| Package | Version | Score | Details |
| npm/@babel/compat-data | 7.24.9 |
:green_circle: 6.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 9 | Found 28/30 approved changesets -- score normalized to 9 | | Maintained | :green_circle: 10 | 30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 | | License | :green_circle: 10 | license file detected | | CII-Best-Practices | :warning: 2 | badge detected: InProgress | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Token-Permissions | :green_circle: 9 | detected GitHub workflow tokens with excessive permissions | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :warning: 0 | 16 existing vulnerabilities detected |
|
| npm/@babel/core | 7.24.9 |
:green_circle: 6.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 9 | Found 28/30 approved changesets -- score normalized to 9 | | Maintained | :green_circle: 10 | 30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 | | License | :green_circle: 10 | license file detected | | CII-Best-Practices | :warning: 2 | badge detected: InProgress | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Token-Permissions | :green_circle: 9 | detected GitHub workflow tokens with excessive permissions | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :warning: 0 | 16 existing vulnerabilities detected |
|
| npm/@babel/eslint-parser | 7.24.8 |
:green_circle: 6.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 9 | Found 28/30 approved changesets -- score normalized to 9 | | Maintained | :green_circle: 10 | 30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 | | License | :green_circle: 10 | license file detected | | CII-Best-Practices | :warning: 2 | badge detected: InProgress | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Token-Permissions | :green_circle: 9 | detected GitHub workflow tokens with excessive permissions | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :warning: 0 | 16 existing vulnerabilities detected |
|
| npm/@babel/generator | 7.24.9 |
:green_circle: 6.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 9 | Found 28/30 approved changesets -- score normalized to 9 | | Maintained | :green_circle: 10 | 30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 | | License | :green_circle: 10 | license file detected | | CII-Best-Practices | :warning: 2 | badge detected: InProgress | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Token-Permissions | :green_circle: 9 | detected GitHub workflow tokens with excessive permissions | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :warning: 0 | 16 existing vulnerabilities detected |
|
| npm/@babel/helper-compilation-targets | 7.24.8 |
:green_circle: 6.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 9 | Found 28/30 approved changesets -- score normalized to 9 | | Maintained | :green_circle: 10 | 30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 | | License | :green_circle: 10 | license file detected | | CII-Best-Practices | :warning: 2 | badge detected: InProgress | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Token-Permissions | :green_circle: 9 | detected GitHub workflow tokens with excessive permissions | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :warning: 0 | 16 existing vulnerabilities detected |
|
| npm/@babel/helper-module-transforms | 7.24.9 |
:green_circle: 6.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 9 | Found 28/30 approved changesets -- score normalized to 9 | | Maintained | :green_circle: 10 | 30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 | | License | :green_circle: 10 | license file detected | | CII-Best-Practices | :warning: 2 | badge detected: InProgress | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Token-Permissions | :green_circle: 9 | detected GitHub workflow tokens with excessive permissions | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :warning: 0 | 16 existing vulnerabilities detected |
|
| npm/@babel/helper-string-parser | 7.24.8 |
:green_circle: 6.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 9 | Found 28/30 approved changesets -- score normalized to 9 | | Maintained | :green_circle: 10 | 30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 | | License | :green_circle: 10 | license file detected | | CII-Best-Practices | :warning: 2 | badge detected: InProgress | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Token-Permissions | :green_circle: 9 | detected GitHub workflow tokens with excessive permissions | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :warning: 0 | 16 existing vulnerabilities detected |
|
| npm/@babel/helper-validator-option | 7.24.8 |
:green_circle: 6.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 9 | Found 28/30 approved changesets -- score normalized to 9 | | Maintained | :green_circle: 10 | 30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 | | License | :green_circle: 10 | license file detected | | CII-Best-Practices | :warning: 2 | badge detected: InProgress | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Token-Permissions | :green_circle: 9 | detected GitHub workflow tokens with excessive permissions | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :warning: 0 | 16 existing vulnerabilities detected |
|
| npm/@babel/helpers | 7.24.8 |
