@xylabs/eslint-config-flat
ESLint Config used throughout XY Labs TypeScript/JavaScript libraries and react projects
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@ariestools/eslint-config-flat | AI (dependencies): Sibling package under same publisher's new org; stub redirects here by design. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Sparse metadata expected for a declared deprecated stub package. | ai | |
| phantom-deps | phantom-dep:browserslist | AI (phantom-deps): Used in config files, not directly imported; expected for eslint config packages. | ai | |
| provenance | missing-githead | AI (provenance): Minor metadata gap in a long-established, actively maintained monorepo package. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): High-volume publisher with 450 versions; rapid publishes are consistent with automated CI release pipelines for this org. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): atrouw is a known maintainer matched by email on prior approved versions; not a new external actor. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): xyo removal paired with atrouw addition reflects an internal maintainer rotation, not a takeover. | ai | |
| provenance | no-provenance | AI (provenance): Dev tooling package from established org; lack of provenance is common and not a risk signal here. | ai |
Versions (showing 51 of 268)
| Version | Deps | Published |
|---|---|---|
| 8.7.0 | 1 / 5 | |
| 8.6.12 | 1 / 5 | |
| 8.6.11 | 1 / 5 | |
| 8.6.10 | 11 / 11 | |
| 8.6.9 | 11 / 11 | |
| 8.6.8 | 11 / 11 | |
| 8.6.7 | 11 / 11 | |
| 8.6.6 | 11 / 11 | |
| 8.6.5 | 11 / 11 | |
| 8.6.4 | 11 / 11 | |
| 8.6.3 | 11 / 11 | |
| 8.6.2 | 10 / 12 | |
| 8.6.1 | 10 / 12 | |
| 8.6.0 | 10 / 12 | |
| 8.5.15 | 10 / 12 | |
| 8.5.14 | 10 / 12 | |
| 8.5.13 | 10 / 12 | |
| 8.5.12 | 10 / 12 | |
| 8.5.11 | 10 / 12 | |
| 8.5.10 | 10 / 12 | |
| 8.5.9 | 10 / 12 | |
| 8.5.8 | 10 / 12 | |
| 8.5.7 | 10 / 12 | |
| 8.5.6 | 10 / 12 | |
| 8.5.5 | 10 / 12 | |
| 8.5.4 | 10 / 12 | |
| 8.5.3 | 10 / 12 | |
| 8.5.1 | 10 / 12 | |
| 8.5.0 | 10 / 12 | |
| 8.4.1 | 10 / 12 | |
| 8.4.0 | 10 / 12 | |
| 8.3.0 | 10 / 12 | |
| 8.2.19 | 10 / 12 | |
| 8.2.18 | 10 / 12 | |
| 8.2.17 | 10 / 12 | |
| 8.2.16 | 10 / 12 | |
| 8.2.14 | 10 / 12 | |
| 8.2.13 | 11 / 12 | |
| 8.2.12 | 11 / 12 | |
| 8.2.11 | 11 / 12 | |
| 8.2.10 | 11 / 12 | |
| 8.2.9 | 11 / 12 | |
| 8.2.8 | 11 / 12 | |
| 8.2.7 | 11 / 12 | |
| 8.2.6 | 11 / 12 | |
| 8.2.5 | 11 / 12 | |
| 8.2.4 | 11 / 12 | |
| 8.2.3 | 11 / 12 | |
| 8.2.2 | 11 / 12 | |
| 8.2.1 | 11 / 12 | |
| 8.2.0 | 11 / 12 |
v8.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.15
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.14
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.13
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.12
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.11
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.10
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.9
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.8
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.4.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.