npm package report

Is @typescript-eslint/utils safe?

Checked against the XYZ decision brain: known-malicious corpus, advisories, commit-level findings, dependencies and provenance.

cyberxyz.io/packages/npm/typescript-eslint__utils
npm packagelast checked 2026-09-19

@typescript-eslint/utils · verdict ALLOW · no known risk

0.6/10
XYZ SCORE
SUMMARY

Verdict ALLOW · 11 graph-tracked dependencies · 1 flagged · provenance: verified (sigstore)

Re-check live →

SIGNALS
Commit-Level AnalysisclearOK

5 unconfirmed pattern hit(s) in watched commit history; none verified as malicious.

Anomaly HistoryclearOK

12 historical anomaly alert(s) (version_jump) on this package. Add a version to check whether it is affected.

DEPENDENCIES
downlevel-dts@*clean
eslint@^8.57.0 || ^9.0.0 || ^10.0.0clean
@eslint-community/eslint-utils@^4.2.0clean
eslint-scope@^5.1.1block
eslint-utils@^3.0.0clean
jest@29.6.2clean
prettier@^2.8.4clean
rimraf@*clean
semver@^7.3.7clean
typescript@*clean
@typescript-eslint/parser@5.39.1-alpha.25+121f4c0eclean
PACKAGE @typescript-eslint/utilsECOSYSTEM npmDECISION ALLOW

Package facts

Weekly downloads
624.4M
Centrality tier
tier 1
Build provenance
verified (sigstore)
Direct dependencies
11
Flagged dependencies
1

History on this package: popular package (3056 versions over 97d) with pattern-only evidence — de-escalated for review rather than blocked

Baked snapshot · run a live check for the current verdict · browse all packages

Other package reports

ua-parser-jsunderscoreundicitypescript-eslint__typescript-estreetypescript-eslint__rule-testertypescript-eslint__parser

See all package reports or check any package live.