@commercetools-frontend/eslint-config-mc-app
ESLint config used by Merchant Center customizations.
28
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
tdeekensemmenkocommercetools-admin
Keywords
javascriptfrontendreacttoolkiteslint
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@typescript-eslint/eslint-plugin | AI (phantom-deps): ESLint config packages reference plugins in config files, not code imports. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-prettier | AI (phantom-deps): ESLint config packages reference plugins in config files, not code imports. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/parser | AI (phantom-deps): ESLint config packages reference parsers in config files, not code imports. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react-hooks | AI (phantom-deps): ESLint config packages reference plugins in config files, not code imports. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-testing-library | AI (phantom-deps): ESLint config packages reference plugins in config files, not code imports. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-jest | AI (phantom-deps): ESLint config packages reference plugins in config files, not code imports. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react | AI (phantom-deps): ESLint config packages reference plugins in config files, not code imports. | ai | |
| phantom-deps | phantom-dep:@babel/eslint-parser | AI (phantom-deps): ESLint config packages reference parsers in config files, not code imports. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-import | AI (phantom-deps): ESLint config packages reference plugins in config files, not code imports. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-cypress | AI (phantom-deps): ESLint config packages reference plugins in config files, not code imports. | ai | |
| phantom-deps | phantom-dep:eslint-config-prettier | AI (phantom-deps): ESLint config packages reference configs in config files, not code imports. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-jest-dom | AI (phantom-deps): ESLint config packages reference plugins in config files, not code imports. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-jsx-a11y | AI (phantom-deps): ESLint config packages reference plugins in config files, not code imports. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Declared as runtime dep for @typescript-eslint integration; loaded by convention in ESLint configs. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped peer dep for @babel/eslint-parser; loaded by convention. | ai | |
| phantom-deps | phantom-dep:eslint-import-resolver-typescript | AI (phantom-deps): Referenced in ESLint config settings; not directly imported but used as resolver plugin. | ai | |
| phantom-deps | phantom-dep:prettier | AI (phantom-deps): Declared as runtime dep for eslint-plugin-prettier integration; not directly imported by JS but used by config. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 27.7.0 | 20 / 1 | |
| 27.6.3 | 20 / 1 | |
| 27.6.2 | 20 / 1 | |
| 27.6.1 | 20 / 1 | |
| 27.6.0 | 20 / 1 | |
| 27.5.4 | 20 / 1 | |
| 27.5.3 | 20 / 1 | |
| 27.5.2 | 20 / 1 | |
| 27.5.1 | 20 / 1 | |
| 27.5.0 | 20 / 1 | |
| 27.4.2 | 20 / 1 | |
| 27.4.1 | 20 / 1 | |
| 27.4.0 | 20 / 1 | |
| 27.3.0 | 20 / 1 | |
| 27.2.0 | 20 / 1 | |
| 27.1.0 | 20 / 1 | |
| 27.0.0 | 20 / 1 | |
| 26.1.0 | 20 / 1 | |
| 26.0.2 | 20 / 1 | |
| 26.0.1 | 20 / 1 | |
| 26.0.0 | 20 / 1 | |
| 25.2.0 | 20 / 1 | |
| 25.1.0 | 20 / 1 | |
| 25.0.0 | 20 / 1 | |
| 24.13.0 | 20 / 1 | |
| 24.12.0 | 20 / 1 | |
| 24.11.0 | 20 / 1 | |
| 24.10.0 | 20 / 1 |
v27.7.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.