| Package | Version | Score | Details |
| npm/@eslint-community/regexpp | 4.12.1 |
Unknown | Unknown |
| npm/@eslint/config-array | 0.19.0 |
Unknown | Unknown |
| npm/@eslint/core | 0.9.0 |
Unknown | Unknown |
| npm/@eslint/eslintrc | 3.2.0 |
:green_circle: 6.1 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 4 | 4 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 4 | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Code-Review | :green_circle: 9 | Found 20/21 approved changesets -- score normalized to 9 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | License | :green_circle: 10 | license file detected | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Security-Policy | :green_circle: 10 | security policy file detected | | Packaging | :green_circle: 10 | packaging workflow detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/@eslint/js | 9.16.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 7 | Found 21/28 approved changesets -- score normalized to 7 | | Maintained | :green_circle: 10 | 30 commit(s) and 17 issue activity found in the last 90 days -- score normalized to 10 | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Signed-Releases | :warning: -1 | no releases found | | Security-Policy | :green_circle: 10 | security policy file detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits |
|
| npm/@eslint/object-schema | 2.1.4 |
Unknown | Unknown |
| npm/@eslint/plugin-kit | 0.2.3 |
Unknown | Unknown |
| npm/@humanfs/core | 0.19.1 |
Unknown | Unknown |
| npm/@humanfs/node | 0.16.6 |
Unknown | Unknown |
| npm/@humanwhocodes/retry | 0.3.1 |
Unknown | Unknown |
| npm/@humanwhocodes/retry | 0.4.1 |
Unknown | Unknown |
| npm/@types/estree | 1.0.6 |
:green_circle: 7 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10 | | Packaging | :warning: -1 | packaging workflow not detected | | Code-Review | :green_circle: 9 | Found 27/30 approved changesets -- score normalized to 9 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Security-Policy | :green_circle: 10 | security policy file detected | | License | :green_circle: 9 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :green_circle: 8 | dependency not pinned by hash detected -- score normalized to 8 | | Fuzzing | :warning: 0 | project is not fuzzed |
|
| npm/@types/json-schema | 7.0.15 |
:green_circle: 7 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10 | | Packaging | :warning: -1 | packaging workflow not detected | | Code-Review | :green_circle: 9 | Found 27/30 approved changesets -- score normalized to 9 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Security-Policy | :green_circle: 10 | security policy file detected | | License | :green_circle: 9 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :green_circle: 8 | dependency not pinned by hash detected -- score normalized to 8 | | Fuzzing | :warning: 0 | project is not fuzzed |
|
| npm/acorn | 8.14.0 |
:green_circle: 5.4 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 11 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10 | | Token-Permissions | :green_circle: 10 | GitHub workflow tokens follow principle of least privilege | | Code-Review | :green_circle: 4 | Found 11/26 approved changesets -- score normalized to 4 | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Packaging | :warning: -1 | packaging workflow not detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Security-Policy | :warning: 0 | security policy file not detected | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | License | :warning: 0 | license file not detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/eslint | 9.16.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 7 | Found 21/28 approved changesets -- score normalized to 7 | | Maintained | :green_circle: 10 | 30 commit(s) and 17 issue activity found in the last 90 days -- score normalized to 10 | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Signed-Releases | :warning: -1 | no releases found | | Security-Policy | :green_circle: 10 | security policy file detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits |
|
| npm/eslint-scope | 8.2.0 |
Unknown | Unknown |
| npm/eslint-visitor-keys | 4.2.0 |
Unknown | Unknown |
| npm/espree | 10.3.0 |
Unknown | Unknown |
| npm/file-entry-cache | 8.0.0 |
:green_circle: 4.2 | Details| Check | Score | Reason |
|---|
| Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Packaging | :warning: -1 | packaging workflow not detected | | Code-Review | :warning: 0 | Found 0/14 approved changesets -- score normalized to 0 | | Maintained | :green_circle: 8 | 10 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 8 | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :warning: 0 | security policy file not detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/flat-cache | 4.0.1 |
:green_circle: 4.1 | Details| Check | Score | Reason |
|---|
| Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Code-Review | :warning: 1 | Found 2/14 approved changesets -- score normalized to 1 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Maintained | :warning: 1 | 0 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 1 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Packaging | :warning: -1 | packaging workflow not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Security-Policy | :warning: 0 | security policy file not detected | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Fuzzing | :warning: 0 | project is not fuzzed | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | SAST | :green_circle: 8 | SAST tool is not run on all commits -- score normalized to 8 |
|
| npm/flatted | 3.3.2 |
:green_circle: 3.8 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 4 | 3 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 4 | | Packaging | :warning: -1 | packaging workflow not detected | | Code-Review | :warning: 0 | Found 0/25 approved changesets -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Pinned-Dependencies | :green_circle: 3 | dependency not pinned by hash detected -- score normalized to 3 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Security-Policy | :warning: 0 | security policy file not detected | | Fuzzing | :warning: 0 | project is not fuzzed | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Vulnerabilities | :green_circle: 8 | 2 existing vulnerabilities detected |
|
| npm/globals | 14.0.0 |
:green_circle: 5.4 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 10 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :green_circle: 4 | Found 11/24 approved changesets -- score normalized to 4 | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Packaging | :warning: -1 | packaging workflow not detected | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/eslint | ^9.0.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 7 | Found 21/28 approved changesets -- score normalized to 7 | | Maintained | :green_circle: 10 | 30 commit(s) and 17 issue activity found in the last 90 days -- score normalized to 10 | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Signed-Releases | :warning: -1 | no releases found | | Security-Policy | :green_circle: 10 | security policy file detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits |
