Gathering detailed insights and metrics for @backstage/plugin-scaffolder-backend
Gathering detailed insights and metrics for @backstage/plugin-scaffolder-backend
Gathering detailed insights and metrics for @backstage/plugin-scaffolder-backend
Gathering detailed insights and metrics for @backstage/plugin-scaffolder-backend
@backstage/plugin-scaffolder-backend-module-gitlab
@backstage/plugin-scaffolder-backend-module-github
The github module for @backstage/plugin-scaffolder-backend
@backstage/plugin-scaffolder-backend-module-azure
The azure module for @backstage/plugin-scaffolder-backend
@backstage/plugin-scaffolder-backend-module-gerrit
The gerrit module for @backstage/plugin-scaffolder-backend
npm install @backstage/plugin-scaffolder-backend
Typescript
Module System
60.4
Supply Chain
73.8
Quality
92.9
Maintenance
25
Vulnerability
61
License
TypeScript (94.69%)
MDX (2.11%)
JavaScript (1.92%)
CSS (0.73%)
Handlebars (0.22%)
Mustache (0.11%)
HTML (0.05%)
Dockerfile (0.05%)
SCSS (0.05%)
Shell (0.03%)
Makefile (0.03%)
HCL (0.01%)
Total Downloads
5,342,491
Last Day
6,337
Last Week
46,866
Last Month
216,024
Last Year
2,205,325
28,869 Stars
61,370 Commits
6,113 Forks
232 Watching
515 Branches
1,621 Contributors
Latest Version
1.28.0
Package Id
@backstage/plugin-scaffolder-backend@1.28.0
Unpacked Size
1.13 MB
Size
223.75 kB
File Count
114
Publised On
17 Dec 2024
Cumulative downloads
Total Downloads
Last day
-33.2%
6,337
Compared to previous day
Last week
-6.3%
46,866
Compared to previous week
Last month
5.2%
216,024
Compared to previous month
Last year
23.8%
2,205,325
Compared to previous year
53
English | 한국어 | 中文版 | Français
Backstage is an open source framework for building developer portals. Powered by a centralized software catalog, Backstage restores order to your microservices and infrastructure and enables your product teams to ship high-quality code quickly without compromising autonomy.
Backstage unifies all your infrastructure tooling, services, and documentation to create a streamlined development environment from end to end.
Out of the box, Backstage includes:
Backstage was created by Spotify but is now hosted by the Cloud Native Computing Foundation (CNCF) as an Incubation level project. For more information, see the announcement.
For information about the detailed project roadmap including delivered milestones, see the Roadmap.
To start using Backstage, see the Getting Started documentation.
The documentation of Backstage includes:
To engage with our community, you can use the following resources:
See the GOVERNANCE.md document in the backstage/community repository.
Copyright 2020-2024 © The Backstage Authors. All rights reserved. The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our Trademark Usage page: https://www.linuxfoundation.org/trademark-usage
Licensed under the Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0
Please report sensitive security issues using Spotify's bug-bounty program rather than GitHub.
For further details, see our complete security release process.
Stable Version
3
8.1/10
Summary
Backstage Scaffolder plugin has insecure sandbox
Affected Versions
< 1.15.0
Patched Versions
1.15.0
8.5/10
Summary
Path Traversal in @backstage/plugin-scaffolder-backend
Affected Versions
< 0.15.14
Patched Versions
0.15.14
0/10
Summary
RCE vulnerability affecting v1beta3 templates in @backstage/plugin-scaffolder-backend
Affected Versions
< 0.15.14
Patched Versions
0.15.14
1
6.8/10
Summary
Path Traversal in @backstage/plugin-scaffolder-backend
Affected Versions
>= 0.9.4, < 0.15.9
Patched Versions
0.15.9
Reason
no binaries found in the repo
Reason
15 out of 15 merged PRs checked by a CI test -- score normalized to 10
Reason
all changesets reviewed
Reason
project has 17 contributing companies or organizations
Details
Reason
update tool detected
Details
Reason
license file detected
Details
Reason
30 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10
Reason
packaging workflow detected
Details
Reason
SAST tool detected
Details
Reason
security policy file detected
Details
Reason
dependency not pinned by hash detected -- score normalized to 8
Details
Reason
badge detected: InProgress
Reason
dangerous workflow patterns detected
Details
Reason
project is not fuzzed
Details
Reason
detected GitHub workflow tokens with excessive permissions
Details
Reason
28 existing vulnerabilities detected
Details
Score
Last Scanned on 2024-12-23T11:06:03Z
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More