Installations
npm install eslint-config-starstuff
Developer Guide
Typescript
No
Module System
CommonJS
Min. Node Version
>=10
Node Version
22.13.1
NPM Version
10.9.2
Releases
Contributors
Unable to fetch Contributors
Languages
JavaScript (96.63%)
Shell (3.37%)
Love this project? Help keep it running — sponsor us today! 🚀
Developer
keplersj
Download Statistics
Total Downloads
253,668
Last Day
11
Last Week
195
Last Month
1,390
Last Year
13,090
GitHub Statistics
1,103 Commits
3 Watchers
8 Branches
2 Contributors
Updated on Feb 10, 2025
Bundle Size
493.00 B
Minified
287.00 B
Minified + Gzipped
Sponsor this package
Package Meta Information
Latest Version
1.5.110
Package Id
eslint-config-starstuff@1.5.110
Unpacked Size
8.30 kB
Size
3.11 kB
File Count
17
NPM Version
10.9.2
Node Version
22.13.1
Published on
Feb 11, 2025
Total Downloads
Cumulative downloads
Total Downloads
253,668
Last Day
120%
11
Compared to previous day
Last Week
-16.7%
195
Compared to previous week
Last Month
127.9%
1,390
Compared to previous month
Last Year
-72.7%
13,090
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Dependencies
13
Peer Dependencies
1
eslint-config-starstuff
Opinionated, yet simple ESLint config
Philosophy
This config is built with the assumption that you're going to be using Prettier across your project, and want ESLint to provide advice and respect Prettier's formatting. This config aims to share this in a simple, shareable config.
Installation
1npm install --save-dev eslint eslint-config-starstuff
Recommended Usage
The recommended usage of eslint-config-starstuff
is to allow it to configure itself within your project using the auto preset.
To configure your project with the recommended configuration, add the following to your package.json
:
1{ 2 "eslintConfig": { 3 "extends": "starstuff/auto" 4 } 5}
Presets
The following preset are built into the Starstuff ESLint config.
Base
The base configuration is suitable for use is nearly any JavaScript project. It enforces using good code practices using a variety of ESLint plugins and enforces code style using Prettier.
The following ESLint plugins are used in this configuration:
To use this preset add the following to your package.json
:
1{ 2 "eslintConfig": { 3 "extends": "starstuff" 4 } 5}
Recommended
The recommended preset is a shorthand for the auto preset. This follows with conventions in the ESLint ecosystem.
To use this preset add the following to your package.json
:
1{ 2 "eslintConfig": { 3 "extends": "starstuff/recommended" 4 } 5}
Auto
This configuration automatically loads dependency-specific and environment-specific presets, based on project configuration.
To use this preset add the following to your package.json
:
1{ 2 "eslintConfig": { 3 "extends": "starstuff/auto" 4 } 5}
React
To use this preset add the following to your package.json
:
1{ 2 "eslintConfig": { 3 "extends": ["starstuff", "starstuff/react"] 4 } 5}
TypeScript
To use this preset add the following to your package.json
:
1{ 2 "eslintConfig": { 3 "extends": ["starstuff", "starstuff/typescript"] 4 } 5}
License
Copyright 2019-2020 Kepler Sticka-Jones. License ISC

No vulnerabilities found.
Reason
26 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Reason
no binaries found in the repo
Reason
no dangerous workflow patterns detected
Reason
packaging workflow detected
Details
- Info: Project packages its releases by way of GitHub Actions.: .github/workflows/release.yml:9
Reason
dependency not pinned by hash detected -- score normalized to 6
Details
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/node.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/keplersj/eslint-config-starstuff/node.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/keplersj/eslint-config-starstuff/release.yml/master?enable=pin
- Info: 2 out of 4 GitHub-owned GitHubAction dependencies pinned
- Info: 2 out of 2 npmCommand dependencies pinned
Reason
6 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-67hx-6x53-jw92
- Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275
- Warn: Project is vulnerable to: GHSA-9c47-m6qq-7p4h
- Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw
- Warn: Project is vulnerable to: GHSA-72xf-g2v4-qvf3
- Warn: Project is vulnerable to: GHSA-3h5v-q93c-6h6q
Reason
Found 0/30 approved changesets -- score normalized to 0
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Warn: no topLevel permission defined: .github/workflows/node.yml:1
- Warn: no topLevel permission defined: .github/workflows/release.yml:1
- Info: no jobLevel write permissions found
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
security policy file not detected
Details
- Warn: no security policy file detected
- Warn: no security file to analyze
- Warn: no security file to analyze
- Warn: no security file to analyze
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Reason
license file not detected
Details
- Warn: project does not have a license file
Reason
branch protection not enabled on development/release branches
Details
- Warn: branch protection not enabled for branch 'master'
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 30 are checked with a SAST tool
Score
4.2
/10
Last Scanned on 2025-02-10
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More