Installations
npm install @angular/core
Developer Guide
Typescript
No
Module System
ESM
Min. Node Version
^18.19.1 || ^20.11.1 || >=22.0.0
Node Version
18.19.1
NPM Version
10.2.4
Score
96.8
Supply Chain
75.9
Quality
96.6
Maintenance
100
Vulnerability
99.3
License
Releases
Contributors
Languages
TypeScript (87.8%)
JavaScript (7.14%)
Starlark (2.31%)
HTML (1.28%)
CSS (0.8%)
SCSS (0.55%)
Shell (0.11%)
Nix (0.02%)
Developer
Download Statistics
Total Downloads
848,772,029
Last Day
659,202
Last Week
3,656,253
Last Month
11,441,282
Last Year
175,860,268
GitHub Statistics
96,663 Stars
31,999 Commits
25,750 Forks
3,007 Watching
97 Branches
2,066 Contributors
Package Meta Information
Latest Version
19.1.2
Package Id
@angular/core@19.1.2
Unpacked Size
9.53 MB
Size
2.11 MB
File Count
54
NPM Version
10.2.4
Node Version
18.19.1
Publised On
20 Jan 2025
Total Downloads
Cumulative downloads
Total Downloads
848,772,029
Last day
-1.6%
659,202
Compared to previous day
Last week
2.7%
3,656,253
Compared to previous week
Last month
-25%
11,441,282
Compared to previous month
Last year
6%
175,860,268
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Angular
The sources for this package are in the main Angular repo. Please file issues and pull requests against that repo.
Usage information and reference details can be found in Angular documentation.
License: MIT
Stable Version
Stable Version
19.1.2
MODERATE
3
5.4/10
Summary
Cross site scripting in Angular
Affected Versions
< 10.2.5
Patched Versions
10.2.5
5.4/10
Summary
Cross site scripting in Angular
Affected Versions
>= 11.0.0, < 11.0.5
Patched Versions
11.0.5
5.4/10
Summary
Cross site scripting in Angular
Affected Versions
>= 11.1.0-next.0, <= 11.1.0-next.2
Patched Versions
11.1.0-next.3
Reason
no binaries found in the repo
Reason
1 out of 1 merged PRs checked by a CI test -- score normalized to 10
Reason
project has 38 contributing companies or organizations
Details
- Info: cloudflare contributor org/company found, nx contributor org/company found, aspect-build contributor org/company found, AngularAir contributor org/company found, SofiaJavaScript contributor org/company found, freelance contributor org/company found, angular contributor org/company found, Athens-AngularJS-Meetup contributor org/company found, guess-js contributor org/company found, angular-app contributor org/company found, mend contributor org/company found, yearofmoo-articles contributor org/company found, stealth startup... contributor org/company found, verto contributor org/company found, obshtestvo contributor org/company found, angular @google contributor org/company found, teambit contributor org/company found, angular-ui contributor org/company found, ultimatepp contributor org/company found, ng-bootstrap contributor org/company found, airpair contributor org/company found, facebook contributor org/company found, ngx-translate contributor org/company found, google contributor org/company found, ng-packagr contributor org/company found, 👀 contributor org/company found, yearofmoo contributor org/company found, GoogleDeveloperExperts contributor org/company found, HTTPArchive contributor org/company found, ngTraining contributor org/company found, nrwl contributor org/company found, builder.io contributor org/company found, blueriq contributor org/company found, googlers contributor org/company found, karma-runner contributor org/company found, beerjs contributor org/company found, google-gemini contributor org/company found, aspect contributor org/company found,
