{"id":19742154,"url":"https://github.com/merkle-open/eslint-config","last_synced_at":"2025-09-03T18:33:56.824Z","repository":{"id":39587465,"uuid":"61297976","full_name":"merkle-open/eslint-config","owner":"merkle-open","description":"Default configurations for eslint","archived":false,"fork":false,"pushed_at":"2024-07-22T15:10:17.000Z","size":1284,"stargazers_count":14,"open_issues_count":0,"forks_count":5,"subscribers_count":10,"default_branch":"master","last_synced_at":"2025-08-21T21:44:27.230Z","etag":null,"topics":["es2015","eslint","eslintconfig","eslintrc","flow","flowtype","node","react"],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/merkle-open.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2016-06-16T13:58:47.000Z","updated_at":"2024-12-17T13:57:27.000Z","dependencies_parsed_at":"2022-08-31T18:33:48.872Z","dependency_job_id":"86a111d2-0136-4d49-9591-7bb4ef1e1337","html_url":"https://github.com/merkle-open/eslint-config","commit_stats":{"total_commits":242,"total_committers":8,"mean_commits":30.25,"dds":"0.31404958677685946","last_synced_commit":"03544c9a8600c525f0fcda18212d0518c02b522a"},"previous_names":["namics/eslint-config-namics"],"tags_count":42,"template":false,"template_full_name":null,"purl":"pkg:github/merkle-open/eslint-config","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/merkle-open%2Feslint-config","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/merkle-open%2Feslint-config/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/merkle-open%2Feslint-config/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/merkle-open%2Feslint-config/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/merkle-open","download_url":"https://codeload.github.com/merkle-open/eslint-config/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/merkle-open%2Feslint-config/sbom","scorecard":{"id":636976,"data":{"date":"2025-08-11","repo":{"name":"github.com/merkle-open/eslint-config","commit":"fbddfd89542bad972204a609b60ab48c6d0f11e2"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.6,"checks":[{"name":"Code-Review","score":0,"reason":"Found 1/26 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/ci.yml:1","Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Pinned-Dependencies","score":1,"reason":"dependency not pinned by hash detected -- score normalized to 1","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/merkle-open/eslint-config/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/merkle-open/eslint-config/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/merkle-open/eslint-config/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/merkle-open/eslint-config/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/merkle-open/eslint-config/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/merkle-open/eslint-config/codeql-analysis.yml/master?enable=pin","Info:   0 out of   6 GitHub-owned GitHubAction dependencies pinned","Info:   1 out of   1 npmCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"SAST","score":7,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 0 commits out of 6 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":6,"reason":"4 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-968p-4wvh-cqc8","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-21T09:28:07.562Z","repository_id":39587465,"created_at":"2025-08-21T09:28:07.563Z","updated_at":"2025-08-21T09:28:07.563Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":273490377,"owners_count":25115135,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-09-03T02:00:09.631Z","response_time":76,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["es2015","eslint","eslintconfig","eslintrc","flow","flowtype","node","react"],"created_at":"2024-11-12T01:29:24.000Z","updated_at":"2025-09-03T18:33:56.753Z","avatar_url":"https://github.com/merkle-open.