← Home

@santi020k/eslint-config-optionals

3
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

santi020k

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:eslint-plugin-mdx AI (dependencies): Well-known ESLint plugin for MDX; appropriate dependency for an optional ESLint config package. ai
dependencies unvetted-dep:eslint-plugin-toml AI (dependencies): Well-known ESLint plugin for TOML; appropriate for optional ESLint config. ai
dependencies unvetted-dep:@cspell/eslint-plugin AI (dependencies): CSpell is a widely-used spell-checking ESLint plugin; appropriate dependency. ai
dependencies unvetted-dep:@vitest/eslint-plugin AI (dependencies): Official Vitest ESLint plugin; appropriate for optional testing config. ai
dependencies unvetted-dep:eslint-plugin-i18next AI (dependencies): Well-known i18next ESLint plugin; appropriate for optional ESLint config. ai
dependencies unvetted-dep:@graphql-eslint/eslint-plugin AI (dependencies): Official GraphQL ESLint plugin from The Guild; appropriate dependency. ai
dependencies unvetted-dep:@tanstack/eslint-plugin-router AI (dependencies): Official TanStack Router ESLint plugin; appropriate for optional config. ai
dependencies unvetted-dep:@stencil-community/eslint-plugin AI (dependencies): Stencil community ESLint plugin; appropriate for optional framework config. ai
dependencies unvetted-dep:eslint-plugin-better-tailwindcss AI (dependencies): Tailwind CSS ESLint plugin; appropriate for optional ESLint config. ai
dependencies unvetted-dep:@darraghor/eslint-plugin-nestjs-typed AI (dependencies): NestJS typed ESLint plugin; appropriate for optional framework config. ai
bogus-package bogus-package AI (bogus-package): ESLint config packages commonly have minimal READMEs and no keywords; not indicative of spam. ai

Versions (showing 3 of 3)

Version Deps Published
1.6.0 30 / 5
1.5.0 30 / 5
1.0.0 30 / 5

v1.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.