← Home

@powerlines/plugin-eslint

A package containing a Powerlines plugin for running ESLint on the codebase.

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

eslintpowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/index.mjs AI (source-diff): dist/index.mjs is standard tsup-minified build output; code is readable and benign. SLSA provenance confirms CI/CD build pipeline. Stable false positive for this package. ai
provenance slsa-provenance AI (provenance): Package consistently publishes with SLSA provenance via Sigstore; strong supply chain integrity signal for this package. ai
provenance publisher-changed AI (provenance): Storm Software transitioned from stormie-bot to GitHub Actions CI publishing. SLSA provenance attestation confirms legitimate CI/CD pipeline. This transition is stable for the package going forward. ai
source-diff obfuscated-file:dist/index.cjs AI (source-diff): dist/index.cjs is standard tsup-bundled/minified CJS output for a build tool plugin. Long lines are a bundling artifact, not obfuscation. Content is readable and benign. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): Core framework dependency for powerlines plugin; used indirectly by plugin system. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): Utility dependency used indirectly by plugin framework; legitimate for this package's architecture. ai
phantom-deps phantom-dep:defu AI (phantom-deps): Plugin package; defu is a legitimate config utility dependency used indirectly by the plugin framework. ai
phantom-deps phantom-dep:eslint AI (phantom-deps): ESLint plugin; eslint is a peer/framework dependency used indirectly; standard pattern for ESLint plugins. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): Utility dependency used indirectly by plugin framework; legitimate for this package's architecture. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): Used in config files rather than direct imports; this is a known pattern for config-tools packages in monorepos. Not a security concern for this package. ai

Versions (showing 51 of 383)

View all versions
Version Deps Published
0.8.627 7 / 1
0.8.626 7 / 1
0.8.625 7 / 1
0.8.624 7 / 1
0.8.623 7 / 1
0.8.622 7 / 1
0.8.621 7 / 1
0.8.620 7 / 1
0.8.619 7 / 1
0.8.618 7 / 1
0.8.617 7 / 1
0.8.616 7 / 1
0.8.615 7 / 1
0.8.614 7 / 1
0.8.612 7 / 1
0.8.611 7 / 1
0.8.610 7 / 1
0.8.609 7 / 1
0.8.608 7 / 1
0.8.607 7 / 1
0.8.606 7 / 1
0.8.605 7 / 1
0.8.604 7 / 1
0.8.603 7 / 1
0.8.602 7 / 1
0.8.601 7 / 1
0.8.600 7 / 1
0.8.599 7 / 1
0.8.598 7 / 1
0.8.597 7 / 1
0.8.596 7 / 1
0.8.595 7 / 1
0.8.594 7 / 1
0.8.593 7 / 1
0.8.592 7 / 1
0.8.591 7 / 1
0.8.590 7 / 1
0.8.589 7 / 1
0.8.588 7 / 1
0.8.587 7 / 1
0.8.586 7 / 1
0.8.585 7 / 1
0.8.584 7 / 1
0.8.583 7 / 1
0.8.582 7 / 1
0.8.581 7 / 1
0.8.580 7 / 1
0.8.579 7 / 1
0.8.578 7 / 1
0.8.577 7 / 1
0.8.576 7 / 1

v0.8.627

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.626

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.625

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.624

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.623

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.622

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.621

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.620

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.619

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.618

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.617

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.616

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.615

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.614

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.612

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.611

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.610

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.609

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.608

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.607

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.606

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.605

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.