Installations
npm install @fy-dev/core-rspack
Developer Guide
Typescript
Yes
Module System
CommonJS, ESM
Node Version
16.19.1
NPM Version
8.19.3
Score
40.7
Supply Chain
53.4
Quality
71.3
Maintenance
100
Vulnerability
98.9
License
Releases
v8.5.0-beta.6
Published on 25 Dec 2024
v8.5.0-beta.5
Published on 23 Dec 2024
v8.5.0-beta.4
Published on 20 Dec 2024
v8.5.0-beta.3
Published on 19 Dec 2024
v8.5.0-beta.2
Published on 18 Dec 2024
v8.5.0-beta.1
Published on 16 Dec 2024
Contributors
Languages
TypeScript (73.1%)
JavaScript (24.3%)
MDX (1.11%)
Svelte (0.66%)
Vue (0.29%)
HTML (0.22%)
CSS (0.19%)
EJS (0.06%)
Pug (0.04%)
Handlebars (0.02%)
Shell (0.01%)
Developer
Download Statistics
Total Downloads
344
Last Day
1
Last Week
2
Last Month
3
Last Year
66
GitHub Statistics
84,981 Stars
65,051 Commits
9,372 Forks
934 Watching
595 Branches
1,959 Contributors
Sponsor this package
Package Meta Information
Latest Version
7.0.0-rc.12
Package Id
@fy-dev/core-rspack@7.0.0-rc.12
Unpacked Size
9.45 kB
Size
2.71 kB
File Count
6
NPM Version
8.19.3
Node Version
16.19.1
Publised On
05 Apr 2023
Total Downloads
Cumulative downloads
Total Downloads
344
Last day
0%
1
Compared to previous day
Last week
0%
2
Compared to previous week
Last month
-25%
3
Compared to previous month
Last year
-76.3%
66
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Dev Dependencies
2
Storybook Core-Common
Common utilities used across @storybook/core-server
(manager UI configuration) and @fy-dev/builder-rspack
(preview configuration).
This is a lot of code extracted for convenience, not because it made sense.
No vulnerabilities found.
Reason
no binaries found in the repo
Reason
11 out of 11 merged PRs checked by a CI test -- score normalized to 10
Reason
42 different organizations found -- score normalized to 10
Details
- Info: contributors work for AEB-labs,AtomLinter,Bambuu,ComponentDriven,DiscoverMeteor,M-GaTE,aeb-labs @storybooks,akurulk,async-library,bridge-school,chroma software,chromatic,chromatic (we're hiring),chromaui,chromaui / @storybookjs,cycle-game,defined networking,dependencies-io,eslint,fossasia,freelancer,gdi4k,jetbrains,lab80,legitimatetech,maintainers,meteorhacks,minum,ngx-rocket,nko4,nko5,normative-io,oortcloud,percolatestudio,prolong.io,sem-js,simple-xmpp,sourcejs,storybook-vue,storybookjs,talentsoft,twitter.com/codebyalex
Reason
no dangerous workflow patterns detected
Reason
update tool detected
Details
- Info: Dependabot detected
Reason
license file detected
Details
- Info: : LICENSE:1
Reason
30 commit(s) out of 30 and 11 issue activity out of 30 found in the last 90 days -- score normalized to 10
Reason
security policy file detected
Details
- Info: security policy detected in current repo: SECURITY.md:1
Reason
no vulnerabilities detected
Reason
9 out of last 12 changesets reviewed before merge -- score normalized to 7
Reason
dependency not pinned by hash detected -- score normalized to 7
Details
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/canary-release-pr.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/canary-release-pr.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/canary-release-pr.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/canary-release-pr.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/canary-release-pr.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/canary-release-pr.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/canary-release-pr.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/canary-release-pr.yml/next?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/canary-release-pr.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/canary-release-pr.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cron-weekly.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/cron-weekly.yml/next?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/cron-weekly.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/cron-weekly.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/danger-js.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/danger-js.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/danger-js.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/danger-js.yml/next?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/danger-js.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/danger-js.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-sandboxes.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/generate-sandboxes.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-sandboxes.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/generate-sandboxes.yml/next?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-sandboxes.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/generate-sandboxes.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-sandboxes.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/generate-sandboxes.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-sandboxes.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/generate-sandboxes.yml/next?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-sandboxes.yml:123: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/generate-sandboxes.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/handle-release-branches.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/handle-release-branches.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/handle-release-branches.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/handle-release-branches.yml/next?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/handle-release-branches.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/handle-release-branches.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/handle-release-branches.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/handle-release-branches.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prepare-non-patch-release.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/prepare-non-patch-release.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prepare-non-patch-release.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/prepare-non-patch-release.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prepare-non-patch-release.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/prepare-non-patch-release.yml/next?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/prepare-non-patch-release.yml:181: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/prepare-non-patch-release.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prepare-patch-release.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/prepare-patch-release.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prepare-patch-release.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/prepare-patch-release.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prepare-patch-release.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/prepare-patch-release.yml/next?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/prepare-patch-release.yml:186: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/prepare-patch-release.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/publish.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/publish.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/publish.yml/next?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yml:198: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/publish.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/stale.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-unit.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/tests-unit.yml/next?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-unit.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/tests-unit.yml/next?enable=pin
- Info: Dockerfile dependencies are pinned
- Info: no insecure (not pinned by hash) dependency downloads found in Dockerfiles
- Info: no insecure (not pinned by hash) dependency downloads found in shell scripts
Reason
no badge detected
Reason
project is not fuzzed
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 29 are checked with a SAST tool
- Warn: CodeQL tool not detected
Reason
non read-only tokens detected in GitHub workflows
Details
- Warn: no topLevel permission defined: .github/workflows/cron-weekly.yml:1: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/cron-weekly.yml/next?enable=permissions
- Warn: no topLevel permission defined: .github/workflows/danger-js.yml:1: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/danger-js.yml/next?enable=permissions
- Warn: no topLevel permission defined: .github/workflows/generate-sandboxes.yml:1: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/generate-sandboxes.yml/next?enable=permissions
- Warn: no topLevel permission defined: .github/workflows/handle-release-branches.yml:1: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/handle-release-branches.yml/next?enable=permissions
- Warn: no topLevel permission defined: .github/workflows/prepare-non-patch-release.yml:1: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/prepare-non-patch-release.yml/next?enable=permissions
- Warn: no topLevel permission defined: .github/workflows/prepare-patch-release.yml:1: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/prepare-patch-release.yml/next?enable=permissions
- Warn: topLevel 'contents' permission set to 'write': .github/workflows/publish.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/publish.yml/next?enable=permissions
- Info: topLevel permissions set to 'read-all': .github/workflows/scorecards.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/scorecards.yml/next?enable=permissions
- Warn: no topLevel permission defined: .github/workflows/stale.yml:1: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/stale.yml/next?enable=permissions
- Warn: no topLevel permission defined: .github/workflows/tests-unit.yml:1: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/tests-unit.yml/next?enable=permissions
- Warn: no topLevel permission defined: .github/workflows/trigger-circle-ci-workflow.yml:1: update your workflow using https://app.stepsecurity.io/secureworkflow/storybookjs/storybook/trigger-circle-ci-workflow.yml/next?enable=permissions
Score
7.2
/10
Last Scanned on 2024-03-19
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More