← Home

eslint-plugin-react-jsx

ESLint React's ESLint plugin for React Flavored JSX rules.

26
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

rel1cx

Keywords

reactjsxeslinteslint-reacteslint-plugineslint-plugin-react-jsx

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@eslint-react/ast AI (dependencies): Sibling package from the same eslint-react monorepo, pinned to exact matching version. Standard monorepo publishing pattern, not a security concern. ai
dependencies unvetted-dep:@eslint-react/jsx AI (dependencies): Sibling package from the same eslint-react monorepo, pinned to exact matching version. Standard monorepo publishing pattern, not a security concern. ai
dependencies unvetted-dep:@eslint-react/var AI (dependencies): Sibling package from the same eslint-react monorepo, pinned to exact matching version. Standard monorepo publishing pattern, not a security concern. ai
dependencies unvetted-dep:@eslint-react/core AI (dependencies): Sibling package from the same eslint-react monorepo, pinned to exact matching version. Standard monorepo publishing pattern, not a security concern. ai
phantom-deps phantom-dep:ts-pattern AI (phantom-deps): Declared in package.json but used transitively or via inlined deps in this monorepo package. Not a security concern. ai
phantom-deps phantom-dep:compare-versions AI (phantom-deps): Declared in package.json but used transitively or via inlined deps in this monorepo package. Not a security concern. ai
phantom-deps phantom-dep:@eslint-react/var AI (phantom-deps): Sibling monorepo package; phantom detection is a false positive for monorepo publishing patterns. ai
phantom-deps phantom-dep:@eslint-react/core AI (phantom-deps): Sibling monorepo package; phantom detection is a false positive for monorepo publishing patterns. ai
phantom-deps phantom-dep:@typescript-eslint/scope-manager AI (phantom-deps): Used transitively within the monorepo build; phantom detection is a false positive here. ai

Versions (showing 26 of 26)

Version Deps Published
5.8.8 7 / 9
5.8.7 7 / 9
5.8.6 7 / 9
5.8.5 7 / 9
5.8.4 7 / 9
5.8.3 7 / 9
5.8.2 7 / 9
5.8.1 7 / 9
5.8.0 7 / 9
5.7.10 7 / 9
5.7.9 7 / 9
5.7.8 7 / 9
5.7.7 7 / 9
5.7.6 7 / 9
5.7.5 7 / 9
5.7.4 7 / 9
5.7.3 7 / 9
5.7.2 7 / 9
5.7.1 7 / 9
5.7.0 7 / 9
5.6.6 7 / 9
5.6.4 7 / 9
5.6.2 6 / 9
5.6.0 6 / 9
4.2.3 10 / 6
4.2.1 10 / 6

v5.8.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.8.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.8.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.8.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.8.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.8.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.7.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.7.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.7.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.7.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.7.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.7.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.7.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.7.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.6.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.6.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.