← Home

@eslint-sukka/eslint-plugin-react-jsx-a11y

18
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sukkaw

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@nolyfill/es-iterator-helpers AI (phantom-deps): Same bundled polyfill pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@nolyfill/string.prototype.includes AI (phantom-deps): Same bundled polyfill pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@nolyfill/array.prototype.tosorted AI (phantom-deps): Same bundled polyfill pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@nolyfill/deep-equal AI (phantom-deps): Bundled polyfill pattern; not directly imported but used transitively via eslint-plugin-jsx-a11y. ai
phantom-deps phantom-dep:@nolyfill/safe-regex-test AI (phantom-deps): Same bundled polyfill pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@nolyfill/object.hasown AI (phantom-deps): Same bundled polyfill pattern; stable false positive for this package. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation via Sigstore confirms legitimate CI/CD publish; mitigates account-takeover concern. ai
npm-metadata no-description AI (npm-metadata): Scoped package with clear repo context; missing description is benign for this package type. ai
dependencies unvetted-dep:@nolyfill/hasown AI (dependencies): @nolyfill/* are known polyfill-optimization packages used across this publisher's ecosystem. ai
dependencies unvetted-dep:@nolyfill/array.prototype.flatmap AI (dependencies): @nolyfill/* are known polyfill-optimization packages used across this publisher's ecosystem. ai
dependencies unvetted-dep:@nolyfill/array.prototype.flat AI (dependencies): @nolyfill/* are known polyfill-optimization packages used across this publisher's ecosystem. ai
dependencies unvetted-dep:@nolyfill/object.fromentries AI (dependencies): @nolyfill/* are known polyfill-optimization packages used across this publisher's ecosystem. ai
dependencies unvetted-dep:@nolyfill/array-includes AI (dependencies): @nolyfill/* are known polyfill-optimization packages used across this publisher's ecosystem. ai
dependencies unvetted-dep:@nolyfill/object.values AI (dependencies): @nolyfill/* are known polyfill-optimization packages used across this publisher's ecosystem. ai
dependencies unvetted-dep:@nolyfill/object.assign AI (dependencies): @nolyfill/* are known polyfill-optimization packages used across this publisher's ecosystem. ai

Versions (showing 18 of 18)

Version Deps Published
8.10.4 7 / 2
8.10.3 7 / 2
8.10.2 7 / 2
8.10.1 7 / 2
8.10.0 7 / 2
8.9.4 7 / 2
8.9.3 7 / 2
8.9.2 7 / 2
8.9.1 7 / 2
8.9.0 7 / 2
8.8.0 7 / 2
8.7.1 7 / 2
8.7.0 7 / 2
8.6.5 7 / 2
8.6.4 7 / 2
8.6.1 7 / 2
8.0.6 13 / 2
8.0.2 13 / 2

v8.10.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.10.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.10.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.10.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.9.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.9.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.9.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.9.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.6.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.6.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.