@babel/eslint-parser
ESLint parser that allows for linting of experimental syntax transformed by Babel
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Babel ecosystem package; provenance attestation not yet standard for this publisher but no security concern given repo transparency. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): danez and loganfsmyth are former Babel contributors; nicolo-ribaudo is a recognized Babel core team member. This reflects a legitimate team transition within the official Babel project. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dependency is scoped to maintainer and pinned; provides eslint-scope v5 internals, a legitimate technical requirement. | ai | |
| provenance | publisher-changed | AI (provenance): nicolo-ribaudo is a well-known Babel core team maintainer; the jlhwung→nicolo-ribaudo transition is a legitimate organizational handoff within the Babel project. | ai | |
| provenance | missing-githead | AI (provenance): Documented publish environment change during maintainer transition; consistent with legitimate handoff, not malicious activity. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Spam signals are outdated (hzoo reference) or minor (no keywords); package is established Babel project component. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require is a version-resolution pattern for Babel compatibility, not arbitrary module loading; stable for this package. | ai | |
| dependencies | unvetted-dep:@nicolo-ribaudo/eslint-scope-5-internals | AI (dependencies): Internal ESLint scope utility pinned to specific version; stable dependency for this package's parser functionality. | ai |
Versions (showing 63 of 63)
| Version | Deps | Published |
|---|---|---|
| 7.29.7 | 3 / 8 | |
| 7.28.6 | 3 / 8 | |
| 7.28.5 | 3 / 8 | |
| 7.28.4 | 3 / 8 | |
| 7.28.0 | 3 / 8 | |
| 7.27.5 | 3 / 8 | |
| 7.27.1 | 3 / 8 | |
| 7.27.0 | 3 / 6 | |
| 7.26.10 | 3 / 6 | |
| 7.26.8 | 3 / 6 | |
| 7.26.5 | 3 / 6 | |
| 7.25.9 | 3 / 6 | |
| 7.25.8 | 3 / 6 | |
| 7.25.7 | 3 / 6 | |
| 7.25.1 | 3 / 6 | |
| 7.25.0 | 3 / 6 | |
| 7.24.8 | 3 / 6 | |
| 7.24.7 | 3 / 6 | |
| 7.24.6 | 3 / 6 | |
| 7.24.5 | 3 / 6 | |
| 7.24.1 | 3 / 6 | |
| 7.23.10 | 3 / 6 | |
| 7.23.9 | 3 / 6 | |
| 7.23.3 | 3 / 3 | |
| 7.22.15 | 3 / 3 | |
| 7.22.11 | 3 / 3 | |
| 7.22.10 | 3 / 3 | |
| 7.22.9 | 3 / 3 | |
| 7.22.7 | 3 / 3 | |
| 7.22.6 | 3 / 3 | |
| 7.22.5 | 3 / 3 | |
| 7.21.8 | 3 / 3 | |
| 7.21.3 | 3 / 3 | |
| 7.19.1 | 3 / 3 | |
| 7.18.9 | 3 / 4 | |
| 7.18.2 | 3 / 4 | |
| 7.17.0 | 3 / 4 | |
| 7.16.5 | 3 / 4 | |
| 7.16.3 | 3 / 4 | |
| 7.16.0 | 3 / 4 | |
| 7.15.8 | 3 / 3 | |
| 7.15.7 | 3 / 3 | |
| 7.15.4 | 3 / 3 | |
| 7.15.0 | 3 / 3 | |
| 7.14.9 | 3 / 3 | |
| 7.14.7 | 3 / 3 | |
| 7.14.5 | 3 / 3 | |
| 7.14.4 | 3 / 3 | |
| 7.14.3 | 3 / 3 | |
| 7.14.2 | 3 / 3 | |
| 7.13.14 | 3 / 3 | |
| 7.13.10 | 3 / 3 | |
| 7.13.8 | 3 / 3 | |
| 7.13.4 | 3 / 3 | |
| 7.13.0 | 3 / 3 | |
| 7.12.17 | 3 / 3 | |
| 7.12.16 | 3 / 3 | |
| 7.12.13 | 3 / 3 | |
| 7.12.1 | 3 / 4 | |
| 7.11.5 | 3 / 4 | |
| 7.11.4 | 3 / 4 | |
| 7.11.3 | 3 / 4 | |
| 7.11.0 | 3 / 4 |
v7.29.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.28.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.28.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.28.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.27.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.27.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.27.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.26.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.26.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.26.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.25.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.25.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.25.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.25.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.24.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.24.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.24.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.24.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.24.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.23.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.23.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.22.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.22.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.22.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.22.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.22.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.22.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.22.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.21.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.21.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.19.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.