Reason
no dangerous workflow patterns detected
Reason
update tool detected
Details
- Info: detected update tool: RenovateBot: renovate.json:1
Reason
project is fuzzed
Details
- Info: OSSFuzz integration found
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: MIT License: LICENSE:0
Reason
30 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
Reason
all dependencies are pinned
Details
- Info: 11 out of 11 GitHub-owned GitHubAction dependencies pinned
- Info: 63 out of 63 third-party GitHubAction dependencies pinned
- Info: 1 out of 1 containerImage dependencies pinned
Reason
security policy file detected
Details
- Info: security policy file detected: SECURITY.md:1
- Info: Found linked content: SECURITY.md:1
- Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1
- Info: Found text in security policy: SECURITY.md:1
Reason
branch protection is not maximal on development and all release branches
Details
- Info: 'allow deletion' disabled on branch 'main'
- Info: 'force pushes' disabled on branch 'main'
- Warn: required approving review count is 1 on branch 'main'
- Warn: codeowners review is not required on branch 'main'
- Warn: no status checks found to merge onto branch 'main'
- Info: PRs are required in order to make changes on branch 'main'
Reason
badge detected: InProgress
Reason
Found 0/30 approved changesets -- score normalized to 0
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 1 are checked with a SAST tool
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/google-internal-tests.yml:12
- Warn: jobLevel 'statuses' permission set to 'write': .github/workflows/google-internal-tests.yml:13
- Info: jobLevel 'actions' permission set to 'read': .github/workflows/scorecard.yml:23
- Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecard.yml:24
- Info: topLevel permissions set to 'read-all': .github/workflows/adev-preview-build.yml:14
- Info: topLevel 'contents' permission set to 'read': .github/workflows/adev-preview-deploy.yml:19
- Info: topLevel 'actions' permission set to 'read': .github/workflows/adev-preview-deploy.yml:21
- Info: topLevel 'contents' permission set to 'read': .github/workflows/assistant-to-the-branch-manager.yml:10
- Info: topLevel permissions set to 'read-all': .github/workflows/benchmark-compare.yml:7
- Info: found token with 'none' permissions: .github/workflows/ci.yml:1
- Info: topLevel 'contents' permission set to 'read': .github/workflows/dev-infra.yml:9
- Info: found token with 'none' permissions: .github/workflows/google-internal-tests.yml:1
- Warn: no topLevel permission defined: .github/workflows/manual.yml:1
- Info: found token with 'none' permissions: .github/workflows/merge-ready-status.yml:1
- Info: topLevel 'contents' permission set to 'read': .github/workflows/perf.yml:9
- Info: found token with 'none' permissions: .github/workflows/pr.yml:1
- Info: topLevel 'contents' permission set to 'read': .github/workflows/scorecard.yml:12
- Info: topLevel 'contents' permission set to 'read': .github/workflows/update-cli-help.yml:13
Reason
71 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-wf5p-g6vw-rhxx
- Warn: Project is vulnerable to: GHSA-qwcr-r2fm-qrc7
- Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg
- Warn: Project is vulnerable to: GHSA-pxg6-pf52-xh8x
- Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275
- Warn: Project is vulnerable to: GHSA-rv95-896h-c2vc
- Warn: Project is vulnerable to: GHSA-qw6h-vgh9-j6wx
- Warn: Project is vulnerable to: GHSA-jchw-25xp-jwwc
