← Home

@mongodb-js/eslint-config-devtools

Shared DevTools eslint configuration

7
Versions
SSPL
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

mongodb-js-useralexander_schrollmbroadsthswolffsatyasinhajeff-allen-mongojonathan.balsanomongodb-buildjack.weirkristina.stefanojarjeeshaketbabydevtoolsbotgribnoysupmutukrishmongo-jdariakpaddaleaxnbbeekendbx-nodenirinchevpearsb1mcasimir_mdb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:eslint-plugin-filename-rules AI (dependencies): eslint-plugin-filename-rules is a legitimate ESLint plugin; its use is consistent with this shared ESLint config package. ai
bogus-package bogus-package AI (bogus-package): Internal MongoDB DevTools ESLint config in a monorepo; sparse README and no keywords are expected for org-internal tooling. ai
phantom-deps phantom-dep:eslint-plugin-react AI (phantom-deps): ESLint config package; plugins referenced in config files, not imported directly. ai
phantom-deps phantom-dep:@babel/eslint-parser AI (phantom-deps): ESLint config package; parsers loaded by convention, not direct import. ai
phantom-deps phantom-dep:eslint-config-prettier AI (phantom-deps): ESLint config package; configs referenced in config files, not imported directly. ai
phantom-deps phantom-dep:eslint-plugin-jsx-a11y AI (phantom-deps): ESLint config package; plugins referenced in config files, not imported directly. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): ESLint config package; plugins/parsers are loaded by convention, not direct import. ai
phantom-deps phantom-dep:eslint-plugin-react-hooks AI (phantom-deps): ESLint config package; plugins referenced in config files, not imported directly. ai
phantom-deps phantom-dep:eslint-plugin-filename-rules AI (phantom-deps): ESLint config package; plugins referenced in config files, not imported directly. ai
phantom-deps phantom-dep:@typescript-eslint/eslint-plugin AI (phantom-deps): ESLint config package; plugins referenced in config files, not imported directly. ai
phantom-deps phantom-dep:@mongodb-js/eslint-plugin-devtools AI (phantom-deps): Same-org ESLint plugin; referenced in config files, not imported directly. ai
phantom-deps phantom-dep:@typescript-eslint/parser AI (phantom-deps): ESLint config package; parsers loaded by convention, not direct import. ai
phantom-deps phantom-dep:eslint-plugin-mocha AI (phantom-deps): ESLint config package; plugins referenced in config files, not imported directly. ai

Versions (showing 7 of 7)

Version Deps Published
0.11.7 13 / 1
0.11.6 13 / 1
0.11.5 13 / 1
0.11.4 13 / 1
0.11.2 13 / 1
0.11.1 13 / 1
0.9.12 12 / 1

v0.11.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.