← Home

@friggframework/eslint-config

1
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

michael.webber.lefthooklefthooktomseanspeaks

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:eslint AI (phantom-deps): ESLint config packages reference plugins/parsers via config strings, not direct imports — stable FP for this package type. ai
phantom-deps phantom-dep:eslint-plugin-json AI (phantom-deps): Same pattern: eslint config references plugins by name in config, not via require(). ai
phantom-deps phantom-dep:eslint-plugin-yaml AI (phantom-deps): Same pattern: eslint config references plugins by name in config, not via require(). ai
phantom-deps phantom-dep:@babel/eslint-parser AI (phantom-deps): Same pattern: eslint config references parsers by name in config, not via require(). ai
phantom-deps phantom-dep:eslint-config-prettier AI (phantom-deps): Same pattern: eslint config extends other configs by name, not via require(). ai
phantom-deps phantom-dep:eslint-plugin-markdown AI (phantom-deps): Same pattern: eslint config references plugins by name in config, not via require(). ai
phantom-deps phantom-dep:eslint-plugin-no-only-tests AI (phantom-deps): Same pattern: eslint config references plugins by name in config, not via require(). ai

Versions (showing 1 of 1)

Version Deps Published
1.2.2 7 / 0