← Home

eslint-plugin-rxjs-x

16
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

jasonweinzierl

Keywords

lintruleseslinteslintplugineslint-pluginrxjs

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Package explicitly uses GitHub Actions for publishing with SLSA provenance; publisher change from human to GHA is intentional. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy followed by GHA-published release with SLSA attestation; no signs of takeover. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a declared runtime dependency used implicitly by TypeScript compilation output; stable false positive. ai

Versions (showing 16 of 16)

Version Deps Published
1.0.3 3 / 31
1.0.2 3 / 29
1.0.1 3 / 29
1.0.0 3 / 24
0.9.5 6 / 23
0.9.4 6 / 23
0.9.3 6 / 23
0.9.2 6 / 23
0.9.1 6 / 23
0.9.0 6 / 23
0.8.5 6 / 23
0.8.4 6 / 23
0.8.3 6 / 24
0.8.2 6 / 24
0.8.1 6 / 24
0.8.0 6 / 24

v1.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.