@xylabs/eslint-config-flat
ESLint Config used throughout XY Labs TypeScript/JavaScript libraries and react projects
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@ariestools/eslint-config-flat | AI (dependencies): Sibling package under same publisher's new org; stub redirects here by design. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Sparse metadata expected for a declared deprecated stub package. | ai | |
| phantom-deps | phantom-dep:browserslist | AI (phantom-deps): Used in config files, not directly imported; expected for eslint config packages. | ai | |
| provenance | missing-githead | AI (provenance): Minor metadata gap in a long-established, actively maintained monorepo package. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): High-volume publisher with 450 versions; rapid publishes are consistent with automated CI release pipelines for this org. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): atrouw is a known maintainer matched by email on prior approved versions; not a new external actor. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): xyo removal paired with atrouw addition reflects an internal maintainer rotation, not a takeover. | ai | |
| provenance | no-provenance | AI (provenance): Dev tooling package from established org; lack of provenance is common and not a risk signal here. | ai |
Versions (showing 100 of 268)
| Version | Deps | Published |
|---|---|---|
| 8.7.0 | 1 / 5 | |
| 8.6.12 | 1 / 5 | |
| 8.6.11 | 1 / 5 | |
| 8.6.10 | 11 / 11 | |
| 8.6.9 | 11 / 11 | |
| 8.6.8 | 11 / 11 | |
| 8.6.7 | 11 / 11 | |
| 8.6.6 | 11 / 11 | |
| 8.6.5 | 11 / 11 | |
| 8.6.4 | 11 / 11 | |
| 8.6.3 | 11 / 11 | |
| 8.6.2 | 10 / 12 | |
| 8.6.1 | 10 / 12 | |
| 8.6.0 | 10 / 12 | |
| 8.5.15 | 10 / 12 | |
| 8.5.14 | 10 / 12 | |
| 8.5.13 | 10 / 12 | |
| 8.5.12 | 10 / 12 | |
| 8.5.11 | 10 / 12 | |
| 8.5.10 | 10 / 12 | |
| 8.5.9 | 10 / 12 | |
| 8.5.8 | 10 / 12 | |
| 8.5.7 | 10 / 12 | |
| 8.5.6 | 10 / 12 | |
| 8.5.5 | 10 / 12 | |
| 8.5.4 | 10 / 12 | |
| 8.5.3 | 10 / 12 | |
| 8.5.1 | 10 / 12 | |
| 8.5.0 | 10 / 12 | |
| 8.4.1 | 10 / 12 | |
| 8.4.0 | 10 / 12 | |
| 8.3.0 | 10 / 12 | |
| 8.2.19 | 10 / 12 | |
| 8.2.18 | 10 / 12 | |
| 8.2.17 | 10 / 12 | |
| 8.2.16 | 10 / 12 | |
| 8.2.14 | 10 / 12 | |
| 8.2.13 | 11 / 12 | |
| 8.2.12 | 11 / 12 | |
| 8.2.11 | 11 / 12 | |
| 8.2.10 | 11 / 12 | |
| 8.2.9 | 11 / 12 | |
| 8.2.8 | 11 / 12 | |
| 8.2.7 | 11 / 12 | |
| 8.2.6 | 11 / 12 | |
| 8.2.5 | 11 / 12 | |
| 8.2.4 | 11 / 12 | |
| 8.2.3 | 11 / 12 | |
| 8.2.2 | 11 / 12 | |
| 8.2.1 | 11 / 12 | |
| 8.2.0 | 11 / 12 | |
| 8.1.21 | 11 / 11 | |
| 8.1.20 | 11 / 11 | |
| 8.1.19 | 11 / 11 | |
| 8.1.18 | 11 / 11 | |
| 8.1.17 | 11 / 11 | |
| 8.1.16 | 11 / 11 | |
| 8.1.15 | 11 / 11 | |
| 8.1.14 | 11 / 11 | |
| 8.1.13 | 11 / 11 | |
| 8.1.12 | 11 / 13 | |
| 8.1.11 | 11 / 13 | |
| 8.1.10 | 11 / 13 | |
| 8.1.9 | 11 / 13 | |
| 8.1.8 | 11 / 13 | |
| 8.1.7 | 11 / 13 | |
| 8.1.6 | 11 / 13 | |
| 8.1.5 | 11 / 13 | |
| 8.1.4 | 11 / 13 | |
| 8.1.3 | 11 / 13 | |
| 8.1.2 | 11 / 13 | |
| 8.1.1 | 11 / 13 | |
| 8.0.17 | 11 / 13 | |
| 8.0.16 | 11 / 13 | |
| 8.0.15 | 11 / 13 | |
| 8.0.14 | 11 / 13 | |
| 8.0.13 | 11 / 13 | |
| 8.0.12 | 11 / 13 | |
| 8.0.11 | 11 / 13 | |
| 8.0.10 | 11 / 13 | |
| 8.0.9 | 11 / 13 | |
| 8.0.8 | 11 / 13 | |
| 8.0.7 | 11 / 13 | |
| 8.0.6 | 11 / 13 | |
| 8.0.4 | 11 / 13 | |
| 8.0.3 | 11 / 13 | |
| 8.0.2 | 11 / 13 | |
| 8.0.1 | 11 / 13 | |
| 8.0.0 | 11 / 13 | |
| 7.13.24 | 11 / 14 | |
| 7.13.23 | 11 / 14 | |
| 7.13.22 | 11 / 14 | |
| 7.13.21 | 11 / 14 | |
| 7.13.20 | 11 / 14 | |
| 7.13.19 | 11 / 14 | |
| 7.13.18 | 11 / 14 | |
| 7.13.17 | 11 / 14 | |
| 7.13.16 | 11 / 14 | |
| 7.13.15 | 11 / 14 | |
| 7.13.14 | 11 / 14 |
v8.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.15
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.14
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.13
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.12
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.11
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.10
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.9
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.8
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.4.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.3
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
v8.1.2
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
v8.0.16
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
v8.0.15
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
v8.0.14
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
v8.0.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.10
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (atrouw) than the most recent previously approved version (xyo) on 2026-05-19, but atrouw is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.13.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.13.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.13.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.13.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.13.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.13.19
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (atrouw) than the most recent previously approved version (xyo) on 2026-05-07, but atrouw is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v7.13.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.13.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.13.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.13.15
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (atrouw) than the most recent previously approved version (xyo) on 2026-05-07, but atrouw is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v7.13.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.