← Home

@tsparticles/prettier-config

tsParticles default Prettier Configuration

46
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

matteobruni

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): This is a legitimate minimal prettier config package from the tsParticles ecosystem. Tiny payload, no README code, and no repo URL are expected for a JSON-only config package. ai
phantom-deps phantom-dep:prettier AI (phantom-deps): prettier is a peer/runtime dep bundled for consumers of this config; not imported via require() because the package is JSON-based, not JS. ai
provenance no-provenance AI (provenance): Established tsParticles publisher with 29 approved packages; lack of provenance is consistent across their catalog and not a risk indicator here. ai
provenance missing-githead AI (provenance): Package has SLSA/Sigstore provenance attestation via GitHub Actions, which supersedes gitHead as a supply chain integrity signal. Acceptable for this package. ai
phantom-deps phantom-dep:prettier-plugin-multiline-arrays AI (phantom-deps): This is a Prettier config package; plugins are referenced by name in JSON config, not via JS imports. Phantom-dep detection is a structural false positive for this package type. ai

Versions (showing 46 of 46)

Version Deps Published
4.3.2 1 / 2
4.3.1 1 / 2
4.3.0 1 / 2
4.2.1 1 / 2
4.2.0 1 / 2
4.1.3 1 / 2
4.1.2 1 / 2
4.1.1 1 / 2
4.1.0 1 / 2
4.0.5 1 / 2
4.0.4 1 / 2
4.0.3 1 / 2
4.0.2 1 / 2
4.0.1 1 / 2
4.0.0 1 / 2
3.4.14 1 / 2
3.4.13 1 / 2
3.4.12 1 / 2
3.4.11 1 / 2
3.4.10 1 / 2
3.4.9 1 / 2
3.4.7 1 / 2
3.4.6 1 / 2
3.4.5 1 / 2
3.4.4 1 / 2
3.4.3 1 / 2
3.4.2 1 / 2
3.4.1 1 / 2
3.3.5 1 / 2
3.3.4 1 / 2
3.3.3 1 / 2
3.3.2 1 / 2
3.3.1 1 / 2
3.3.0 1 / 2
3.2.0 2 / 1
3.1.9 2 / 1
3.1.8 2 / 1
3.1.7 2 / 1
3.1.6 2 / 1
3.1.4 2 / 0
3.0.11 2 / 0
3.0.10 2 / 0
3.0.7 2 / 0
3.0.6 2 / 0
3.0.1 2 / 0
3.0.0 2 / 0

v4.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.