@taiga-ui/stylelint-config
Taiga UI stylelint config
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:stylelint-plugin-use-baseline | AI (dependencies): Stylelint plugin used as a config dependency; no malicious indicators, stable pattern for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established Taiga UI toolkit package; provenance not yet enabled but no other risk signals present. | ai | |
| phantom-deps | phantom-dep:postcss-less | AI (phantom-deps): Config-only package; deps referenced in config files, not JS imports. Expected pattern. | ai | |
| phantom-deps | phantom-dep:stylelint-order | AI (phantom-deps): Config-only package; deps referenced in config files, not JS imports. Expected pattern. | ai | |
| phantom-deps | phantom-dep:stylelint-rem-over-px | AI (phantom-deps): Config-only package; deps referenced in config files, not JS imports. Expected pattern. | ai | |
| phantom-deps | phantom-dep:stylelint-use-logical | AI (phantom-deps): Config-only package; deps referenced in config files, not JS imports. Expected pattern. | ai | |
| phantom-deps | phantom-dep:stylelint-config-standard | AI (phantom-deps): Config-only package; deps referenced in config files, not JS imports. Expected pattern. | ai | |
| phantom-deps | phantom-dep:@stylistic/stylelint-plugin | AI (phantom-deps): Config-only package; deps referenced in config files, not JS imports. Expected pattern. | ai | |
| phantom-deps | phantom-dep:stylelint-plugin-logical-css | AI (phantom-deps): Config-only package; deps referenced in config files, not JS imports. Expected pattern. | ai | |
| phantom-deps | phantom-dep:stylelint-plugin-use-baseline | AI (phantom-deps): Config-only package; deps referenced in config files, not JS imports. Expected pattern. | ai | |
| phantom-deps | phantom-dep:stylelint-no-unsupported-browser-features | AI (phantom-deps): Config-only package; deps referenced in config files, not JS imports. Expected pattern. | ai | |
| phantom-deps | phantom-dep:@stylistic/stylelint-config | AI (phantom-deps): Config-only package; deps referenced in config files, not JS imports. Expected pattern. | ai | |
| phantom-deps | phantom-dep:postcss | AI (phantom-deps): Config-only package; deps referenced in config files, not JS imports. Expected pattern. | ai | |
| provenance | publisher-changed | AI (provenance): splincode is a named contributor in package.json and has a clean track record; transition appears legitimate for this package. | ai |
Versions (showing 51 of 594)
| Version | Deps | Published |
|---|---|---|
| 0.554.0 | 13 / 0 | |
| 0.553.0 | 13 / 0 | |
| 0.552.0 | 13 / 0 | |
| 0.551.0 | 13 / 0 | |
| 0.550.0 | 13 / 0 | |
| 0.549.0 | 13 / 0 | |
| 0.548.0 | 13 / 0 | |
| 0.547.0 | 13 / 0 | |
| 0.546.0 | 13 / 0 | |
| 0.545.0 | 13 / 0 | |
| 0.544.0 | 13 / 0 | |
| 0.543.0 | 13 / 0 | |
| 0.542.0 | 13 / 0 | |
| 0.541.0 | 13 / 0 | |
| 0.540.0 | 13 / 0 | |
| 0.539.0 | 13 / 0 | |
| 0.538.0 | 13 / 0 | |
| 0.537.0 | 13 / 0 | |
| 0.536.0 | 13 / 0 | |
| 0.535.0 | 13 / 0 | |
| 0.534.0 | 13 / 0 | |
| 0.533.0 | 13 / 0 | |
| 0.532.0 | 13 / 0 | |
| 0.531.0 | 13 / 0 | |
| 0.530.0 | 13 / 0 | |
| 0.529.0 | 13 / 0 | |
| 0.528.0 | 13 / 0 | |
| 0.527.0 | 13 / 0 | |
| 0.526.0 | 13 / 0 | |
| 0.525.0 | 13 / 0 | |
| 0.524.0 | 13 / 0 | |
| 0.523.0 | 13 / 0 | |
| 0.522.0 | 13 / 0 | |
| 0.521.0 | 13 / 0 | |
| 0.520.0 | 0 / 0 | |
| 0.519.0 | 0 / 0 | |
| 0.518.0 | 0 / 0 | |
| 0.517.0 | 0 / 0 | |
| 0.516.0 | 0 / 0 | |
| 0.515.0 | 0 / 0 | |
| 0.514.0 | 0 / 0 | |
| 0.513.0 | 0 / 0 | |
| 0.512.0 | 0 / 0 | |
| 0.511.0 | 0 / 0 | |
| 0.510.0 | 0 / 0 | |
| 0.509.0 | 0 / 0 | |
| 0.508.0 | 0 / 0 | |
| 0.507.0 | 0 / 0 | |
| 0.506.0 | 0 / 0 | |
| 0.505.0 | 0 / 0 | |
| 0.504.0 | 0 / 0 |
v0.554.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.553.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.552.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.551.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.550.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.549.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.548.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.547.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.546.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.545.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.