Installations
npm install @react-native/eslint-plugin-specs
Developer Guide
Typescript
No
Module System
CommonJS
Min. Node Version
>=18
Node Version
18.20.5
NPM Version
10.8.2
Score
56.9
Supply Chain
55
Quality
94.6
Maintenance
100
Vulnerability
97.9
License
Releases
Contributors
Languages
C++ (29.86%)
JavaScript (16.58%)
Java (14.71%)
Kotlin (13.27%)
Objective-C++ (12.37%)
Objective-C (8.24%)
Ruby (2.86%)
CMake (0.72%)
TypeScript (0.56%)
Shell (0.4%)
C (0.32%)
Assembly (0.1%)
HTML (0.01%)
Swift (0.01%)
Developer
Download Statistics
Total Downloads
463,724
Last Day
134
Last Week
521
Last Month
3,739
Last Year
88,307
GitHub Statistics
120,358 Stars
34,829 Commits
24,461 Forks
3,592 Watching
235 Branches
2,781 Contributors
Bundle Size
1.18 MB
Minified
295.76 kB
Minified + Gzipped
Package Meta Information
Latest Version
0.77.0
Package Id
@react-native/eslint-plugin-specs@0.77.0
Unpacked Size
16.05 kB
Size
4.78 kB
File Count
10
NPM Version
10.8.2
Node Version
18.20.5
Publised On
21 Jan 2025
Total Downloads
Cumulative downloads
Total Downloads
463,724
Last day
14.5%
134
Compared to previous day
Last week
-38.8%
521
Compared to previous week
Last month
-16.9%
3,739
Compared to previous month
Last year
-44.5%
88,307
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
@react-native/eslint-plugin-specs
Installation
yarn add --dev @react-native/eslint-plugin-specs
Note: We're using yarn
to install deps. Feel free to change commands to use npm
3+ and npx
if you like
Testing
To run the tests in this package, run the following commands from the React Native root folder:
yarn
to install the dependencies. You just need to run this onceyarn jest packages/eslint-plugin-specs
.
No vulnerabilities found.
Reason
30 commit(s) and 12 issue activity found in the last 90 days -- score normalized to 10
Reason
all changesets reviewed
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: MIT License: LICENSE:0
Reason
no dangerous workflow patterns detected
Reason
security policy file detected
Details
- Info: security policy file detected: github.com/facebook/.github/SECURITY.md:1
- Info: Found linked content: github.com/facebook/.github/SECURITY.md:1
- Warn: One or no descriptive hints of disclosure, vulnerability, and/or timelines in security policy
- Info: Found text in security policy: github.com/facebook/.github/SECURITY.md:1
Reason
binaries present in source code
Details
- Warn: binary detected: gradle/wrapper/gradle-wrapper.jar:1
- Warn: binary detected: packages/gradle-plugin/gradle/wrapper/gradle-wrapper.jar:1
- Warn: binary detected: packages/helloworld/android/gradle/wrapper/gradle-wrapper.jar:1
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/autorebase.yml:15
- Warn: jobLevel 'contents' permission set to 'write': .github/workflows/autorebase.yml:14
- Info: jobLevel 'contents' permission set to 'read': .github/workflows/needs-attention.yml:13
- Info: topLevel 'contents' permission set to 'read': .github/workflows/autorebase.yml:9
- Warn: no topLevel permission defined: .github/workflows/cache-reaper.yml:1
- Warn: no topLevel permission defined: .github/workflows/check-for-reproducer.yml:1
- Warn: no topLevel permission defined: .github/workflows/check-nightly.yml:1
- Info: topLevel 'contents' permission set to 'read': .github/workflows/close-pr.yml:6
- Warn: no topLevel permission defined: .github/workflows/create-release.yml:1
- Warn: topLevel 'statuses' permission set to 'write': .github/workflows/danger-pr.yml:13
- Warn: topLevel 'actions' permission set to 'write': .github/workflows/danger-pr.yml:8
- Warn: topLevel 'checks' permission set to 'write': .github/workflows/danger-pr.yml:9
- Warn: topLevel 'contents' permission set to 'write': .github/workflows/danger-pr.yml:10
- Info: topLevel 'contents' permission set to 'read': .github/workflows/needs-attention.yml:8
- Warn: no topLevel permission defined: .github/workflows/nightly.yml:1
- Warn: topLevel 'contents' permission set to 'write': .github/workflows/on-issue-labeled.yml:8
- Warn: no topLevel permission defined: .github/workflows/publish-bumped-packages.yml:1
- Warn: no topLevel permission defined: .github/workflows/publish-release.yml:1
- Warn: no topLevel permission defined: .github/workflows/stale-bot.yml:1
- Warn: no topLevel permission defined: .github/workflows/test-all.yml:1
- Warn: no topLevel permission defined: .github/workflows/test-libraries-on-nightlies.yml:1
Reason
no SAST tool detected
Details
- Warn: no pull requests merged into dev branch
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/autorebase.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/autorebase.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/autorebase.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/autorebase.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cache-reaper.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/cache-reaper.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cache-reaper.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/cache-reaper.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-for-reproducer.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/check-for-reproducer.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-for-reproducer.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/check-for-reproducer.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-nightly.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/check-nightly.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/close-pr.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/close-pr.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-release.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/create-release.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/danger-pr.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/danger-pr.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/needs-attention.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/needs-attention.