14.1 auto_approved
mocha-test-container-support ^0.2.0 Not imported

Transitive Dependency Tree

41 transitive deps max depth 6
  ├─ @bpmn-io/diagram-js-ui ^0.2.3 → 0.2.4
  ├─ bpmn-moddle ^10.0.0 → 10.0.0
  ├─ bpmnlint ^11.12.1 → 11.12.1
  ├─ bpmnlint-plugin-camunda-compat ^2.49.2 → 2.52.0
  ├─ bpmnlint-utils ^1.0.2 → 1.1.1
  ├─ camunda-bpmn-moddle ^7.0.1 → 7.0.1
  ├─ clsx ^2.0.0 → 2.1.1
  ├─ min-dash ^5.0.0 → 5.0.0
  ├─ min-dom ^5.2.0 → 5.3.0
  ├─ modeler-moddle ^0.2.0 → 0.2.0
  ├─ semver-compare ^1.0.0 → 1.0.0
├─ zeebe-bpmn-moddle ^1.13.0 → 1.14.0
  ├─ @bpmn-io/feel-lint ^3.1.0 → 3.1.0
  ├─ @bpmn-io/moddle-utils ^0.3.0 → 0.3.0
  ├─ @camunda/feel-builtins ^1.0.0 → 1.2.0
  ├─ ansi-colors ^4.1.3 → 4.1.3
  ├─ bpmn-moddle ^10.0.0 → 10.0.0
  ├─ bpmnlint-utils ^1.1.1 → 1.1.1
  ├─ bpmnlint-utils ^1.1.1
  ├─ cli-table ^0.3.11 → 0.3.11
  ├─ color-support ^1.1.3 → 1.1.3
  ├─ domify ^3.0.0
  ├─ htm ^3.1.1 → 3.1.1
  ├─ min-dash ^5.0.0 → 5.0.0
  ├─ moddle ^8.0.0 → 8.1.0
  ├─ moddle-xml ^12.0.0 → 12.0.0
  ├─ mri ^1.2.0 → 1.2.0
  ├─ pluralize ^8.0.0 → 8.0.0
  ├─ preact ^10.29.2 → 10.29.2
  ├─ semver-compare ^1.0.0 → 1.0.0
├─ tiny-glob ^0.2.9 → 0.2.9
  ├─ @bpmn-io/lezer-feel ^2.1.0
  ├─ @codemirror/language ^6.12.1 → 6.12.3
  ├─ colors 1.0.3 → 1.0.3
  ├─ globalyzer 0.1.0 → 0.1.0
  ├─ globrex ^0.1.2 → 0.1.2
  ├─ min-dash ^5.0.0 → 5.0.0
  ├─ moddle ^8.0.0 → 8.1.0
  ├─ moddle-xml ^12.0.0 → 12.0.0
├─ saxen ^11.0.2
  ├─ @codemirror/state ^6.0.0 → 6.6.0
  ├─ @codemirror/view ^6.23.0 → 6.43.1
  ├─ @lezer/common ^1.5.0 → 1.5.2
  ├─ @lezer/highlight ^1.0.0 → 1.2.3
  ├─ @lezer/lr ^1.0.0 → 1.4.10
  ├─ min-dash ^5.0.0 → 5.0.0
  ├─ saxen ^11.0.2
├─ style-mod ^4.0.0
  ├─ @codemirror/state ^6.6.0 → 6.6.0
  ├─ @lezer/common ^1.3.0 → 1.5.2
  ├─ @lezer/common ^1.0.0 → 1.5.2
  ├─ @marijn/find-cluster-break ^1.0.0 → 1.0.2
  ├─ crelt ^1.0.6 → 1.0.6
  ├─ style-mod ^4.1.0 → 4.1.3
├─ w3c-keyname ^2.2.4 → 2.2.8
  ├─ @marijn/find-cluster-break ^1.0.0 → 1.0.2

Risk Dispositions (1 applicable to this version, 0 other)

Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.

Rule Source Disposition Author Reason
bogus-package bogus-package reject AI AI (bogus-package): SPAM-FLAGGED publisher with 20 rejections; empty entry point indicates account compromise or malicious intent.

SAST Findings (1)

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

Review Summary

Risk score: 43. Findings: 1 critical (+40), 1 low (+3), 2 info (+0).

Commit: 993df60ae8c4 Browse source

Published to npm: