| Package | Version | Score | Details |
| npm/eslint | ^9.0.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 30 commit(s) and 23 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :green_circle: 7 | Found 21/30 approved changesets -- score normalized to 7 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/eslint | ^8.57.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 30 commit(s) and 23 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :green_circle: 7 | Found 21/30 approved changesets -- score normalized to 7 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/eslint | ^9.0.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 30 commit(s) and 23 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :green_circle: 7 | Found 21/30 approved changesets -- score normalized to 7 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/eslint | ^8.0.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 30 commit(s) and 23 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :green_circle: 7 | Found 21/30 approved changesets -- score normalized to 7 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/@eslint/eslintrc | 3.0.2 |
:green_circle: 6.1 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 8 | Found 18/21 approved changesets -- score normalized to 8 | | Maintained | :green_circle: 5 | 6 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 5 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Security-Policy | :green_circle: 10 | security policy file detected | | Packaging | :green_circle: 10 | packaging workflow detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/@eslint/js | 9.2.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 30 commit(s) and 23 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :green_circle: 7 | Found 21/30 approved changesets -- score normalized to 7 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/@humanwhocodes/config-array | 0.13.0 |
:green_circle: 5.3 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 13 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :green_circle: 4 | Found 7/15 approved changesets -- score normalized to 4 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Fuzzing | :warning: 0 | project is not fuzzed | | Security-Policy | :warning: 0 | security policy file not detected | | Packaging | :green_circle: 10 | packaging workflow detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 2 | dependency not pinned by hash detected -- score normalized to 2 | | Vulnerabilities | :green_circle: 6 | 4 existing vulnerabilities detected |
|
| npm/@humanwhocodes/object-schema | 2.0.3 |
:green_circle: 3.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :warning: 0 | Found 0/23 approved changesets -- score normalized to 0 | | Maintained | :warning: 1 | 2 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 1 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Packaging | :green_circle: 10 | packaging workflow detected | | Security-Policy | :warning: 0 | security policy file not detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Vulnerabilities | :green_circle: 3 | 7 existing vulnerabilities detected | | Pinned-Dependencies | :warning: 2 | dependency not pinned by hash detected -- score normalized to 2 |
|
| npm/@humanwhocodes/retry | 0.2.4 |
Unknown | Unknown |
| npm/eslint | 9.2.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 30 commit(s) and 23 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :green_circle: 7 | Found 21/30 approved changesets -- score normalized to 7 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/eslint-scope | 8.0.1 |
:green_circle: 6.1 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 5 | 6 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5 | | Code-Review | :green_circle: 8 | Found 23/26 approved changesets -- score normalized to 8 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Packaging | :green_circle: 10 | packaging workflow detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/eslint-visitor-keys | 4.0.0 |
:green_circle: 6 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 4 | 5 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 4 | | Code-Review | :green_circle: 8 | Found 22/26 approved changesets -- score normalized to 8 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Packaging | :green_circle: 10 | packaging workflow detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/espree | 10.0.1 |
:green_circle: 5.9 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 7 | Found 18/25 approved changesets -- score normalized to 7 | | Maintained | :green_circle: 4 | 4 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 4 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/file-entry-cache | 8.0.0 |
:green_circle: 3.5 | Details| Check | Score | Reason |
|---|
| Code-Review | :warning: 0 | Found 0/15 approved changesets -- score normalized to 0 | | Maintained | :warning: 1 | 2 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 1 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :warning: 0 | security policy file not detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/flat-cache | 4.0.1 |
:green_circle: 4.8 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 8 | 8 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 8 | | Code-Review | :warning: 2 | Found 2/10 approved changesets -- score normalized to 2 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Packaging | :warning: -1 | packaging workflow not detected | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :warning: 0 | security policy file not detected | | SAST | :green_circle: 6 | SAST tool is not run on all commits -- score normalized to 6 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/globals | 14.0.0 |
:green_circle: 5.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 7 | Found 20/26 approved changesets -- score normalized to 7 | | Maintained | :green_circle: 10 | 30 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Packaging | :warning: -1 | packaging workflow not detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/@eslint/eslintrc | 2.1.4 |