:green_circle: 6.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 9 | Found 28/30 approved changesets -- score normalized to 9 | | Maintained | :green_circle: 10 | 30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 | | License | :green_circle: 10 | license file detected | | CII-Best-Practices | :warning: 2 | badge detected: InProgress | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Token-Permissions | :green_circle: 9 | detected GitHub workflow tokens with excessive permissions | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :warning: 0 | 16 existing vulnerabilities detected |
|
| npm/@babel/parser | 7.24.8 |
:green_circle: 6.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 9 | Found 28/30 approved changesets -- score normalized to 9 | | Maintained | :green_circle: 10 | 30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 | | License | :green_circle: 10 | license file detected | | CII-Best-Practices | :warning: 2 | badge detected: InProgress | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Token-Permissions | :green_circle: 9 | detected GitHub workflow tokens with excessive permissions | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :warning: 0 | 16 existing vulnerabilities detected |
|
| npm/@babel/traverse | 7.24.8 |
:green_circle: 6.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 9 | Found 28/30 approved changesets -- score normalized to 9 | | Maintained | :green_circle: 10 | 30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 | | License | :green_circle: 10 | license file detected | | CII-Best-Practices | :warning: 2 | badge detected: InProgress | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Token-Permissions | :green_circle: 9 | detected GitHub workflow tokens with excessive permissions | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :warning: 0 | 16 existing vulnerabilities detected |
|
| npm/@babel/types | 7.24.9 |
:green_circle: 6.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 9 | Found 28/30 approved changesets -- score normalized to 9 | | Maintained | :green_circle: 10 | 30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 | | License | :green_circle: 10 | license file detected | | CII-Best-Practices | :warning: 2 | badge detected: InProgress | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Token-Permissions | :green_circle: 9 | detected GitHub workflow tokens with excessive permissions | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :warning: 0 | 16 existing vulnerabilities detected |
|
| npm/browserslist | 4.23.2 |
:green_circle: 4.6 | Details| Check | Score | Reason |
|---|
| Code-Review | :warning: 2 | Found 7/30 approved changesets -- score normalized to 2 | | Maintained | :green_circle: 10 | 11 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Packaging | :warning: -1 | packaging workflow not detected | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Signed-Releases | :warning: -1 | no releases found | | Fuzzing | :warning: 0 | project is not fuzzed | | Security-Policy | :warning: 0 | security policy file not detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected |
|
| npm/caniuse-lite | 1.0.30001642 |
:green_circle: 4.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :warning: 0 | Found 0/28 approved changesets -- score normalized to 0 | | Maintained | :green_circle: 10 | 30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Packaging | :warning: -1 | packaging workflow not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Security-Policy | :warning: 0 | security policy file not detected | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected |
|
| npm/electron-to-chromium | 1.4.827 |
Unknown | Unknown |
| npm/escalade | 3.1.2 |
:green_circle: 3.5 | Details| Check | Score | Reason |
|---|
| Code-Review | :warning: 1 | Found 3/30 approved changesets -- score normalized to 1 | | Maintained | :warning: 0 | 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Packaging | :warning: -1 | packaging workflow not detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Fuzzing | :warning: 0 | project is not fuzzed | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Security-Policy | :warning: 0 | security policy file not detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/picocolors | 1.0.1 |
:green_circle: 4.3 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 4 | 4 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 4 | | Code-Review | :green_circle: 5 | Found 9/17 approved changesets -- score normalized to 5 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Security-Policy | :warning: 0 | security policy file not detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 |
|
| npm/update-browserslist-db | 1.1.0 |
:green_circle: 3.9 | Details| Check | Score | Reason |
|---|
| Code-Review | :warning: 2 | Found 4/18 approved changesets -- score normalized to 2 | | Maintained | :green_circle: 10 | 30 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Packaging | :warning: -1 | packaging workflow not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Fuzzing | :warning: 0 | project is not fuzzed | | Security-Policy | :warning: 0 | security policy file not detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Vulnerabilities | :green_circle: 3 | 7 existing vulnerabilities detected |
|