eslinter
Simple wrapper around eslint with support for globs and cache, so files that not changed can be skipped, if previous run passed
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require(opts.format) is the standard ESLint formatter loading pattern; expected behavior for an ESLint wrapper tool. | ai | |
| phantom-deps | phantom-dep:babel-eslint | AI (phantom-deps): babel-eslint is a legitimate ESLint parser plugin declared in dependencies; referenced in config files rather than directly imported is normal for ESLint plugins. | ai | |
| phantom-deps | phantom-dep:optionator | AI (phantom-deps): optionator is a legitimate CLI option parsing library declared in dependencies; its use via config is expected for this tool. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react | AI (phantom-deps): eslint-plugin-react is a legitimate ESLint plugin declared in dependencies; referenced in config files is the normal usage pattern for ESLint plugins. | ai | |
| phantom-deps | phantom-dep:eslint-friendly-formatter | AI (phantom-deps): eslint-friendly-formatter is a legitimate ESLint formatter declared in dependencies; referenced in config files is expected for ESLint formatters. | ai |
Versions (showing 21 of 21)
| Version | Deps | Published |
|---|---|---|
| 3.2.1 | 8 / 8 | |
| 3.2.0 | 8 / 8 | |
| 3.1.0 | 7 / 8 | |
| 3.0.2 | 7 / 8 | |
| 3.0.1 | 7 / 8 | |
| 3.0.0 | 7 / 8 | |
| 2.3.3 | 10 / 8 | |
| 2.3.2 | 10 / 8 | |
| 2.3.1 | 10 / 8 | |
| 2.3.0 | 10 / 8 | |
| 2.2.0 | 10 / 8 | |
| 2.1.0 | 9 / 7 | |
| 2.0.6 | 9 / 8 | |
| 2.0.5 | 9 / 8 | |
| 2.0.4 | 9 / 8 | |
| 2.0.3 | 9 / 8 | |
| 2.0.1 | 9 / 8 | |
| 1.0.3 | 8 / 7 | |
| 1.0.2 | 8 / 7 | |
| 1.0.1 | 8 / 8 | |
| 1.0.0 | 8 / 7 |
v3.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.