← Home

@comet/eslint-config

A set of ESLint configurations for Comet projects

44
Versions
BSD-2-Clause
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

kaufmofranzeldkarnutschnsamsmanuelblumvividplanetjohnnyomair

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:npm-run-all AI (phantom-deps): ESLint config package; plugins/tools declared as deps are loaded by convention, not direct import. ai
phantom-deps phantom-dep:eslint-plugin-react AI (phantom-deps): ESLint config package; plugins declared as deps loaded by ESLint convention. ai
phantom-deps phantom-dep:@comet/eslint-plugin AI (phantom-deps): Same-org plugin dependency; loaded by ESLint config convention. ai
phantom-deps phantom-dep:eslint-plugin-import AI (phantom-deps): ESLint config package; plugins declared as deps loaded by ESLint convention. ai
phantom-deps phantom-dep:eslint-config-prettier AI (phantom-deps): ESLint config package; plugins declared as deps loaded by ESLint convention. ai
phantom-deps phantom-dep:eslint-plugin-formatjs AI (phantom-deps): ESLint config package; plugins declared as deps loaded by ESLint convention. ai
phantom-deps phantom-dep:eslint-plugin-prettier AI (phantom-deps): ESLint config package; plugins declared as deps loaded by ESLint convention. ai
phantom-deps phantom-dep:@typescript-eslint/eslint-plugin AI (phantom-deps): ESLint config package; plugins declared as deps loaded by ESLint convention. ai
phantom-deps phantom-dep:eslint-plugin-simple-import-sort AI (phantom-deps): ESLint config package; plugins declared as deps loaded by ESLint convention. ai
phantom-deps phantom-dep:eslint-import-resolver-typescript AI (phantom-deps): ESLint config package; resolver declared as dep loaded by ESLint convention. ai
phantom-deps phantom-dep:eslint-plugin-json-files AI (phantom-deps): ESLint config package; plugins declared as deps loaded by ESLint convention. ai
phantom-deps phantom-dep:@typescript-eslint/parser AI (phantom-deps): ESLint config package; parser declared as dep loaded by ESLint convention. ai
phantom-deps phantom-dep:eslint-plugin-react-hooks AI (phantom-deps): ESLint config package; plugins declared as deps loaded by ESLint convention. ai
phantom-deps phantom-dep:eslint-plugin-unused-imports AI (phantom-deps): ESLint config package; plugins declared as deps loaded by ESLint convention. ai
phantom-deps phantom-dep:@calm/eslint-plugin-react-intl AI (phantom-deps): ESLint config package; plugins declared as deps loaded by ESLint convention. ai
phantom-deps phantom-dep:npm-run-all2 AI (phantom-deps): npm-run-all2 used in lint scripts; phantom-dep false positive for config packages. ai
phantom-deps phantom-dep:eslint-config-next AI (phantom-deps): ESLint config extends eslint-config-next; phantom-dep false positive for config packages. ai
phantom-deps phantom-dep:@next/eslint-plugin-next AI (phantom-deps): Framework-scoped plugin loaded by convention; phantom-dep false positive for config packages. ai

Versions (showing 44 of 44)

Version Deps Published
8.24.0 18 / 3
8.23.4 18 / 3
8.23.3 18 / 3
8.23.2 18 / 3
8.23.1 18 / 3
8.23.0 18 / 3
8.22.0 18 / 3
8.21.1 18 / 3
8.21.0 18 / 3
8.20.4 18 / 3
8.20.3 18 / 3
8.20.2 18 / 3
8.20.1 18 / 3
8.20.0 18 / 3
8.19.0 18 / 3
8.18.0 18 / 3
8.17.1 18 / 3
8.17.0 18 / 3
8.16.0 18 / 3
8.15.0 18 / 3
8.14.0 18 / 3
8.13.0 19 / 3
8.12.0 19 / 3
8.11.1 19 / 3
8.11.0 19 / 3
8.10.0 19 / 3
8.9.0 19 / 3
8.8.0 19 / 3
8.7.1 19 / 3
8.7.0 19 / 3
8.6.0 19 / 3
8.5.2 19 / 3
8.5.1 19 / 3
8.5.0 19 / 3
8.4.2 19 / 3
8.4.0 19 / 3
8.3.0 19 / 3
8.2.0 19 / 3
8.1.1 19 / 3
8.1.0 19 / 3
8.0.0 19 / 3
7.25.14 17 / 3
7.25.13 17 / 3
7.25.12 17 / 3

v8.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.23.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.23.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.23.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.23.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.21.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.20.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.20.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.20.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.20.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.17.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.25.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.25.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.25.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.