Skip to content

json_path_absent

Assert a JSONPath query over the document matches nothing; one file-level violation if present.

Semantics:

  • The query must select zero nodes. Any match fires exactly one violation for the file — never per-match, so a $[?…] filter that fans out over every top-level key still yields a single violation.
  • The existence sibling of the value-checking kinds; mirrors file_absent for a path. equals / matches / if_present don’t apply.
  • Useful for forbidding a key: a postinstall script in package.json, a [patch] table in Cargo.toml, or write-all permissions in a workflow.
OptionTypeRequiredDefaultDescription
pathstringyesJSONPath expression rooted at $. The rule fires one violation per file if the query matches any node (the path must be absent).

Plus the common paths, level, id, and when fields. This table is generated from the JSON Schema; option types and defaults are authoritative.

A package.json that runs a postinstall script

Section titled “A package.json that runs a postinstall script”

The rule fires on this repository:

package.json
package.json
{
"name": "demo",
"version": "1.0.0",
"scripts": {
"postinstall": "node ./scripts/setup.js"
}
}

With this .alint.yml:

version: 1
rules:
- id: no-postinstall-script
kind: json_path_absent
paths: "package.json"
path: "$.scripts.postinstall"
level: error
message: >-
package.json declares a `postinstall` script; these run automatically
on `npm install` and are a common supply-chain foothold.

alint check reports:

Terminal window
--- package.json ---------------------------------------------------------------
x error no-postinstall-script
package.json declares a `postinstall` script; these run
automatically on `npm install` and are a common supply-chain
foothold.
Summary (1 violation):
x 1 error
0 passing * 1 failing

This repository is compliant:

package.json
package.json
{
"name": "demo",
"version": "1.0.0",
"scripts": {
"build": "tsc"
}
}

With this .alint.yml:

version: 1
rules:
- id: no-postinstall-script
kind: json_path_absent
paths: "package.json"
path: "$.scripts.postinstall"
level: error

alint check reports:

Terminal window
v All 1 rule(s) passed.