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# ESLint config\n\n[![Build Status](https://github.com/merkle-open/eslint-config/workflows/ci/badge.svg)](https://github.com/merkle-open/eslint-config/actions)\n[![npm](https://img.shields.io/npm/v/@merkle-open/eslint-config.svg)](https://www.npmjs.com/package/@merkle-open/eslint-config)\n[![Codestyle](https://img.shields.io/badge/codestyle-merkle-green.svg)](https://github.com/merkle-open/eslint-config)\n\n## Installation\n\n```bash\n$ npm install --save-dev eslint eslint-plugin-import @merkle-open/eslint-config\n```\n\n## Usage Typescript (recommended)\n\n- `@merkle-open/eslint-config/configurations/typescript-browser` - typescript + browser\n- `@merkle-open/eslint-config/configurations/typescript-react` - typescript + react\n- `@merkle-open/eslint-config/configurations/typescript-node` - typescript + node\n\n_package.json_\n\n```json\n{\n  \"scripts\": {\n    \"lint:ts\": \"eslint . --ext .jsx,.js,.ts,.tsx\"\n  }\n}\n```\n\n_Enabling ESLint on TS files in VSCode_\n\nYou need to update the eslint.validate setting to:\n\n```json\n\"eslint.validate\": [\n  \"javascript\",\n  \"javascriptreact\",\n  \"typescript\",\n  \"typescriptreact\"\n]\n```\n\n## Usage ES8 (ES2017)\n\n- `@merkle-open/eslint-config/configurations/es8-browser` - ES8 + browser\n- `@merkle-open/eslint-config/configurations/es8-react` - ES8 + react\n- `@merkle-open/eslint-config/configurations/es8-node` - ES8 + node\n\n## Usage ES7 (ES2016)\n\n- `@merkle-open/eslint-config/configurations/es7-browser` - ES7 + browser (deprecated)\n- `@merkle-open/eslint-config/configurations/es7-react` - ES7 + react (deprecated)\n- `@merkle-open/eslint-config/configurations/es7-node` - ES7 + node\n\n## Usage ES6 (ES2015) - deprecated\n\n- `@merkle-open/eslint-config/configurations/es6-browser` - ES6 + browser (deprecated)\n- `@merkle-open/eslint-config/configurations/es6-react` - ES6 + react (deprecated)\n- `@merkle-open/eslint-config/configurations/es6-node` - ES6 + node (deprecated)\n\n## Usage with Prettier\n\n- [configuration with prettier](./documentation/with-prettier.md)\n\n### .eslintrc.js (add globals here if needed)\n\n```\nmodule.exports = {\n  extends: require.resolve('@merkle-open/eslint-config/configurations/es8-browser.js'),\n};\n```\n\n### .eslintignore\n\n```\n/.idea/\n/node_modules/\n```\n\n### package.json\n\n```\n\"scripts\": {\n  \"lint\": \"npm run lint:js\",\n  \"lint:js\": \"eslint .\"\n},\n```\n\nthen run `npm run lint`\n\n### Example usage in project tree\n\n- .eslintrc.js (es8-react)\n- .eslintignore\n- src\n  - app.jsx\n- test\n  - .eslintrc.js (es8-node)\n  - index.js\n- scripts\n  - .eslintrc.js (es6-node)\n  - index.js\n\n## Documentation\n\n- [Best practices](./documentation/best-practices.md) (ES5/6/7/8)\n- [Style](./documentation/style.md) (ES5/6/7/8)\n- [Variables](./documentation/variables.md) (ES5/6/7/8)\n- [Errors](./documentation/errors.md) (ES5/6/7/8)\n- [Node](./documentation/node.md) (ES5/6/7/8)\n- [ES6](./documentation/es6.md) (ES6/7/8)\n- [ES8](./documentation/es8.md) (ES8)\n- [Imports](./documentation/imports.md) (ES6/7/8)\n- [React](./documentation/react.md) (ES6/7/8)\n- [React A11y](./documentation/react-a11y.md) (ES6/7/8)\n- [React hooks](./documentation/react-hooks.md) (ES6/7/8)\n- [Typescript](./documentation/typescript.md) (typescript)\n\n## Build release\n\n1. Create feature or bugfix branch based on master\n2. Make changes and create pull request, add reviewer, wait for approval\n3. Merge pull request into master\n4. Prepare release notes, adjust package.json to next version ([Semantic Versioning](semantic versioning))\n5. Run `npm publish` (locally) to create npm version\n6. Create and push git tag for version\n7. Add release notes on GitHub\n\n## Thanks to\n\n- [Merkle](https://www.merkleinc.ch/)\n- [ESLint](https://github.com/eslint/eslint) for ESLint and the documentation [eslint.org](http://eslint.org/)\n- [Walmart](https://github.com/walmartlabs) for sharing their config in [eslint-config-walmart](https://github.com/walmartlabs/eslint-config-walmart)\n- [AirBnB](https://github.com/airbnb) for sharing their eslint config in [JavaScript Style Guide](https://github.com/airbnb/javascript)\n\n## License\n\n[MIT License](./LICENSE)\n\n## Changelog\n\nPlease see the [Releases](https://github.com/merkle-open/eslint-config/releases)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmerkle-open%2Feslint-config","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmerkle-open%2Feslint-config","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmerkle-open%2Feslint-config/lists"}