Installations
npm install @medusajs/cache-redis
Score
51.5
Supply Chain
48.9
Quality
81.2
Maintenance
50
Vulnerability
94.6
License
Developer
Developer Guide
Module System
CommonJS
Min. Node Version
>=20
Typescript Support
Yes
Node Version
21.7.3
NPM Version
10.8.1
Statistics
26,168 Stars
7,146 Commits
2,648 Forks
164 Watching
1,520 Branches
289 Contributors
Updated on 28 Nov 2024
Bundle Size
129.62 kB
Minified
38.83 kB
Minified + Gzipped
Languages
TypeScript (86.28%)
JavaScript (13.38%)
Shell (0.25%)
Handlebars (0.06%)
CSS (0.02%)
Total Downloads
Cumulative downloads
Total Downloads
1,381,242
Last day
3.8%
4,781
Compared to previous day
Last week
1.6%
30,116
Compared to previous week
Last month
12.8%
121,811
Compared to previous month
Last year
538.6%
1,194,235
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Dependencies
1
Peer Dependencies
2
Dev Dependencies
6
Medusa
Documentation | Website
Building blocks for digital commerce
Getting Started
Visit the Documentation to set up a Medusa application.
What is Medusa
Medusa is a set of commerce modules and tools that allow you to build rich, reliable, and performant commerce applications without reinventing core commerce logic. The modules can be customized and used to build advanced ecommerce stores, marketplaces, or any product that needs foundational commerce primitives. All modules are open-source and freely available on npm.
Learn more about Medusa’s architecture and commerce modules in the Docs.
Roadmap, Upgrades & Integrations
You can view the planned, started and completed features in the Roadmap discussion.
Follow the Release Notes to keep your Medusa project up-to-date.
Check out all available Medusa integrations.
Community & Contributions
The community and core team are available in GitHub Discussions, where you can ask for support, discuss roadmap, and share ideas.
Our Contribution Guide describes how to contribute to the codebase and Docs.
Join our Discord server to meet other community members.
Other channels
License
Licensed under the MIT License.
No vulnerabilities found.
Reason
30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
Reason
security policy file detected
Details
- Info: security policy file detected: SECURITY.md:1
- Info: Found linked content: SECURITY.md:1
- Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1
- Info: Found text in security policy: SECURITY.md:1
Reason
no dangerous workflow patterns detected
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: MIT License: LICENSE:0
Reason
no binaries found in the repo
Reason
Found 18/30 approved changesets -- score normalized to 6
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Warn: no topLevel permission defined: .github/workflows/action.yml:1
- Warn: no topLevel permission defined: .github/workflows/admin-i18n-validation.yml:1
- Warn: no topLevel permission defined: .github/workflows/create-linear-issue-on-discussion.yml:1
- Warn: no topLevel permission defined: .github/workflows/create-linear-issue-on-pr.yml:1
- Warn: no topLevel permission defined: .github/workflows/docs-freshness-check.yml:1
- Warn: no topLevel permission defined: .github/workflows/docs-test.yml:1
- Warn: no topLevel permission defined: .github/workflows/docs-update-version.yml:1
- Warn: no topLevel permission defined: .github/workflows/generate-public-references.yml:1
- Warn: no topLevel permission defined: .github/workflows/oas-test.yml:1
- Warn: no topLevel permission defined: .github/workflows/release-notifications.yml:1
- Warn: no topLevel permission defined: .github/workflows/release.yml:1
- Warn: no topLevel permission defined: .github/workflows/snapshot-this.yml:1
- Warn: no topLevel permission defined: .github/workflows/stale-bot.yml:1
- Info: topLevel 'contents' permission set to 'read': .github/workflows/team-labeler.yml:6
- Warn: no topLevel permission defined: .github/workflows/test-cli-with-database.yml:1
- Warn: no topLevel permission defined: .github/workflows/trigger-release.yml:1
- Warn: no topLevel permission defined: .github/workflows/trigger-staging-deployment.yml:1
- Info: no jobLevel write permissions found
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 30 are checked with a SAST tool
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:197: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:272: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/action.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:145: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/admin-i18n-validation.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/admin-i18n-validation.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/admin-i18n-validation.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/admin-i18n-validation.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/create-linear-issue-on-discussion.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/create-linear-issue-on-discussion.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/create-linear-issue-on-pr.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/create-linear-issue-on-pr.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-freshness-check.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-freshness-check.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-freshness-check.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-freshness-check.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-freshness-check.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-freshness-check.