:green_circle: 6.1 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 8 | Found 18/21 approved changesets -- score normalized to 8 | | Maintained | :green_circle: 5 | 6 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 5 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Security-Policy | :green_circle: 10 | security policy file detected | | Packaging | :green_circle: 10 | packaging workflow detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/@eslint/js | 8.57.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 30 commit(s) and 23 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :green_circle: 7 | Found 21/30 approved changesets -- score normalized to 7 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/@humanwhocodes/config-array | 0.11.14 |
:green_circle: 5.3 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 13 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :green_circle: 4 | Found 7/15 approved changesets -- score normalized to 4 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Fuzzing | :warning: 0 | project is not fuzzed | | Security-Policy | :warning: 0 | security policy file not detected | | Packaging | :green_circle: 10 | packaging workflow detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 2 | dependency not pinned by hash detected -- score normalized to 2 | | Vulnerabilities | :green_circle: 6 | 4 existing vulnerabilities detected |
|
| npm/@humanwhocodes/object-schema | 2.0.2 |
:green_circle: 3.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :warning: 0 | Found 0/23 approved changesets -- score normalized to 0 | | Maintained | :warning: 1 | 2 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 1 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Packaging | :green_circle: 10 | packaging workflow detected | | Security-Policy | :warning: 0 | security policy file not detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Vulnerabilities | :green_circle: 3 | 7 existing vulnerabilities detected | | Pinned-Dependencies | :warning: 2 | dependency not pinned by hash detected -- score normalized to 2 |
|
| npm/doctrine | 3.0.0 |
:green_circle: 5.2 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 5 | Found 15/29 approved changesets -- score normalized to 5 | | Maintained | :warning: 0 | project is archived | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Dangerous-Workflow | :warning: -1 | no workflows found | | Token-Permissions | :warning: -1 | No tokens found | | Pinned-Dependencies | :warning: -1 | no dependencies found | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :green_circle: 10 | security policy file detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/eslint | 8.57.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 30 commit(s) and 23 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :green_circle: 7 | Found 21/30 approved changesets -- score normalized to 7 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/eslint-scope | 7.2.2 |
:green_circle: 6.1 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 5 | 6 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5 | | Code-Review | :green_circle: 8 | Found 23/26 approved changesets -- score normalized to 8 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Packaging | :green_circle: 10 | packaging workflow detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/espree | 9.6.1 |
:green_circle: 5.9 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 7 | Found 18/25 approved changesets -- score normalized to 7 | | Maintained | :green_circle: 4 | 4 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 4 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Packaging | :green_circle: 10 | packaging workflow detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/file-entry-cache | 6.0.1 |
:green_circle: 3.5 | Details| Check | Score | Reason |
|---|
| Code-Review | :warning: 0 | Found 0/15 approved changesets -- score normalized to 0 | | Maintained | :warning: 1 | 2 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 1 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :warning: 0 | security policy file not detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/flat-cache | 3.2.0 |
:green_circle: 4.8 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 8 | 8 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 8 | | Code-Review | :warning: 2 | Found 2/10 approved changesets -- score normalized to 2 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Packaging | :warning: -1 | packaging workflow not detected | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :warning: 0 | security policy file not detected | | SAST | :green_circle: 6 | SAST tool is not run on all commits -- score normalized to 6 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/globals | 13.24.0 |
:green_circle: 5.7 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 7 | Found 20/26 approved changesets -- score normalized to 7 | | Maintained | :green_circle: 10 | 30 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Packaging | :warning: -1 | packaging workflow not detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|
| npm/graphemer | 1.4.0 |
:green_circle: 3.9 | Details| Check | Score | Reason |
|---|
| Maintained | :warning: 0 | 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0 | | Code-Review | :warning: 2 | Found 4/20 approved changesets -- score normalized to 2 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Fuzzing | :warning: 0 | project is not fuzzed | | Security-Policy | :warning: 0 | security policy file not detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :green_circle: 3 | dependency not pinned by hash detected -- score normalized to 3 | | Vulnerabilities | :green_circle: 7 | 3 existing vulnerabilities detected |
|
| npm/type-fest | 0.20.2 |
:green_circle: 5.5 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 5 | Found 16/29 approved changesets -- score normalized to 5 | | Maintained | :green_circle: 10 | 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 |
|