Installations
npm install @logtail/core
Developer
Developer Guide
Module System
CommonJS
Min. Node Version
Typescript Support
Yes
Node Version
20.3.0
NPM Version
lerna/8.1.5/node@v20.3.0+arm64 (darwin)
Statistics
54 Stars
216 Commits
13 Forks
4 Watching
7 Branches
14 Contributors
Updated on 24 Oct 2024
Languages
TypeScript (95.98%)
JavaScript (4.02%)
Total Downloads
Cumulative downloads
Total Downloads
3,936,274
Last day
1.5%
12,081
Compared to previous day
Last week
0.7%
64,006
Compared to previous week
Last month
2.5%
278,768
Compared to previous month
Last year
92.8%
2,436,027
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Dependencies
3
Better Stack JavaScript client
📣 Logtail is now part of Better Stack. Learn more ⇗
Experience SQL-compatible structured log management based on ClickHouse. Learn more ⇗
Documentation
Need help?
Please let us know at hello@betterstack.com. We're happy to help!
No vulnerabilities found.
Reason
no dangerous workflow patterns detected
Reason
no binaries found in the repo
Reason
license file detected
Details
- Info: project has a license file: LICENSE.md:0
- Info: FSF or OSI recognized license: ISC License: LICENSE.md:0
Reason
5 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275
- Warn: Project is vulnerable to: GHSA-8hc4-vh64-cxmj
- Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv
- Warn: Project is vulnerable to: GHSA-9wv6-86v2-598j
- Warn: Project is vulnerable to: GHSA-4vvj-4cpr-p986
Reason
Found 13/30 approved changesets -- score normalized to 4
Reason
2 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 3
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Warn: no topLevel permission defined: .github/workflows/end-to-end.yml:1
- Warn: no topLevel permission defined: .github/workflows/lint.yml:1
- Warn: no topLevel permission defined: .github/workflows/tests.yml:1
- Info: no jobLevel write permissions found
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/end-to-end.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/logtail/logtail-js/end-to-end.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/end-to-end.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/logtail/logtail-js/end-to-end.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/end-to-end.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/logtail/logtail-js/end-to-end.yml/master?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/end-to-end.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/logtail/logtail-js/end-to-end.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/logtail/logtail-js/lint.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/logtail/logtail-js/lint.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/logtail/logtail-js/tests.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/logtail/logtail-js/tests.yml/master?enable=pin
- Warn: npmCommand not pinned by hash: .github/workflows/lint.yml:35
- Warn: npmCommand not pinned by hash: .github/workflows/tests.yml:45
- Info: 0 out of 7 GitHub-owned GitHubAction dependencies pinned
- Info: 0 out of 1 third-party GitHubAction dependencies pinned
- Info: 0 out of 2 npmCommand dependencies pinned
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
security policy file not detected
Details
- Warn: no security policy file detected
- Warn: no security file to analyze
- Warn: no security file to analyze
- Warn: no security file to analyze
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 15 are checked with a SAST tool
Score
4
/10
Last Scanned on 2024-11-18
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More