← Home

eslint-plugin-yml

15
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ota-meshi

Keywords

eslinteslintplugineslint-pluginyamlymllint

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:yaml-eslint-parser AI (dependencies): yaml-eslint-parser is authored by the same maintainer (ota-meshi) and is the core YAML parsing dependency for this plugin. Expected and legitimate. ai
dependencies unvetted-dep:@ota-meshi/ast-token-store AI (dependencies): @ota-meshi/ast-token-store is authored by the same maintainer and is a core AST utility dependency. Expected and legitimate. ai
phantom-deps phantom-dep:debug AI (phantom-deps): debug is declared in package.json dependencies and is a well-known logging utility. Minor packaging concern, not a security issue. ai

Versions (showing 15 of 15)

Version Deps Published
3.4.0 7 / 51
3.3.2 7 / 51
3.3.1 8 / 52
3.3.0 8 / 52
3.2.2 8 / 52
3.2.1 8 / 52
3.2.0 8 / 52
3.1.2 7 / 52
3.1.1 7 / 52
3.1.0 7 / 56
3.0.0 7 / 55
2.0.2 7 / 55
2.0.1 7 / 55
2.0.0 7 / 55
1.19.1 6 / 55

v3.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.