← Home

@titelmedia/linter-executables

2
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

titelmedia-admindazliousmariaglucknanonansen2stellafangsanehussainbelenjonesapfelfabrik

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require is the core forwarding mechanism for resolving peer linter binaries; stable pattern for this package. ai
publish-pattern dormant-publish AI (publish-pattern): Publisher is a known maintainer on prior approved versions; dormancy reflects normal maintenance cadence for this org package. ai
phantom-deps phantom-dep:@typescript-eslint/eslint-plugin AI (phantom-deps): This package bundles linter plugins as deps for forwarding; all phantom-dep findings are expected for this wrapper pattern. ai
phantom-deps phantom-dep:eslint-plugin-simple-import-sort AI (phantom-deps): Same wrapper pattern; plugin is a bundled peer dep, not directly imported. ai
phantom-deps phantom-dep:stylelint-config-sass-guidelines AI (phantom-deps): Same wrapper pattern; config is a bundled peer dep, not directly imported. ai
phantom-deps phantom-dep:stylelint-scss AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:eslint-plugin-jest AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:stylelint-prettier AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:eslint-plugin-react AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:eslint-plugin-import AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:eslint-plugin-cypress AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:eslint-config-prettier AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:eslint AI (phantom-deps): Linter config bundle; tools are declared deps referenced in configs, not imported directly. ai
phantom-deps phantom-dep:eslint-plugin-prettier AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:eslint-plugin-storybook AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:@typescript-eslint/parser AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:eslint-plugin-react-hooks AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:eslint-plugin-react-native AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:stylelint-config-css-modules AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:stylelint-config-standard-scss AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:eslint-plugin-jsx-a11y AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:prettier AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:stylelint AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): Same pattern — config bundle, not a JS importer. ai

Versions (showing 2 of 2)

Version Deps Published
8.1.1 23 / 0
8.0.0 23 / 0

v8.1.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: titelmedia-admin → dazlious (on 2026-06-03, known maintainer) provenance

This version was published by a different npm account (dazlious) than the most recent previously approved version (titelmedia-admin) on 2026-06-03, but dazlious is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v8.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.