- Warn: Project is vulnerable to: GHSA-cxjh-pqwp-8mfp
- Warn: Project is vulnerable to: GHSA-c7qv-q95q-8v27
- Warn: Project is vulnerable to: GHSA-78xj-cgh5-2h22
- Warn: Project is vulnerable to: GHSA-2p57-rm9w-gvfp
- Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv
- Warn: Project is vulnerable to: GHSA-mwcw-c2x4-8c55
- Warn: Project is vulnerable to: GHSA-9wv6-86v2-598j
- Warn: Project is vulnerable to: GHSA-rhx6-c78j-4q9w
- Warn: Project is vulnerable to: GHSA-gcx4-mw62-g8wm
- Warn: Project is vulnerable to: GHSA-m6fv-jmcg-4jfg
- Warn: Project is vulnerable to: GHSA-cm22-4g7w-348p
- Warn: Project is vulnerable to: GHSA-f5x3-32g6-xq36
- Warn: Project is vulnerable to: GHSA-92r3-m2mg-pj97
- Warn: Project is vulnerable to: GHSA-c24v-8rfc-w8vw
- Warn: Project is vulnerable to: GHSA-8jhw-289h-jh2g
- Warn: Project is vulnerable to: GHSA-4vvj-4cpr-p986 / GHSA-64vr-g452-qvp3
- Warn: Project is vulnerable to: GHSA-9cwx-2883-4wfx
- Warn: Project is vulnerable to: GHSA-wr3j-pwj9-hqq6
- Warn: Project is vulnerable to: GHSA-3h5v-q93c-6h6q
- Warn: Project is vulnerable to: GHSA-p8p7-x288-28g6
- Warn: Project is vulnerable to: GHSA-72xf-g2v4-qvf3
- Warn: Project is vulnerable to: GHSA-776f-qx25-q3cc
- Warn: Project is vulnerable to: GHSA-j4f2-536g-r55m
- Warn: Project is vulnerable to: GHSA-r7qp-cfhv-p84w
- Warn: Project is vulnerable to: GHSA-7x7c-qm48-pq9c
- Warn: Project is vulnerable to: GHSA-rc3x-jf5g-xvc5
- Warn: Project is vulnerable to: GHSA-82v2-mx6x-wq7q
- Warn: Project is vulnerable to: GHSA-vh95-rmgr-6w4m
- Warn: Project is vulnerable to: GHSA-xvch-5gv4-984h
- Warn: Project is vulnerable to: GHSA-6fx8-h7jm-663j
- Warn: Project is vulnerable to: GHSA-fxwf-4rqh-v8g3
- Warn: Project is vulnerable to: GHSA-25hc-qcg6-38wj
- Warn: Project is vulnerable to: GHSA-xfhh-g9f5-x4m4
- Warn: Project is vulnerable to: GHSA-qm95-pgcg-qqfq
- Warn: Project is vulnerable to: GHSA-cqmj-92xf-r6r9
- Warn: Project is vulnerable to: GHSA-mgfv-m47x-4wqp
- Warn: Project is vulnerable to: GHSA-72mh-269x-7mh5
- Warn: Project is vulnerable to: GHSA-h4j5-c7cj-74xg
- Warn: Project is vulnerable to: GHSA-gxpj-cx7g-858c
- Warn: Project is vulnerable to: GHSA-394c-5j6w-4xmx
- Warn: Project is vulnerable to: GHSA-78cj-fxph-m83p
- Warn: Project is vulnerable to: GHSA-fhg7-m89q-25r3
- Warn: Project is vulnerable to: GHSA-v88g-cgmw-v5xw
- Warn: Project is vulnerable to: GHSA-f8q6-p94x-37v3
- Warn: Project is vulnerable to: GHSA-89w7-5q45-r53w
- Warn: Project is vulnerable to: GHSA-hrpp-h998-j3pp
- Warn: Project is vulnerable to: GHSA-76p3-8jx3-jpfq
- Warn: Project is vulnerable to: GHSA-3rfm-jhwj-7488
- Warn: Project is vulnerable to: GHSA-hhq3-ff78-jv3g
- Warn: Project is vulnerable to: GHSA-28hp-fgcr-2r4h
- Warn: Project is vulnerable to: GHSA-89mq-4x47-5v83
- Warn: Project is vulnerable to: GHSA-5cp4-xmrw-59wf
- Warn: Project is vulnerable to: GHSA-mhp6-pxh8-r675
- Warn: Project is vulnerable to: GHSA-2qqx-w9hr-q5gx
- Warn: Project is vulnerable to: GHSA-2vrf-hf26-jrp5
- Warn: Project is vulnerable to: GHSA-4w4v-5hc9-xrr2
- Warn: Project is vulnerable to: GHSA-m9gf-397r-hwpg
- Warn: Project is vulnerable to: GHSA-mqm9-c95h-x2p6
- Warn: Project is vulnerable to: GHSA-prc3-vjfx-vhm9
- Warn: Project is vulnerable to: GHSA-qwqh-hm9m-p5hr
- Warn: Project is vulnerable to: GHSA-m2h2-264f-f486
- Warn: Project is vulnerable to: GHSA-cg87-wmx4-v546
- Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw
Score
6.5
/10
Last Scanned on 2025-01-21T18:53:44Z
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More