eslint-plugin-react-jsx
ESLint React's ESLint plugin for React Flavored JSX rules.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@eslint-react/ast | AI (dependencies): Sibling package from the same eslint-react monorepo, pinned to exact matching version. Standard monorepo publishing pattern, not a security concern. | ai | |
| dependencies | unvetted-dep:@eslint-react/jsx | AI (dependencies): Sibling package from the same eslint-react monorepo, pinned to exact matching version. Standard monorepo publishing pattern, not a security concern. | ai | |
| dependencies | unvetted-dep:@eslint-react/var | AI (dependencies): Sibling package from the same eslint-react monorepo, pinned to exact matching version. Standard monorepo publishing pattern, not a security concern. | ai | |
| dependencies | unvetted-dep:@eslint-react/core | AI (dependencies): Sibling package from the same eslint-react monorepo, pinned to exact matching version. Standard monorepo publishing pattern, not a security concern. | ai | |
| phantom-deps | phantom-dep:ts-pattern | AI (phantom-deps): Declared in package.json but used transitively or via inlined deps in this monorepo package. Not a security concern. | ai | |
| phantom-deps | phantom-dep:compare-versions | AI (phantom-deps): Declared in package.json but used transitively or via inlined deps in this monorepo package. Not a security concern. | ai | |
| phantom-deps | phantom-dep:@eslint-react/var | AI (phantom-deps): Sibling monorepo package; phantom detection is a false positive for monorepo publishing patterns. | ai | |
| phantom-deps | phantom-dep:@eslint-react/core | AI (phantom-deps): Sibling monorepo package; phantom detection is a false positive for monorepo publishing patterns. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/scope-manager | AI (phantom-deps): Used transitively within the monorepo build; phantom detection is a false positive here. | ai |
Versions (showing 26 of 26)
| Version | Deps | Published |
|---|---|---|
| 5.8.8 | 7 / 9 | |
| 5.8.7 | 7 / 9 | |
| 5.8.6 | 7 / 9 | |
| 5.8.5 | 7 / 9 | |
| 5.8.4 | 7 / 9 | |
| 5.8.3 | 7 / 9 | |
| 5.8.2 | 7 / 9 | |
| 5.8.1 | 7 / 9 | |
| 5.8.0 | 7 / 9 | |
| 5.7.10 | 7 / 9 | |
| 5.7.9 | 7 / 9 | |
| 5.7.8 | 7 / 9 | |
| 5.7.7 | 7 / 9 | |
| 5.7.6 | 7 / 9 | |
| 5.7.5 | 7 / 9 | |
| 5.7.4 | 7 / 9 | |
| 5.7.3 | 7 / 9 | |
| 5.7.2 | 7 / 9 | |
| 5.7.1 | 7 / 9 | |
| 5.7.0 | 7 / 9 | |
| 5.6.6 | 7 / 9 | |
| 5.6.4 | 7 / 9 | |
| 5.6.2 | 6 / 9 | |
| 5.6.0 | 6 / 9 | |
| 4.2.3 | 10 / 6 | |
| 4.2.1 | 10 / 6 |
v5.8.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.6.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.6.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.6.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.