Installations
npm install @camunda/element-templates-json-schema-shared
Developer Guide
Typescript
No
Module System
N/A
Node Version
20.12.2
NPM Version
lerna/8.0.0/node@v20.12.2+arm64 (darwin)
Score
73.3
Supply Chain
68.2
Quality
85
Maintenance
100
Vulnerability
100
License
Releases
Contributors
Languages
JavaScript (100%)
Developer
camunda
Download Statistics
Total Downloads
2,734
Last Day
2
Last Week
8
Last Month
32
Last Year
695
GitHub Statistics
10 Stars
276 Commits
7 Forks
6 Watching
6 Branches
52 Contributors
Package Meta Information
Latest Version
0.11.0
Package Id
@camunda/element-templates-json-schema-shared@0.11.0
Unpacked Size
17.98 kB
Size
4.02 kB
File Count
9
NPM Version
lerna/8.0.0/node@v20.12.2+arm64 (darwin)
Node Version
20.12.2
Publised On
29 May 2024
Total Downloads
Cumulative downloads
Total Downloads
2,734
Last day
0%
2
Compared to previous day
Last week
-42.9%
8
Compared to previous week
Last month
-23.8%
32
Compared to previous month
Last year
-43.5%
695
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
No dependencies detected.
@camunda/element-templates-json-schema-shared
Shared schema definitions used within element-templates-json-schema.
License
MIT
No vulnerabilities found.
Reason
22 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Reason
no dangerous workflow patterns detected
Reason
no binaries found in the repo
Reason
6 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275
- Warn: Project is vulnerable to: GHSA-7q7g-4xm8-89cq
- Warn: Project is vulnerable to: GHSA-2p57-rm9w-gvfp
- Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv
- Warn: Project is vulnerable to: GHSA-mwcw-c2x4-8c55
- Warn: Project is vulnerable to: GHSA-f5x3-32g6-xq36
Reason
dependency not pinned by hash detected -- score normalized to 3
Details
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/CI.yml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/camunda/element-templates-json-schema/CI.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/CI.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/camunda/element-templates-json-schema/CI.yml/main?enable=pin
- Info: 0 out of 2 GitHub-owned GitHubAction dependencies pinned
- Info: 1 out of 1 npmCommand dependencies pinned
Reason
Found 4/20 approved changesets -- score normalized to 2
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Warn: no topLevel permission defined: .github/workflows/CI.yml:1
- Info: no jobLevel write permissions found
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
license file not detected
Details
- Warn: project does not have a license file
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Reason
security policy file not detected
Details
- Warn: no security policy file detected
- Warn: no security file to analyze
- Warn: no security file to analyze
- Warn: no security file to analyze
Reason
branch protection not enabled on development/release branches
Details
- Warn: branch protection not enabled for branch 'main'
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 15 are checked with a SAST tool
Score
3.9
/10
Last Scanned on 2025-01-27
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More