← Home

textlint-scripts

textlint scripts help you to create textlint rule.

20
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

azutextlint-user

Keywords

textlint

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from textlint-user to GitHub Actions CI/CD is confirmed legitimate by SLSA Sigstore attestation on the textlint monorepo. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation via GitHub Actions CI/CD confirms legitimate automated release; dormancy explained by monorepo release cadence. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped; loaded by babel toolchain convention. ai
phantom-deps phantom-dep:textlint-tester AI (phantom-deps): Referenced in config; stable false positive for this package. ai
phantom-deps phantom-dep:mocha AI (phantom-deps): Referenced in test config/scripts; not directly imported by convention. ai
phantom-deps phantom-dep:babel-plugin-static-fs AI (phantom-deps): Babel plugin; loaded by convention via babel config. ai
phantom-deps phantom-dep:@babel/preset-typescript AI (phantom-deps): Babel preset; loaded by convention via babel config. ai
phantom-deps phantom-dep:@babel/preset-env AI (phantom-deps): Babel preset; loaded by convention via babel config. ai
phantom-deps phantom-dep:@babel/cli AI (phantom-deps): Framework-scoped CLI tool; loaded by convention, not direct import. ai

Versions (showing 20 of 20)

Version Deps Published
15.7.1 11 / 2
15.7.0 11 / 2
15.6.1 11 / 2
15.6.0 11 / 2
15.5.4 11 / 2
15.5.3 11 / 3
15.5.2 11 / 3
15.5.1 11 / 3
15.5.0 11 / 3
15.4.1 11 / 3
15.4.0 11 / 3
15.3.0 11 / 3
15.2.3 11 / 3
15.2.2 11 / 3
15.2.1 11 / 3
15.2.0 11 / 3
15.1.1 11 / 3
15.1.0 11 / 3
15.0.1 11 / 3
15.0.0 11 / 3

v15.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.5.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.2.3

2 findings
HIGH Publisher changed: textlint-user → GitHub Actions (on 2025-10-11) provenance

This version was published by a different npm account than previous versions on 2025-10-11. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v15.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v15.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v15.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v15.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v15.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v15.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.