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/needs-attention.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/needs-attention.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/nightly.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:130: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/nightly.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/nightly.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/nightly.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/nightly.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:151: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/nightly.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:184: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/nightly.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/nightly.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/on-issue-labeled.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/on-issue-labeled.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/on-issue-labeled.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/on-issue-labeled.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/on-issue-labeled.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/on-issue-labeled.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/on-issue-labeled.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/on-issue-labeled.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/on-issue-labeled.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/on-issue-labeled.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-bumped-packages.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/publish-bumped-packages.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/publish-release.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:127: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/publish-release.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:148: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/publish-release.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/publish-release.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/publish-release.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:182: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/publish-release.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:194: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/publish-release.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:204: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/publish-release.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/publish-release.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/publish-release.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale-bot.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/stale-bot.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale-bot.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/stale-bot.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale-bot.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/stale-bot.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale-bot.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/stale-bot.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:581: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:609: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:626: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:422: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:459: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:465: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:501: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:128: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:150: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:244: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-all.yml:252: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:256: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:261: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:441: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:530: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:534: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:539: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:566: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:211: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:213: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:403: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:182: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:324: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:330: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:335: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:340: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-all.yml:638: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-all.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-libraries-on-nightlies.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-libraries-on-nightlies.yml/main?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-libraries-on-nightlies.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/react-native/test-libraries-on-nightlies.yml/main?enable=pin
- Info: 0 out of 70 GitHub-owned GitHubAction dependencies pinned
- Info: 0 out of 3 third-party GitHubAction dependencies pinned
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Reason
10 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-2rxp-v6pw-ch6m
- Warn: Project is vulnerable to: GHSA-4xqq-m2hx-25v8
- Warn: Project is vulnerable to: GHSA-5866-49gr-22v4
- Warn: Project is vulnerable to: GHSA-r55c-59qm-vjw6
- Warn: Project is vulnerable to: GHSA-vg3r-rm7w-2xgh
- Warn: Project is vulnerable to: GHSA-vmwr-mc7x-5vc3
- Warn: Project is vulnerable to: GHSA-p8p7-x288-28g6
- Warn: Project is vulnerable to: GHSA-m6fv-jmcg-4jfg
- Warn: Project is vulnerable to: GHSA-cm22-4g7w-348p
- Warn: Project is vulnerable to: GHSA-72xf-g2v4-qvf3
Score
5.1
/10
Last Scanned on 2025-01-27
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More