ESLint plugin with rules that help validate proper imports.
Installations
npm install @uselessscope/eslint-import-resolver-webpack
Developer Guide
Typescript
No
Module System
CommonJS
Min. Node Version
>= 6
Node Version
18.0.0
NPM Version
8.6.0
Releases
Contributors
Languages
JavaScript (99.12%)
HTML (0.46%)
TypeScript (0.2%)
Shell (0.17%)
PowerShell (0.03%)
Batchfile (0.02%)
Love this project? Help keep it running — sponsor us today! 🚀
Developer
import-js
Download Statistics
Total Downloads
0
Last Day
0
Last Week
0
Last Month
0
Last Year
0
GitHub Statistics
MIT License
5,639 Stars
2,311 Commits
1,575 Forks
37 Watchers
16 Branches
364 Contributors
Updated on Feb 18, 2025
Package Meta Information
Latest Version
0.14.9
Package Id
@uselessscope/eslint-import-resolver-webpack@0.14.9
Unpacked Size
18.63 kB
Size
5.75 kB
File Count
4
NPM Version
8.6.0
Node Version
18.0.0
Published on
Mar 11, 2024
Total Downloads
Cumulative downloads
Total Downloads
NaN
Last Day
0%
NaN
Compared to previous day
Last Week
0%
NaN
Compared to previous week
Last Month
0%
NaN
Compared to previous month
Last Year
0%
NaN
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Dependencies
11
Peer Dependencies
1
Dev Dependencies
6
eslint-import-resolver-webpack
Webpack-literate module resolution plugin for eslint-plugin-import
.
:boom: Only "synchronous" Webpack configs are supported at the moment. If your config returns a
Promise
, this will cause problems. Consider splitting your asynchronous configuration to a separate config.
Published separately to allow pegging to a specific version in case of breaking changes.
To use with eslint-plugin-import
, run:
1npm i eslint-import-resolver-webpack -g
or if you manage ESLint as a dev dependency:
1# inside your project's working tree 2npm install eslint-import-resolver-webpack --save-dev
Will look for webpack.config.js
as a sibling of the first ancestral package.json
,
or a config
parameter may be provided with another filename/path either relative to the
package.json
, or a complete, absolute path.
If multiple webpack configurations are found the first configuration containing a resolve section will be used. Optionally, the config-index
(zero-based) setting can be used to select a specific configuration.
1--- 2settings: 3 import/resolver: webpack # take all defaults
or with explicit config file name:
1--- 2settings: 3 import/resolver: 4 webpack: 5 config: 'webpack.dev.config.js'
or with explicit config file index:
1--- 2settings: 3 import/resolver: 4 webpack: 5 config: 'webpack.multiple.config.js' 6 config-index: 1 # take the config at index 1
or with explicit config file path relative to your projects's working directory:
1--- 2settings: 3 import/resolver: 4 webpack: 5 config: './configs/webpack.dev.config.js'
or with explicit config object:
1--- 2settings: 3 import/resolver: 4 webpack: 5 config: 6 resolve: 7 extensions: 8 - .js 9 - .jsx
If your config relies on environment variables, they can be specified using the env
parameter. If your config is a function, it will be invoked with the value assigned to env
:
1--- 2settings: 3 import/resolver: 4 webpack: 5 config: 'webpack.config.js' 6 env: 7 NODE_ENV: 'local' 8 production: true
Support
Get supported eslint-import-resolver-webpack with the Tidelift Subscription

No vulnerabilities found.
Reason
18 commit(s) and 12 issue activity found in the last 90 days -- score normalized to 10
Reason
security policy file detected
Details
- Info: security policy file detected: SECURITY.md:1
- Info: Found linked content: SECURITY.md:1
- Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1
- Info: Found text in security policy: SECURITY.md:1
Reason
no dangerous workflow patterns detected
Reason
no binaries found in the repo
Reason
0 existing vulnerabilities detected
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: MIT License: LICENSE:0
Reason
Found 19/27 approved changesets -- score normalized to 7
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/require-allow-edits.yml:11
- Warn: no topLevel permission defined: .github/workflows/native-wsl.yml:1
- Info: topLevel 'contents' permission set to 'read': .github/workflows/node-4+.yml:10
- Info: topLevel 'contents' permission set to 'read': .github/workflows/node-pretest.yml:6
- Info: topLevel 'contents' permission set to 'read': .github/workflows/packages.yml:10
- Warn: no topLevel permission defined: .github/workflows/rebase.yml:1
- Info: topLevel 'contents' permission set to 'read': .github/workflows/require-allow-edits.yml:6
- Info: no jobLevel write permissions found
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/native-wsl.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/native-wsl.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/native-wsl.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/native-wsl.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/native-wsl.yml:149: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/native-wsl.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-4+.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/node-4+.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/node-4+.yml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/node-4+.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-4+.yml:140: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/node-4+.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-4+.yml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/node-4+.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/node-pretest.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/node-pretest.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-pretest.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/node-pretest.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/node-pretest.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/node-pretest.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-pretest.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/node-pretest.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/packages.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/packages.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/packages.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/packages.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/packages.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/packages.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/packages.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/packages.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/require-allow-edits.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/import-js/eslint-plugin-import/require-allow-edits.yml/main?enable=pin
- Warn: npmCommand not pinned by hash: tests/dep-time-travel.sh:14
- Warn: npmCommand not pinned by hash: tests/dep-time-travel.sh:18
- Warn: npmCommand not pinned by hash: tests/dep-time-travel.sh:23
- Warn: npmCommand not pinned by hash: tests/dep-time-travel.sh:25
- Warn: npmCommand not pinned by hash: tests/dep-time-travel.sh:31
- Warn: npmCommand not pinned by hash: tests/dep-time-travel.sh:34
- Warn: npmCommand not pinned by hash: tests/dep-time-travel.sh:37
- Warn: npmCommand not pinned by hash: tests/dep-time-travel.sh:43
- Warn: npmCommand not pinned by hash: tests/dep-time-travel.sh:49
- Warn: npmCommand not pinned by hash: .github/workflows/node-pretest.yml:32
- Info: 0 out of 5 GitHub-owned GitHubAction dependencies pinned
- Info: 0 out of 11 third-party GitHubAction dependencies pinned
- Info: 0 out of 10 npmCommand dependencies pinned
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 22 are checked with a SAST tool
Score
6.2
/10
Last Scanned on 2025-02-10
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More