eslint-plugin-jsdoc
JSDoc linting rules for ESLint.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI/CD publishing with SLSA attestation; stable for this package. | ai | |
| dependencies | unvetted-dep:parse-imports | AI (dependencies): parse-imports is a legitimate ES module import parser; its use in eslint-plugin-jsdoc for import analysis is expected and benign across all versions. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): html-entities is a legitimate, well-known package; its addition to a JSDoc linting plugin is plausible for HTML entity handling in JSDoc comments. | ai | |
| dependencies | unvetted-dep:spdx-expression-parse | AI (dependencies): spdx-expression-parse is a well-known, legitimate library for parsing SPDX license expressions; its use in a JSDoc linting plugin is expected and benign. | ai |
Versions (showing 100 of 826)
| Version | Deps | Published |
|---|---|---|
| 48.3.0 | 10 / 50 | |
| 48.2.15 | 8 / 49 | |
| 48.2.14 | 9 / 49 | |
| 48.2.13 | 8 / 49 | |
| 48.2.12 | 8 / 49 | |
| 48.2.11 | 8 / 49 | |
| 48.2.10 | 8 / 49 | |
| 48.2.9 | 8 / 49 | |
| 48.2.8 | 8 / 49 | |
| 48.2.7 | 8 / 49 | |
| 48.2.6 | 8 / 49 | |
| 48.2.5 | 9 / 49 | |
| 48.2.4 | 9 / 49 | |
| 48.2.3 | 9 / 49 | |
| 48.2.2 | 9 / 49 | |
| 48.2.1 | 9 / 49 | |
| 48.2.0 | 9 / 49 | |
| 48.1.0 | 9 / 49 | |
| 48.0.6 | 9 / 49 | |
| 48.0.5 | 9 / 49 | |
| 48.0.4 | 9 / 49 | |
| 48.0.3 | 9 / 49 | |
| 48.0.2 | 9 / 49 | |
| 48.0.1 | 9 / 49 | |
| 48.0.0 | 9 / 49 | |
| 47.0.2 | 9 / 49 | |
| 47.0.1 | 9 / 49 | |
| 47.0.0 | 9 / 49 | |
| 46.10.1 | 9 / 49 | |
| 46.10.0 | 9 / 49 | |
| 46.9.1 | 9 / 48 | |
| 46.9.0 | 9 / 48 | |
| 46.8.2 | 9 / 48 | |
| 46.8.1 | 9 / 48 | |
| 46.8.0 | 9 / 48 | |
| 46.7.0 | 9 / 48 | |
| 46.6.0 | 9 / 48 | |
| 46.5.1 | 9 / 48 | |
| 46.5.0 | 9 / 48 | |
| 46.4.6 | 9 / 46 | |
| 46.4.5 | 9 / 46 | |
| 46.4.4 | 9 / 46 | |
| 46.4.3 | 9 / 46 | |
| 46.4.2 | 9 / 46 | |
| 46.4.1 | 9 / 46 | |
| 46.4.0 | 9 / 46 | |
| 46.3.0 | 9 / 46 | |
| 46.2.6 | 9 / 46 | |
| 46.2.5 | 9 / 46 | |
| 46.2.4 | 8 / 46 | |
| 46.2.3 | 8 / 46 | |
| 46.2.2 | 8 / 46 | |
| 46.2.1 | 8 / 46 | |
| 46.2.0 | 8 / 46 | |
| 46.1.0 | 8 / 46 | |
| 46.0.0 | 8 / 46 | |
| 45.0.0 | 8 / 44 | |
| 44.2.7 | 8 / 44 | |
| 44.2.6 | 8 / 44 | |
| 44.2.5 | 8 / 44 | |
| 44.2.4 | 8 / 44 | |
| 44.2.3 | 8 / 43 | |
| 44.2.2 | 8 / 36 | |
| 44.2.1 | 8 / 36 | |
| 44.2.0 | 8 / 36 | |
| 44.1.0 | 8 / 36 | |
| 44.0.2 | 8 / 36 | |
| 44.0.1 | 8 / 34 | |
| 44.0.0 | 8 / 34 | |
| 43.2.0 | 8 / 34 | |
| 43.1.1 | 8 / 34 | |
| 43.1.0 | 8 / 34 | |
| 43.0.9 | 8 / 34 | |
| 43.0.8 | 8 / 34 | |
| 43.0.7 | 8 / 34 | |
| 43.0.6 | 8 / 34 | |
| 43.0.5 | 8 / 34 | |
| 43.0.4 | 8 / 34 | |
| 43.0.3 | 8 / 34 | |
| 43.0.2 | 8 / 34 | |
| 43.0.1 | 8 / 34 | |
| 43.0.0 | 8 / 34 | |
| 42.0.0 | 8 / 34 | |
| 41.1.2 | 8 / 34 | |
| 41.1.1 | 8 / 34 | |
| 41.1.0 | 8 / 34 | |
| 41.0.0 | 7 / 34 | |
| 40.3.0 | 7 / 34 | |
| 40.2.1 | 7 / 34 | |
| 40.2.0 | 7 / 34 | |
| 40.1.2 | 7 / 34 | |
| 40.1.1 | 7 / 34 | |
| 40.1.0 | 7 / 34 | |
| 40.0.3 | 7 / 34 | |
| 40.0.2 | 7 / 34 | |
| 40.0.1 | 7 / 34 | |
| 40.0.0 | 7 / 34 | |
| 39.9.1 | 7 / 34 | |
| 39.9.0 | 7 / 34 | |
| 39.8.0 | 7 / 34 |
v48.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.2.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.2.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.2.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.2.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.2.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.2.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.2.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.2.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.2.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.2.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.2.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.2.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.