← Home

@eslint/css

CSS linting plugin for ESLint

21
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

openjsfoundationeslintbot

Keywords

eslinteslint-plugineslintplugincsslinting

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-tripled AI (source-diff): Size increase explained by bundling previously-external deps (css-tree, plugin-kit) directly into the package. Consistent with the removed runtime deps in the version diff. ai
npm-metadata url-dep:@types/css-tree AI (npm-metadata): file: protocol points to a local bundled typings package within the repo (private, not a remote URL). Standard monorepo pattern for shipping custom type definitions. ai
phantom-deps phantom-dep:@types/css-tree AI (phantom-deps): @types/ packages are consumed by TypeScript tooling, not via direct imports. Expected phantom-dep pattern for type definition packages. ai
typosquat typosquat.levenshtein:qs AI (typosquat): @eslint/css is the official ESLint CSS plugin under the @eslint org scope; Levenshtein proximity to 'qs' is coincidental and not a typosquat. ai
typosquat typosquat.levenshtein:cors AI (typosquat): @eslint/css is the official ESLint CSS plugin under the @eslint org scope; Levenshtein proximity to 'cors' is coincidental and not a typosquat. ai
provenance publisher-changed AI (provenance): ESLint org migrated publishing to GitHub Actions CI/CD with SLSA provenance attestation; this publisher change is expected and verified for all future versions of this package. ai
source-diff net-exec-file:dist/rules/no-invalid-properties.js AI (source-diff): False positive: the file is a standard ESLint CSS rule implementation with no actual network calls or dynamic code execution. Official ESLint org package with SLSA provenance. ai
source-diff large-new-source-files AI (source-diff): Major version (1.0.0) release of an official ESLint plugin; new files include CSS baseline data consistent with the package's purpose and build tooling. ai

Versions (showing 21 of 21)

Version Deps Published
1.3.0 3 / 19
1.2.0 3 / 19
1.1.0 3 / 19
1.0.0 3 / 17
0.14.1 3 / 18
0.14.0 3 / 18
0.13.0 3 / 19
0.12.0 3 / 19
0.11.1 3 / 20
0.11.0 3 / 20
0.10.0 3 / 20
0.9.0 3 / 19
0.8.1 3 / 19
0.8.0 3 / 19
0.7.0 3 / 19
0.6.0 3 / 18
0.5.0 3 / 16
0.4.0 4 / 16
0.3.0 4 / 16
0.2.0 2 / 17
0.1.0 2 / 17

v1.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

2 findings
HIGH New file with network + code execution: dist/rules/no-invalid-properties.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.0

2 findings
HIGH Publisher changed: eslintbot → GitHub Actions (on 2025-10-10) provenance

This version was published by a different npm account than previous versions on 2025-10-10. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.