| Package | Version | Score | Details |
| npm/@vitejs/plugin-react-swc | ^3.7.0 |
Unknown | Unknown |
| npm/@swc/core | 1.7.14 |
:green_circle: 4.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 3 | Found 9/29 approved changesets -- score normalized to 3 | | Maintained | :green_circle: 10 | 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :warning: 0 | security policy file not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :green_circle: 10 | project is fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :warning: 0 | 36 existing vulnerabilities detected |
|
| npm/@swc/core-darwin-arm64 | 1.7.14 |
:green_circle: 4.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 3 | Found 9/29 approved changesets -- score normalized to 3 | | Maintained | :green_circle: 10 | 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :warning: 0 | security policy file not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :green_circle: 10 | project is fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :warning: 0 | 36 existing vulnerabilities detected |
|
| npm/@swc/core-darwin-x64 | 1.7.14 |
:green_circle: 4.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 3 | Found 9/29 approved changesets -- score normalized to 3 | | Maintained | :green_circle: 10 | 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :warning: 0 | security policy file not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :green_circle: 10 | project is fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :warning: 0 | 36 existing vulnerabilities detected |
|
| npm/@swc/core-linux-arm-gnueabihf | 1.7.14 |
:green_circle: 4.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 3 | Found 9/29 approved changesets -- score normalized to 3 | | Maintained | :green_circle: 10 | 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :warning: 0 | security policy file not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :green_circle: 10 | project is fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :warning: 0 | 36 existing vulnerabilities detected |
|
| npm/@swc/core-linux-arm64-gnu | 1.7.14 |
:green_circle: 4.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 3 | Found 9/29 approved changesets -- score normalized to 3 | | Maintained | :green_circle: 10 | 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :warning: 0 | security policy file not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :green_circle: 10 | project is fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :warning: 0 | 36 existing vulnerabilities detected |
|
| npm/@swc/core-linux-arm64-musl | 1.7.14 |
:green_circle: 4.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 3 | Found 9/29 approved changesets -- score normalized to 3 | | Maintained | :green_circle: 10 | 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :warning: 0 | security policy file not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :green_circle: 10 | project is fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :warning: 0 | 36 existing vulnerabilities detected |
|
| npm/@swc/core-linux-x64-gnu | 1.7.14 |
:green_circle: 4.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 3 | Found 9/29 approved changesets -- score normalized to 3 | | Maintained | :green_circle: 10 | 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :warning: 0 | security policy file not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :green_circle: 10 | project is fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :warning: 0 | 36 existing vulnerabilities detected |
|
| npm/@swc/core-linux-x64-musl | 1.7.14 |
:green_circle: 4.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 3 | Found 9/29 approved changesets -- score normalized to 3 | | Maintained | :green_circle: 10 | 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :warning: 0 | security policy file not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :green_circle: 10 | project is fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :warning: 0 | 36 existing vulnerabilities detected |
|
| npm/@swc/core-win32-arm64-msvc | 1.7.14 |
:green_circle: 4.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 3 | Found 9/29 approved changesets -- score normalized to 3 | | Maintained | :green_circle: 10 | 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :warning: 0 | security policy file not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :green_circle: 10 | project is fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :warning: 0 | 36 existing vulnerabilities detected |
|
| npm/@swc/core-win32-ia32-msvc | 1.7.14 |
:green_circle: 4.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 3 | Found 9/29 approved changesets -- score normalized to 3 | | Maintained | :green_circle: 10 | 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :warning: 0 | security policy file not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :green_circle: 10 | project is fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :warning: 0 | 36 existing vulnerabilities detected |
|
| npm/@swc/core-win32-x64-msvc | 1.7.14 |
:green_circle: 4.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 3 | Found 9/29 approved changesets -- score normalized to 3 | | Maintained | :green_circle: 10 | 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :warning: 0 | security policy file not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :green_circle: 10 | project is fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :warning: 0 | 36 existing vulnerabilities detected |
|
| npm/@swc/counter | 0.1.3 |
Unknown | Unknown |
| npm/@swc/types | 0.1.12 |
:green_circle: 4.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 3 | Found 9/29 approved changesets -- score normalized to 3 | | Maintained | :green_circle: 10 | 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :warning: 0 | security policy file not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :green_circle: 10 | project is fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :warning: 0 | 36 existing vulnerabilities detected |
|
| npm/@vitejs/plugin-react-swc | 3.7.0 |
Unknown | Unknown |