
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
@eslint-react/eslint-plugin
Advanced tools
ESLint React's unified ESLint plugin that combines all individual plugins into one.
Composable ESLint rules for React and friends.
eslint-plugin-react-x - X rules (renderer-agnostic, compatible with x-platform).eslint-plugin-react-jsx - React Flavored JSX rules.eslint-plugin-react-rsc - Rules for React Server Components.eslint-plugin-react-dom - DOM-specific rules for React DOM.eslint-plugin-react-web-api - Rules for interacting with Web APIs.eslint-plugin-react-naming-convention - Naming convention rules.@eslint-react/eslint-plugin - A unified plugin that combines all individual plugins into one. Get complete, out-of-the-box rule coverage with instant feedback.[!NOTE]
Don't know which one to use? See our FAQ for guidance.
[!NOTE]
ESLint React requires the following minimum versions:
- Node.js: 22.0.0
- ESLint: 10.3.0
- TypeScript: 5.0.0
npm install --save-dev typescript-eslint @eslint-react/eslint-plugin
// eslint.config.js
import eslintReact from "@eslint-react/eslint-plugin";
import eslintJs from "@eslint/js";
import { defineConfig } from "eslint/config";
import tseslint from "typescript-eslint";
export default defineConfig(
{
files: ["**/*.ts", "**/*.tsx"],
// Extend recommended rule sets from:
// 1. ESLint JS's recommended rules
// 2. TypeScript ESLint recommended rules
// 3. ESLint React's recommended-typescript rules
extends: [
eslintJs.configs.recommended,
tseslint.configs.recommended,
eslintReact.configs["recommended-typescript"],
],
// Configure language/parsing options
languageOptions: {
// Use TypeScript ESLint parser for TypeScript files
parser: tseslint.parser,
parserOptions: {
// Enable project service for better TypeScript integration
projectService: true,
tsconfigRootDir: import.meta.dirname,
},
},
// Custom rule overrides (modify rule levels or disable rules)
rules: {
"@eslint-react/no-missing-key": "warn",
},
},
);
xjsxrscdomweb-apinaming-conventionrecommended
Enforce rules that are recommended by ESLint React for general-purpose React + React DOM projects.
This preset includes the x, jsx, rsc, dom, web-api, and naming-convention presets.
strict
Same as the recommended preset but enables additional strict rules.
recommended-typescript
Same as the recommended preset but disables rules that can be enforced by TypeScript.
recommended-type-checked
Same as the recommended-typescript preset but enables additional rules that require type information.
strict-typescript
Same as the strict preset but disables rules that can be enforced by TypeScript.
strict-type-checked
Same as the strict-typescript preset but enables additional rules that require type information.
disable-jsxjsx preset.disable-rscrsc preset.disable-domdom preset.disable-web-apiweb-api preset.disable-naming-conventionnaming-convention preset.disable-experimentaldisable-type-checkeddisable-conflict-eslint-plugin-reacteslint-plugin-react that conflict with rules in our plugins.disable-conflict-eslint-plugin-react-hookseslint-plugin-react-hooks that conflict with rules in our plugins.offFrequently Asked Questions โ
This project is not affiliated with Meta Platforms, Inc. or the facebook/react project or team, nor is it endorsed or sponsored by them.
This project is, and will remain, 90% of its code written by humans.
A huge thank you to our amazing sponsors who make this project possible.
Contributions are welcome!
This project does not have contributing guidelines. Explore the repository to learn how to contribute.
This project is licensed under the MIT License - see the LICENSE file for details.
FAQs
ESLint React's unified ESLint plugin that combines all individual plugins into one.
The npm package @eslint-react/eslint-plugin receives a total of 1,223,940 weekly downloads. As such, @eslint-react/eslint-plugin popularity was classified as popular.
We found that @eslint-react/eslint-plugin demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago.ย It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.