Gathering detailed insights and metrics for @keystone-6/core
Gathering detailed insights and metrics for @keystone-6/core
Gathering detailed insights and metrics for @keystone-6/core
Gathering detailed insights and metrics for @keystone-6/core
@mirrormedia/lilith-core
## Installation
@keystone-6-master/core
Keystone-6 is the latest version of Keystone. To get help with this package join the conversation in [Slack](https://community.keystonejs.com/), or [Github](https://github.com/keystonejs/keystone/).
@kids-reporter/cms-core
### Installation
@nivalis/keystone-core
Keystone-6 is the latest version of Keystone. To get help with this package join the conversation in [Slack](https://community.keystonejs.com/), or [Github](https://github.com/keystonejs/keystone/).
The superpowered headless CMS for Node.js — built with GraphQL and React
npm install @keystone-6/core
Typescript
Module System
Node Version
NPM Version
TypeScript (98.84%)
JavaScript (0.94%)
HTML (0.23%)
Total Downloads
0
Last Day
0
Last Week
0
Last Month
0
Last Year
0
MIT License
9,623 Stars
8,103 Commits
1,207 Forks
74 Watchers
49 Branches
261 Contributors
Updated on Jul 12, 2025
Latest Version
6.5.1
Package Id
@keystone-6/core@6.5.1
Unpacked Size
3.57 MB
Size
640.86 kB
File Count
733
NPM Version
10.8.2
Node Version
20.19.1
Published on
May 05, 2025
Cumulative downloads
Total Downloads
Last Day
0%
NaN
Compared to previous day
Last Week
0%
NaN
Compared to previous week
Last Month
0%
NaN
Compared to previous month
Last Year
0%
NaN
Compared to previous year
64
Keystone-6 is the latest version of Keystone. To get help with this package join the conversation in Slack, or Github.
Visit https://keystonejs.com/ for docs, and follow @keystonejs on Twitter for the latest updates.
9.8/10
Summary
@keystone-6/core's NODE_ENV defaults to development with esbuild
Affected Versions
>= 3.0.0, < 3.0.2
Patched Versions
3.0.2
9.1/10
Summary
Field-level access-control bypass for multiselect field
Affected Versions
>= 2.2.0, < 2.3.1
Patched Versions
2.3.1
5.3/10
Summary
When `ui.isAccessAllowed` is `undefined`, the `adminMeta` GraphQL query is publicly accessible
Affected Versions
< 5.5.1
Patched Versions
5.5.1
3.1/10
Summary
Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields
Affected Versions
<= 6.4.0
Patched Versions
6.5.0
0/10
Summary
@keystone-6/core's bundled cuid package known to be insecure
Affected Versions
<= 5.3.1
Reason
security policy file detected
Details
Reason
30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10
Reason
no dangerous workflow patterns detected
Reason
license file detected
Details
Reason
no binaries found in the repo
Reason
Found 8/21 approved changesets -- score normalized to 3
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
detected GitHub workflow tokens with excessive permissions
Details
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
Reason
project is not fuzzed
Details
Reason
14 existing vulnerabilities detected
Details
Score
Last Scanned on 2025-07-07
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More