Our API and developer documentation for writing instrumentation will be of help. We particularly recommend the tutorials and various "shim" API documentation.
Usage
In addition to the Koa framework, we support additional specific routing modules.
At New Relic we take your privacy and the security of your information seriously, and are committed to protecting your information. We must emphasize the importance of not sharing personal data in public forums, and ask all users to scrub logs and diagnostic information for sensitive information, whether personal, proprietary, or otherwise.
We define “Personal Data” as any information relating to an identified or identifiable individual, including, for example, your name, phone number, post code or zip code, Device ID, IP address and email address.
We encourage your contributions to improve the koa instrumentation module! Keep in mind when you submit your pull request, you'll need to sign the CLA via the click-through using CLA-Assistant. You only have to sign the CLA one time per project.
If you have any questions, or to execute our corporate CLA, required if your contribution is on behalf of a company, please drop us an email at opensource@newrelic.com.
A note about vulnerabilities
As noted in our security policy, New Relic is committed to the privacy and security of our customers and their data. We believe that providing coordinated disclosure by security researchers and engaging with the security community are important means to achieve our security goals.
If you believe you have found a security vulnerability in this project or any of New Relic's products or websites, we welcome and greatly appreciate you reporting it to New Relic through HackerOne.
If you would like to contribute to this project, review these guidelines.
To all contributors, we thank you! Without your contribution, this project would not be what it is today. We also host a community project page dedicated to New Relic Koa (Node).
License
New Relic Koa instrumentation is licensed under the Apache 2.0 License.
New Relic Koa instrumentation also uses source code from third-party libraries. You can find full details on which libraries are used and the terms under which they are licensed in the third-party notices document.
No vulnerabilities found.
Reason
no dangerous workflow patterns detected
Reason
no binaries found in the repo
Reason
license file detected
Details
Info: project has a license file: LICENSE:0
Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0
Info: Found linked content: github.com/newrelic/.github/SECURITY.md:1
Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/newrelic/.github/SECURITY.md:1
Info: Found text in security policy: github.com/newrelic/.github/SECURITY.md:1
Reason
Found 10/12 approved changesets -- score normalized to 8
Reason
branch protection is not maximal on development and all release branches
Details
Info: 'allow deletion' disabled on branch 'main'
Info: 'force pushes' disabled on branch 'main'
Warn: 'branch protection settings apply to administrators' is disabled on branch 'main'
Info: 'stale review dismissal' is required to merge on branch 'main'
Warn: required approving review count is 1 on branch 'main'
Warn: codeowners review is not required on branch 'main'
Warn: 'last push approval' is disabled on branch 'main'
Info: status check found to merge onto on branch 'main'
Info: PRs are required in order to make changes on branch 'main'
Reason
SAST tool is not run on all commits -- score normalized to 4
Details
Warn: 13 commits out of 28 are checked with a SAST tool
Reason
project is archived
Details
Warn: Repository is archived.
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-workflow.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/ci-workflow.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-workflow.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/ci-workflow.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-workflow.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/ci-workflow.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-workflow.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/ci-workflow.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-workflow.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/ci-workflow.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-workflow.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/ci-workflow.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-workflow.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/ci-workflow.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-workflow.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/ci-workflow.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/repolinter.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/repolinter.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/repolinter.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/repolinter.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/repolinter.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/repolinter.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/validate-pr.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/validate-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/validate-pr.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/validate-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/validate-pr.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/newrelic/node-newrelic-koa/validate-pr.yml/main?enable=pin
Warn: npmCommand not pinned by hash: .github/workflows/ci-workflow.yml:21
Warn: npmCommand not pinned by hash: .github/workflows/ci-workflow.yml:41
Warn: npmCommand not pinned by hash: .github/workflows/ci-workflow.yml:66
Info: 0 out of 8 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 6 third-party GitHubAction dependencies pinned
Info: 0 out of 3 npmCommand dependencies pinned
Reason
detected GitHub workflow tokens with excessive permissions
Details
Warn: no topLevel permission defined: .github/workflows/add-to-board.yml:1
Warn: no topLevel permission defined: .github/workflows/ci-workflow.yml:1
Warn: no topLevel permission defined: .github/workflows/create-release.yml:1
Warn: no topLevel permission defined: .github/workflows/prepare-release.yml:1
Warn: no topLevel permission defined: .github/workflows/repolinter.yml:1
Info: no jobLevel write permissions found
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
project is not fuzzed
Details
Warn: no fuzzer integrations found
Reason
12 existing vulnerabilities detected
Details
Warn: Project is vulnerable to: GHSA-67hx-6x53-jw92
Warn: Project is vulnerable to: GHSA-7v5v-9h63-cj86
Warn: Project is vulnerable to: GHSA-8hc4-vh64-cxmj
Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg
Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275
Warn: Project is vulnerable to: GHSA-593f-38f6-jp5m
Warn: Project is vulnerable to: GHSA-35jh-r3h4-6jhm
Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv
Warn: Project is vulnerable to: GHSA-9wv6-86v2-598j
Warn: Project is vulnerable to: GHSA-rxrc-rgv4-jpvx
Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw
Warn: Project is vulnerable to: GHSA-3h5v-q93c-6h6q
Score
4.6
/10
Last Scanned on 2025-03-03
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.