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:152: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:169: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:174: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:209: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:226: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:231: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:267: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:284: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:289: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:325: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:342: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:347: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:364: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:369: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-update-version.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-update-version.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-update-version.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-update-version.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-update-version.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-update-version.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-update-version.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-update-version.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:150: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:166: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:171: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:176: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:206: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:221: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:226: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:231: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:257: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/oas-test.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/oas-test.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/oas-test.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/oas-test.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/oas-test.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/oas-test.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snapshot-this.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/snapshot-this.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snapshot-this.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/snapshot-this.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snapshot-this.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/snapshot-this.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snapshot-this.yml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/snapshot-this.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale-bot.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/stale-bot.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/team-labeler.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/team-labeler.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/team-labeler.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/team-labeler.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-cli-with-database.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/test-cli-with-database.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin
- Warn: downloadThenRun not pinned by hash: integration-tests/scripts/cli/get-products.sh:5
- Warn: npmCommand not pinned by hash: .github/workflows/test-cli-with-database.yml:51
- Info: 0 out of 44 GitHub-owned GitHubAction dependencies pinned
- Info: 0 out of 34 third-party GitHubAction dependencies pinned
- Info: 0 out of 1 downloadThenRun dependencies pinned
- Info: 0 out of 1 npmCommand dependencies pinned
Reason
42 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg
- Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275
- Warn: Project is vulnerable to: GHSA-f6v4-cf5j-vf3w
- Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv
- Warn: Project is vulnerable to: GHSA-3787-6prv-h9w3
- Warn: Project is vulnerable to: GHSA-9qxr-qj54-h672
- Warn: Project is vulnerable to: GHSA-m4v8-wqvr-p9f7
- Warn: Project is vulnerable to: GHSA-3h5v-q93c-6h6q
- Warn: Project is vulnerable to: GHSA-7q7g-4xm8-89cq
- Warn: Project is vulnerable to: GHSA-7v5v-9h63-cj86
- Warn: Project is vulnerable to: GHSA-gx9m-whjm-85jf
- Warn: Project is vulnerable to: GHSA-mmhx-hmjr-r674
- Warn: Project is vulnerable to: GHSA-3wc5-fcw2-2329
- Warn: Project is vulnerable to: GHSA-64fm-8hw2-v72w
- Warn: Project is vulnerable to: GHSA-cvr6-37gx-v8wc
- Warn: Project is vulnerable to: GHSA-f98w-7cxr-ff2h
- Warn: Project is vulnerable to: GHSA-m4gq-x24j-jpmf
- Warn: Project is vulnerable to: GHSA-7fh5-64p2-3v2j
- Warn: Project is vulnerable to: GHSA-gcx4-mw62-g8wm
- Warn: Project is vulnerable to: GHSA-f5x3-32g6-xq36
- Warn: Project is vulnerable to: GHSA-fwr7-v2mv-hh25
- Warn: Project is vulnerable to: GHSA-wf5p-g6vw-rhxx
- Warn: Project is vulnerable to: GHSA-8hc4-vh64-cxmj
- Warn: Project is vulnerable to: GHSA-qwcr-r2fm-qrc7
- Warn: Project is vulnerable to: GHSA-pxg6-pf52-xh8x
- Warn: Project is vulnerable to: GHSA-rv95-896h-c2vc
- Warn: Project is vulnerable to: GHSA-qw6h-vgh9-j6wx
- Warn: Project is vulnerable to: GHSA-8cf7-32gw-wr33
- Warn: Project is vulnerable to: GHSA-hjrf-2m68-5959
- Warn: Project is vulnerable to: GHSA-qwph-4952-7xr6
- Warn: Project is vulnerable to: GHSA-5v2h-r2cx-5xgj
- Warn: Project is vulnerable to: GHSA-rrrm-qjm4-v8hf
- Warn: Project is vulnerable to: GHSA-f8q6-p94x-37v3
- Warn: Project is vulnerable to: GHSA-9wv6-86v2-598j
- Warn: Project is vulnerable to: GHSA-hrpp-h998-j3pp
- Warn: Project is vulnerable to: GHSA-p8p7-x288-28g6
- Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw
- Warn: Project is vulnerable to: GHSA-m6fv-jmcg-4jfg
- Warn: Project is vulnerable to: GHSA-cm22-4g7w-348p
- Warn: Project is vulnerable to: GHSA-72xf-g2v4-qvf3
- Warn: Project is vulnerable to: GHSA-64vr-g452-qvp3
- Warn: Project is vulnerable to: GHSA-9cwx-2883-4wfx
Score
5.1
/10
Last Scanned on 2024-11-18
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More