← Home

@fenge/eslint-config

A super strict eslint config for linting js/ts/package.json.

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

zanminkian

Keywords

opinionatedstylestricteststricteslintconfigeslint-configstandard

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get used in a test assertion, not runtime evasion. ai
source-diff obfuscated-file:dist/config/ts/base.js AI (source-diff): Long-line compiled config code, not true obfuscation; no malicious behavior. ai
source-diff obfuscated-file:dist/config/js/base.js AI (source-diff): Long-line compiled config code, not true obfuscation; no malicious behavior. ai
source-diff obfuscated-file:dist/config/base.js AI (source-diff): Long-line compiled config code, not true obfuscation; no malicious behavior. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; consistent with legitimate automation adoption for this package. ai
dependencies unvetted-dep:@fenge/eslint-plugin-ts AI (dependencies): First-party plugin from same org/monorepo; consistent with package purpose. ai
dependencies unvetted-dep:@fenge/eslint-plugin AI (dependencies): First-party plugin from same org/monorepo; consistent with package purpose. ai
dependencies unvetted-dep:eslint-plugin-esm AI (dependencies): Standard eslint plugin dependency for a config package; no malware indicators. ai
dependencies unvetted-dep:eslint-plugin-fp AI (dependencies): Standard eslint plugin dependency for a config package; no malware indicators. ai
phantom-deps phantom-dep:@html-eslint/parser AI (phantom-deps): @html-eslint/parser is a declared runtime dep used by the eslint config at runtime, not imported directly in JS — stable false positive for this package. ai

Versions (showing 51 of 74)

View all versions
Version Deps Published
0.9.4 24 / 3
0.9.3 24 / 3
0.9.2 24 / 3
0.9.1 24 / 3
0.9.0 24 / 3
0.8.3 24 / 3
0.8.2 24 / 3
0.8.1 24 / 3
0.8.0 24 / 3
0.7.25 24 / 3
0.7.24 24 / 3
0.7.23 24 / 3
0.7.22 24 / 3
0.7.21 24 / 3
0.7.20 24 / 3
0.7.19 24 / 3
0.7.18 24 / 3
0.7.17 24 / 3
0.7.16 24 / 3
0.7.15 24 / 3
0.7.14 24 / 3
0.7.13 24 / 3
0.7.12 24 / 3
0.7.11 23 / 3
0.7.10 23 / 3
0.7.9 21 / 3
0.7.8 21 / 3
0.7.7 21 / 3
0.7.6 21 / 3
0.7.5 21 / 3
0.7.4 21 / 3
0.7.3 20 / 3
0.7.2 20 / 3
0.7.1 20 / 3
0.7.0 20 / 3
0.6.15 20 / 3
0.6.14 20 / 3
0.6.13 20 / 3
0.6.12 20 / 3
0.6.11 20 / 3
0.6.10 20 / 3
0.6.9 20 / 3
0.6.8 20 / 3
0.6.7 20 / 3
0.6.6 20 / 3
0.6.5 20 / 3
0.6.4 20 / 3
0.6.3 20 / 3
0.6.2 20 / 3
0.6.1 20 / 3
0.6.0 20 / 3

v0.6.8

4 findings
HIGH New obfuscated file: dist/config/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/js/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/ts/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.7

4 findings
HIGH New obfuscated file: dist/config/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/js/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/ts/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.6

4 findings
HIGH New obfuscated file: dist/config/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/js/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/ts/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.5

4 findings
HIGH New obfuscated file: dist/config/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/js/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/ts/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.4

4 findings
HIGH New obfuscated file: dist/config/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/js/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/ts/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.3

4 findings
HIGH New obfuscated file: dist/config/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/js/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/ts/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.2

4 findings
HIGH New obfuscated file: dist/config/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/js/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/ts/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.1

4 findings
HIGH New obfuscated file: dist/config/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/js/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/ts/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

4 findings
HIGH New obfuscated file: dist/config/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/js/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/config/ts/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.