← Home

@storm-software/eslint-plugin-tsdoc

58
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

eslinteslint-pluginstorm-software

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/plugin-J8NsxKRJ.mjs AI (source-diff): Rolldown bundle of explicitly declared inlinedDependencies; minified but not obfuscated or malicious. ai
source-diff net-exec-file:dist/plugin-J8NsxKRJ.mjs AI (source-diff): Network/exec pattern is from bundled resolver/module deps (resolve, is-core-module), not dropper behavior. ai
source-diff net-exec-file:dist/plugin-BxdznRU6.mjs AI (source-diff): False positive on bundled ESLint plugin; no actual network+exec payload, just bundled module resolution helpers. ai
source-diff obfuscated-file:dist/plugin-BxdznRU6.mjs AI (source-diff): Rolldown bundle of inlined deps (@microsoft/tsdoc etc.); confirmed by inlinedDependencies field and SLSA provenance. ai
source-diff net-exec-file:dist/plugin-BuKHlGry.mjs AI (source-diff): Network/exec pattern is bundler boilerplate from rolldown runtime, not dropper malware. ai
source-diff obfuscated-file:dist/plugin-BuKHlGry.mjs AI (source-diff): Rolldown bundle inlining declared inlinedDependencies; readable commented code, not obfuscation. ai
source-diff source-size-tripled AI (source-diff): Size increase explained by bundling inlinedDependencies into the dist file. ai
phantom-deps phantom-dep:function-bind AI (phantom-deps): Transitive dep; declared explicitly. ai
phantom-deps phantom-dep:is-core-module AI (phantom-deps): Transitive dep of resolve; declared explicitly. ai
phantom-deps phantom-dep:fast-deep-equal AI (phantom-deps): Transitive dep of ajv; declared explicitly. ai
phantom-deps phantom-dep:ajv AI (phantom-deps): Transitive dep of @microsoft/tsdoc-config; declared explicitly, not a phantom threat. ai
phantom-deps phantom-dep:@typescript-eslint/utils AI (phantom-deps): Declared as direct dep; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:defu AI (phantom-deps): Declared as direct dep; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:json-schema-traverse AI (phantom-deps): Transitive dep of ajv; declared explicitly. ai
phantom-deps phantom-dep:jju AI (phantom-deps): Transitive dep of @microsoft/tsdoc-config; declared explicitly. ai
phantom-deps phantom-dep:hasown AI (phantom-deps): Transitive dep of resolve; declared explicitly. ai
phantom-deps phantom-dep:uri-js AI (phantom-deps): Transitive dep of ajv; declared explicitly. ai
phantom-deps phantom-dep:resolve AI (phantom-deps): Legitimate dep for module resolution in eslint plugin context. ai
phantom-deps phantom-dep:es-errors AI (phantom-deps): Transitive dep; declared explicitly, no threat. ai
phantom-deps phantom-dep:path-parse AI (phantom-deps): Transitive dep of resolve; declared explicitly. ai

Versions (showing 58 of 58)

Version Deps Published
0.0.71 16 / 14
0.0.70 16 / 14
0.0.69 16 / 14
0.0.68 16 / 14
0.0.67 16 / 14
0.0.64 16 / 14
0.0.62 16 / 14
0.0.61 16 / 14
0.0.55 16 / 14
0.0.54 16 / 14
0.0.53 16 / 14
0.0.52 16 / 14
0.0.49 16 / 14
0.0.48 16 / 14
0.0.46 16 / 14
0.0.45 16 / 14
0.0.44 16 / 14
0.0.43 16 / 14
0.0.42 16 / 14
0.0.41 16 / 14
0.0.40 16 / 14
0.0.39 16 / 14
0.0.38 16 / 14
0.0.37 16 / 14
0.0.36 16 / 14
0.0.35 16 / 14
0.0.34 16 / 14
0.0.33 16 / 14
0.0.32 16 / 13
0.0.31 16 / 13
0.0.30 16 / 13
0.0.29 16 / 13
0.0.28 16 / 13
0.0.27 16 / 13
0.0.25 16 / 13
0.0.24 16 / 13
0.0.23 16 / 13
0.0.22 16 / 13
0.0.21 16 / 13
0.0.20 16 / 13
0.0.19 16 / 13
0.0.18 16 / 13
0.0.17 16 / 13
0.0.16 16 / 13
0.0.15 16 / 13
0.0.14 16 / 13
0.0.13 16 / 13
0.0.12 16 / 13
0.0.11 16 / 13
0.0.10 16 / 13
0.0.9 16 / 13
0.0.8 3 / 13
0.0.7 3 / 13
0.0.6 3 / 13
0.0.5 3 / 13
0.0.4 3 / 13
0.0.3 3 / 13
0.0.2 3 / 13

v0.0.71

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.70

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.69

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.68

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.67

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.64

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.62

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.61

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.55

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.54

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.53

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.52

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.49

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.48

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.46

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.45

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.