|
| npm/eslint | ^9.0.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 7 | Found 21/28 approved changesets -- score normalized to 7 | | Maintained | :green_circle: 10 | 30 commit(s) and 17 issue activity found in the last 90 days -- score normalized to 10 | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Signed-Releases | :warning: -1 | no releases found | | Security-Policy | :green_circle: 10 | security policy file detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits |
|
| npm/@eslint-community/regexpp | 4.12.1 |
Unknown | Unknown |
| npm/@eslint/config-array | 0.19.0 |
Unknown | Unknown |
| npm/@eslint/core | 0.9.0 |
Unknown | Unknown |
| npm/@eslint/eslintrc | 3.2.0 |
:green_circle: 6.1 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 4 | 4 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 4 | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Code-Review | :green_circle: 9 | Found 20/21 approved changesets -- score normalized to 9 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | License | :green_circle: 10 | license file detected | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Security-Policy | :green_circle: 10 | security policy file detected | | Packaging | :green_circle: 10 | packaging workflow detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/@eslint/js | 9.16.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 7 | Found 21/28 approved changesets -- score normalized to 7 | | Maintained | :green_circle: 10 | 30 commit(s) and 17 issue activity found in the last 90 days -- score normalized to 10 | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Signed-Releases | :warning: -1 | no releases found | | Security-Policy | :green_circle: 10 | security policy file detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits |
|
| npm/@eslint/object-schema | 2.1.4 |
Unknown | Unknown |
| npm/@eslint/plugin-kit | 0.2.3 |
Unknown | Unknown |
| npm/@humanfs/core | 0.19.1 |
Unknown | Unknown |
| npm/@humanfs/node | 0.16.6 |
Unknown | Unknown |
| npm/@humanwhocodes/retry | 0.3.1 |
Unknown | Unknown |
| npm/@humanwhocodes/retry | 0.4.1 |
Unknown | Unknown |
| npm/@types/estree | 1.0.6 |
:green_circle: 7 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10 | | Packaging | :warning: -1 | packaging workflow not detected | | Code-Review | :green_circle: 9 | Found 27/30 approved changesets -- score normalized to 9 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Security-Policy | :green_circle: 10 | security policy file detected | | License | :green_circle: 9 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :green_circle: 8 | dependency not pinned by hash detected -- score normalized to 8 | | Fuzzing | :warning: 0 | project is not fuzzed |
|
| npm/acorn | 8.14.0 |
:green_circle: 5.4 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 11 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10 | | Token-Permissions | :green_circle: 10 | GitHub workflow tokens follow principle of least privilege | | Code-Review | :green_circle: 4 | Found 11/26 approved changesets -- score normalized to 4 | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Packaging | :warning: -1 | packaging workflow not detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Security-Policy | :warning: 0 | security policy file not detected | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | License | :warning: 0 | license file not detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/cross-spawn | 7.0.6 |
:green_circle: 3.8 | Details| Check | Score | Reason |
|---|
| Packaging | :warning: -1 | packaging workflow not detected | | Code-Review | :warning: 2 | Found 8/29 approved changesets -- score normalized to 2 | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Maintained | :green_circle: 10 | 13 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10 | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Pinned-Dependencies | :green_circle: 3 | dependency not pinned by hash detected -- score normalized to 3 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Security-Policy | :warning: 0 | security policy file not detected | | License | :green_circle: 10 | license file detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Vulnerabilities | :warning: 0 | 43 existing vulnerabilities detected |
|
| npm/eslint | 9.16.0 |
:green_circle: 6.9 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 7 | Found 21/28 approved changesets -- score normalized to 7 | | Maintained | :green_circle: 10 | 30 commit(s) and 17 issue activity found in the last 90 days -- score normalized to 10 | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Signed-Releases | :warning: -1 | no releases found | | Security-Policy | :green_circle: 10 | security policy file detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits |
|
| npm/eslint-scope | 8.2.0 |
Unknown | Unknown |
| npm/eslint-visitor-keys | 4.2.0 |
Unknown | Unknown |
| npm/espree | 10.3.0 |
Unknown | Unknown |
| npm/file-entry-cache | 8.0.0 |
:green_circle: 4.2 | Details| Check | Score | Reason |
|---|
| Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Packaging | :warning: -1 | packaging workflow not detected | | Code-Review | :warning: 0 | Found 0/14 approved changesets -- score normalized to 0 | | Maintained | :green_circle: 8 | 10 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 8 | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :warning: 0 | security policy file not detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/flat-cache | 4.0.1 |
:green_circle: 4.1 | Details| Check | Score | Reason |
|---|
| Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Code-Review | :warning: 1 | Found 2/14 approved changesets -- score normalized to 1 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Maintained | :warning: 1 | 0 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 1 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Packaging | :warning: -1 | packaging workflow not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Security-Policy | :warning: 0 | security policy file not detected | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Fuzzing | :warning: 0 | project is not fuzzed | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | SAST | :green_circle: 8 | SAST tool is not run on all commits -- score normalized to 8 |
|
| npm/globals | 14.0.0 |
:green_circle: 5.4 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 10 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :green_circle: 4 | Found 11/24 approved changesets -- score normalized to 4 | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Packaging | :warning: -1 | packaging workflow not detected | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|