← Home

@morev/stylelint-plugin

10
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

morev

Keywords

bemscssstylelintstylelint-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:postcss AI (phantom-deps): Runtime dependency for stylelint plugin; used indirectly through postcss-selector-parser. ai
phantom-deps phantom-dep:postcss-selector-parser AI (phantom-deps): Runtime dependency for BEM/SCSS rule implementation; stable across versions. ai
phantom-deps phantom-dep:valibot AI (phantom-deps): Runtime dependency for validation; used indirectly in plugin logic. ai
phantom-deps phantom-dep:@morev/utils AI (phantom-deps): Same-org scoped dependency; stable pattern for this publisher. ai

Versions (showing 10 of 10)

Version Deps Published
0.6.1 5 / 23
0.6.0 5 / 23
0.5.0 4 / 23
0.4.0 4 / 23
0.3.1 4 / 23
0.3.0 4 / 21
0.2.0 4 / 21
0.1.2 4 / 21
0.1.1 4 / 21
0.1.0 4 / 21

v0.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.