@shopgate/eslint-config
Eslint configuration for the Shopgate Connect projects.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are standard eslint/typescript plugins matching package's stated eslint-config purpose. | ai | |
| dependencies | unvetted-dep:eslint-import-resolver-exports | AI (dependencies): Standard ESLint import resolver plugin, no install scripts or exec. | ai | |
| dependencies | unvetted-dep:eslint-plugin-extra-rules | AI (dependencies): Standard eslint plugin dep, referenced via config not code. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-flowtype | AI (phantom-deps): Config-only reference pattern typical of eslint-config packages. | ai | |
| phantom-deps | phantom-dep:eslint-import-resolver-typescript | AI (phantom-deps): Config-only package; plugins referenced by name, not imported. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-jsdoc | AI (phantom-deps): Config-only package; plugins referenced by name, not imported. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/parser | AI (phantom-deps): Config-only package; plugins referenced by name, not imported. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/eslint-plugin | AI (phantom-deps): Config-only package; plugins referenced by name, not imported. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Shopgate org publisher with strong track record; maintainer rotation is routine for this package. | ai | |
| phantom-deps | phantom-dep:babel-eslint | AI (phantom-deps): ESLint config packages reference plugins via config files, not JS imports; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-tss-unused-classes | AI (phantom-deps): ESLint config packages reference plugins in config files, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-json | AI (phantom-deps): ESLint config packages reference plugins in config files, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-import-resolver-babel-module | AI (phantom-deps): ESLint config packages reference plugins in config files, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react | AI (phantom-deps): ESLint config packages reference plugins in config files, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-config-airbnb | AI (phantom-deps): ESLint config packages reference plugins in config files, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-import | AI (phantom-deps): ESLint config packages reference plugins in config files, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-cypress | AI (phantom-deps): ESLint config packages reference plugins in config files, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-jsx-a11y | AI (phantom-deps): ESLint config packages reference plugins in config files, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-extra-rules | AI (phantom-deps): ESLint config packages reference plugins in config files, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react-hooks | AI (phantom-deps): ESLint config packages reference plugins in config files, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-eslint-comments | AI (phantom-deps): ESLint config packages reference plugins in config files, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-import-resolver-exports | AI (phantom-deps): ESLint config packages reference plugins in config files, not via import; stable false positive for this package. | ai |
Versions (showing 53 of 53)
| Version | Deps | Published |
|---|---|---|
| 7.31.4 | 16 / 1 | |
| 7.31.3 | 16 / 1 | |
| 7.31.1 | 16 / 1 | |
| 7.31.0 | 16 / 1 | |
| 7.30.5 | 12 / 1 | |
| 7.30.4 | 12 / 1 | |
| 7.30.3 | 12 / 1 | |
| 7.30.2 | 12 / 1 | |
| 7.30.1 | 12 / 1 | |
| 7.30.0 | 12 / 1 | |
| 7.29.8 | 12 / 1 | |
| 7.29.7 | 12 / 1 | |
| 7.29.6 | 12 / 1 | |
| 7.29.5 | 12 / 1 | |
| 7.29.4 | 12 / 1 | |
| 7.29.3 | 12 / 1 | |
| 7.28.3 | 12 / 1 | |
| 7.28.0 | 12 / 1 | |
| 7.27.4 | 12 / 1 | |
| 7.26.0 | 12 / 1 | |
| 7.25.0 | 12 / 1 | |
| 7.24.7 | 12 / 1 | |
| 7.24.6 | 12 / 1 | |
| 7.24.5 | 12 / 1 | |
| 7.24.4 | 12 / 1 | |
| 7.24.2 | 12 / 1 | |
| 7.24.1 | 12 / 1 | |
| 7.24.0 | 12 / 1 | |
| 7.23.10 | 12 / 1 | |
| 7.23.9 | 12 / 1 | |
| 7.23.8 | 12 / 1 | |
| 7.23.7 | 12 / 1 | |
| 7.23.6 | 12 / 1 | |
| 7.23.5 | 12 / 1 | |
| 7.23.4 | 12 / 1 | |
| 7.23.3 | 12 / 1 | |
| 7.23.2 | 12 / 1 | |
| 7.23.1 | 12 / 1 | |
| 7.23.0 | 12 / 1 | |
| 7.22.0 | 12 / 1 | |
| 7.21.2 | 12 / 1 | |
| 7.21.1 | 12 / 1 | |
| 7.21.0 | 12 / 1 | |
| 7.20.3 | 12 / 1 | |
| 7.20.2 | 12 / 1 | |
| 7.20.1 | 12 / 1 | |
| 7.20.0 | 12 / 1 | |
| 7.12.9 | 12 / 1 | |
| 7.12.8 | 12 / 1 | |
| 7.12.7 | 12 / 1 | |
| 7.12.6 | 12 / 1 | |
| 7.12.5 | 12 / 1 | |
| 7.12.4 | 12 / 1 |
v7.31.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.31.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.31.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.31.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.30.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.30.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.30.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.29.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.28.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.27.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.26.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.25.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.24.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.24.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.24.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.24.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.24.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.24.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.24.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.23.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.23.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.23.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.23.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.23.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.23.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.23.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.23.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.23.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.23.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.23.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.22.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.21.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.21.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.21.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.20.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.20.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.20.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.20.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.12.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.12.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.12.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.12.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.12.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.12.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.