@graphcommerce/eslint-config-pwa
4
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
paalesbramvanderholst
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@eslint/js | AI (phantom-deps): ESLint config package; plugins loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Peer/config dep for TypeScript ESLint integration; not directly imported. | ai | |
| phantom-deps | phantom-dep:@eslint/compat | AI (phantom-deps): ESLint config package; loaded by convention. | ai | |
| phantom-deps | phantom-dep:@eslint/eslintrc | AI (phantom-deps): ESLint config package; loaded by convention. | ai | |
| phantom-deps | phantom-dep:eslint-config-prettier | AI (phantom-deps): ESLint config package; referenced in config, not directly imported. | ai | |
| phantom-deps | phantom-dep:eslint-import-resolver-typescript | AI (phantom-deps): ESLint resolver; referenced in config, not directly imported. | ai | |
| phantom-deps | phantom-dep:@graphcommerce/typescript-config-pwa | AI (phantom-deps): Same-org sibling dep; expected pattern for this monorepo. | ai |