eslint-plugin-react-web-api
ESLint React's ESLint plugin for interacting with Web APIs
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@eslint-react/eff | AI (dependencies): First-party sibling package from the same eslint-react monorepo, always pinned to the same version as the parent package. Not a third-party risk. | ai | |
| phantom-deps | phantom-dep:string-ts | AI (phantom-deps): string-ts is a declared runtime dependency bundled into dist output; phantom-dep flag is a false positive for compiled/bundled packages. | ai | |
| dependencies | unvetted-dep:@eslint-react/core | AI (dependencies): Co-published sibling package from the same Rel1cx/eslint-react monorepo, always at the same version. Not an independent supply chain risk. | ai | |
| dependencies | unvetted-dep:@eslint-react/ast | AI (dependencies): Co-published sibling package from the same Rel1cx/eslint-react monorepo, always at the same version. Not an independent supply chain risk. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/scope-manager | AI (phantom-deps): Declared for type resolution in TypeScript ESLint tooling; not directly imported but legitimately needed as a peer/type dependency. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/types | AI (phantom-deps): Declared for type resolution in TypeScript ESLint tooling; not directly imported but legitimately needed as a peer/type dependency. Stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@eslint-react/var | AI (dependencies): Co-published sibling package from the same Rel1cx/eslint-react monorepo, always at the same version. Not an independent supply chain risk. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 5.7.7 | 9 / 8 | |
| 5.7.6 | 9 / 8 | |
| 5.7.5 | 9 / 8 | |
| 5.7.4 | 9 / 8 | |
| 5.7.3 | 9 / 8 | |
| 5.7.2 | 9 / 8 | |
| 5.7.1 | 9 / 8 | |
| 5.7.0 | 9 / 8 | |
| 5.6.6 | 9 / 8 | |
| 5.6.4 | 9 / 8 | |
| 5.6.2 | 9 / 8 | |
| 5.6.0 | 9 / 8 | |
| 4.2.3 | 9 / 6 | |
| 4.2.1 | 9 / 6 | |
| 3.0.0 | 9 / 6 | |
| 2.12.4 | 10 / 4 | |
| 2.3.0 | 10 / 4 |
v5.7.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.6.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.6.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.6.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.