@storm-software/eslint-plugin-tsdoc
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/plugin-J8NsxKRJ.mjs | AI (source-diff): Rolldown bundle of explicitly declared inlinedDependencies; minified but not obfuscated or malicious. | ai | |
| source-diff | net-exec-file:dist/plugin-J8NsxKRJ.mjs | AI (source-diff): Network/exec pattern is from bundled resolver/module deps (resolve, is-core-module), not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/plugin-BxdznRU6.mjs | AI (source-diff): False positive on bundled ESLint plugin; no actual network+exec payload, just bundled module resolution helpers. | ai | |
| source-diff | obfuscated-file:dist/plugin-BxdznRU6.mjs | AI (source-diff): Rolldown bundle of inlined deps (@microsoft/tsdoc etc.); confirmed by inlinedDependencies field and SLSA provenance. | ai | |
| source-diff | net-exec-file:dist/plugin-BuKHlGry.mjs | AI (source-diff): Network/exec pattern is bundler boilerplate from rolldown runtime, not dropper malware. | ai | |
| source-diff | obfuscated-file:dist/plugin-BuKHlGry.mjs | AI (source-diff): Rolldown bundle inlining declared inlinedDependencies; readable commented code, not obfuscation. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase explained by bundling inlinedDependencies into the dist file. | ai | |
| phantom-deps | phantom-dep:function-bind | AI (phantom-deps): Transitive dep; declared explicitly. | ai | |
| phantom-deps | phantom-dep:is-core-module | AI (phantom-deps): Transitive dep of resolve; declared explicitly. | ai | |
| phantom-deps | phantom-dep:fast-deep-equal | AI (phantom-deps): Transitive dep of ajv; declared explicitly. | ai | |
| phantom-deps | phantom-dep:ajv | AI (phantom-deps): Transitive dep of @microsoft/tsdoc-config; declared explicitly, not a phantom threat. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/utils | AI (phantom-deps): Declared as direct dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Declared as direct dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:json-schema-traverse | AI (phantom-deps): Transitive dep of ajv; declared explicitly. | ai | |
| phantom-deps | phantom-dep:jju | AI (phantom-deps): Transitive dep of @microsoft/tsdoc-config; declared explicitly. | ai | |
| phantom-deps | phantom-dep:hasown | AI (phantom-deps): Transitive dep of resolve; declared explicitly. | ai | |
| phantom-deps | phantom-dep:uri-js | AI (phantom-deps): Transitive dep of ajv; declared explicitly. | ai | |
| phantom-deps | phantom-dep:resolve | AI (phantom-deps): Legitimate dep for module resolution in eslint plugin context. | ai | |
| phantom-deps | phantom-dep:es-errors | AI (phantom-deps): Transitive dep; declared explicitly, no threat. | ai | |
| phantom-deps | phantom-dep:path-parse | AI (phantom-deps): Transitive dep of resolve; declared explicitly. | ai |
Versions (showing 58 of 58)
| Version | Deps | Published |
|---|---|---|
| 0.0.71 | 16 / 14 | |
| 0.0.70 | 16 / 14 | |
| 0.0.69 | 16 / 14 | |
| 0.0.68 | 16 / 14 | |
| 0.0.67 | 16 / 14 | |
| 0.0.64 | 16 / 14 | |
| 0.0.62 | 16 / 14 | |
| 0.0.61 | 16 / 14 | |
| 0.0.55 | 16 / 14 | |
| 0.0.54 | 16 / 14 | |
| 0.0.53 | 16 / 14 | |
| 0.0.52 | 16 / 14 | |
| 0.0.49 | 16 / 14 | |
| 0.0.48 | 16 / 14 | |
| 0.0.46 | 16 / 14 | |
| 0.0.45 | 16 / 14 | |
| 0.0.44 | 16 / 14 | |
| 0.0.43 | 16 / 14 | |
| 0.0.42 | 16 / 14 | |
| 0.0.41 | 16 / 14 | |
| 0.0.40 | 16 / 14 | |
| 0.0.39 | 16 / 14 | |
| 0.0.38 | 16 / 14 | |
| 0.0.37 | 16 / 14 | |
| 0.0.36 | 16 / 14 | |
| 0.0.35 | 16 / 14 | |
| 0.0.34 | 16 / 14 | |
| 0.0.33 | 16 / 14 | |
| 0.0.32 | 16 / 13 | |
| 0.0.31 | 16 / 13 | |
| 0.0.30 | 16 / 13 | |
| 0.0.29 | 16 / 13 | |
| 0.0.28 | 16 / 13 | |
| 0.0.27 | 16 / 13 | |
| 0.0.25 | 16 / 13 | |
| 0.0.24 | 16 / 13 | |
| 0.0.23 | 16 / 13 | |
| 0.0.22 | 16 / 13 | |
| 0.0.21 | 16 / 13 | |
| 0.0.20 | 16 / 13 | |
| 0.0.19 | 16 / 13 | |
| 0.0.18 | 16 / 13 | |
| 0.0.17 | 16 / 13 | |
| 0.0.16 | 16 / 13 | |
| 0.0.15 | 16 / 13 | |
| 0.0.14 | 16 / 13 | |
| 0.0.13 | 16 / 13 | |
| 0.0.12 | 16 / 13 | |
| 0.0.11 | 16 / 13 | |
| 0.0.10 | 16 / 13 | |
| 0.0.9 | 16 / 13 | |
| 0.0.8 | 3 / 13 | |
| 0.0.7 | 3 / 13 | |
| 0.0.6 | 3 / 13 | |
| 0.0.5 | 3 / 13 | |
| 0.0.4 | 3 / 13 | |
| 0.0.3 | 3 / 13 | |
| 0.0.2 | 3 / 13 |
v0.0.71
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.70
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.69
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.68
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.67
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.64
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.62
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.61
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.55
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.54
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.53
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.52
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.49
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.48
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.42
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.41
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.