← Home

@umijs/lint

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sorryccchenshuai2144kuitospeachscriptxiaohuoniyifankakaxixierenyuanxusd320zoomdong07

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@typescript-eslint/eslint-plugin AI (phantom-deps): ESLint plugin loaded by config convention, not directly imported. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): Lint config package; postcss loaded by convention via stylelint, not directly imported. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped; loaded by babel-eslint-parser convention, not directly imported. ai
phantom-deps phantom-dep:postcss-syntax AI (phantom-deps): Referenced in config files by convention, not directly imported. ai
phantom-deps phantom-dep:eslint-plugin-jest AI (phantom-deps): ESLint plugin loaded by config convention, not directly imported. ai
phantom-deps phantom-dep:eslint-plugin-react AI (phantom-deps): ESLint plugin loaded by config convention, not directly imported. ai
phantom-deps phantom-dep:eslint-plugin-react-hooks AI (phantom-deps): ESLint plugin loaded by config convention, not directly imported. ai
typosquat typosquat.levenshtein:eslint AI (typosquat): Scoped @umijs/ package; not a typosquat of eslint. ai
typosquat typosquat.levenshtein:pino AI (typosquat): Scoped @umijs/ package; not a typosquat of pino. ai
semgrep semgrep:dynamic-require AI (semgrep): Fires in compiled/@rushstack/eslint-patch bundle; legitimate eslint config resolution pattern. ai
semgrep semgrep:base64-decode AI (semgrep): Fires in compiled/postcss-less minified bundle; no malicious payload. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires in compiled/postcss-less minified bundle; standard parser pattern. ai
semgrep semgrep:env-bulk-read AI (semgrep): Fires in compiled stylelint plugin bundle; config library pattern. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Fires in compiled stylelint plugin bundle; not obfuscation. ai

Versions (showing 100 of 247)

Version Deps Published
4.6.82 12 / 5
4.6.81 12 / 5
4.6.80 12 / 5
4.6.79 12 / 5
4.6.78 12 / 5
4.6.77 12 / 5
4.6.76 12 / 5
4.6.75 12 / 5
4.6.74 12 / 5
4.6.73 12 / 5
4.6.72 12 / 5
4.6.71 12 / 5
4.6.70 12 / 5
4.6.69 12 / 5
4.6.68 12 / 5
4.6.67 12 / 5
4.6.66 12 / 5
4.6.65 12 / 5
4.6.64 12 / 5
4.6.63 12 / 5
4.6.62 12 / 5
4.6.61 12 / 5
4.6.59 12 / 5
4.6.58 12 / 5
4.6.57 12 / 5
4.6.56 12 / 5
4.6.55 12 / 5
4.6.54 12 / 5
4.6.53 12 / 5
4.6.52 12 / 5
4.6.51 12 / 5
4.6.50 12 / 5
4.6.49 12 / 5
4.6.48 12 / 5
4.6.45 12 / 5
4.6.42 12 / 5
4.6.41 12 / 5
4.6.39 12 / 5
4.6.36 12 / 5
4.6.35 12 / 5
4.6.34 12 / 5
4.6.33 12 / 5
4.6.32 12 / 5
4.6.31 12 / 5
4.6.30 12 / 5
4.6.29 12 / 5
4.6.28 12 / 5
4.6.27 12 / 5
4.6.26 12 / 5
4.6.25 12 / 5
4.6.24 12 / 5
4.6.23 12 / 5
4.6.22 12 / 5
4.6.21 12 / 5
4.6.20 12 / 5
4.6.19 12 / 5
4.6.18 12 / 5
4.6.17 12 / 5
4.6.16 12 / 5
4.6.15 12 / 5
4.6.14 12 / 5
4.6.13 12 / 5
4.6.12 12 / 5
4.6.11 12 / 5
4.6.10 12 / 5
4.6.9 12 / 5
4.6.8 12 / 5
4.6.7 12 / 5
4.6.6 12 / 5
4.6.5 12 / 5
4.6.4 12 / 5
4.6.3 12 / 5
4.6.2 12 / 5
4.6.1 12 / 5
4.6.0 12 / 5
4.5.3 12 / 5
4.5.2 12 / 5
4.5.1 12 / 5
4.5.0 12 / 5
4.4.12 12 / 5
4.4.11 12 / 5
4.4.10 12 / 5
4.4.9 12 / 5
4.4.8 12 / 5
4.4.7 12 / 5
4.4.6 12 / 5
4.4.5 12 / 5
4.4.4 12 / 5
4.4.3 12 / 5
4.4.2 12 / 5
4.4.1 12 / 5
4.4.0 12 / 5
4.3.36 12 / 5
4.3.35 12 / 5
4.3.34 12 / 5
4.3.33 12 / 5
4.3.32 12 / 5
4.3.31 12 / 5
4.3.30 12 / 5
4.3.29 12 / 5
Showing 100 of 247 Next page →

v4.6.82

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.81

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.80

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.79

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.78

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.77

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.76

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.75

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.74

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.73

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.72

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.71

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.70

2 findings
HIGH Publisher changed: zoomdong07 → GitHub Actions (on 2026-07-03) provenance

This version was published by a different npm account than previous versions on 2026-07-03. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.69

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.3.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.3.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.3.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.3.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.3.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.3.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.3.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.3.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.