Gathering detailed insights and metrics for @types/spdx-correct
Gathering detailed insights and metrics for @types/spdx-correct
Gathering detailed insights and metrics for @types/spdx-correct
Gathering detailed insights and metrics for @types/spdx-correct
The repository for high quality TypeScript type definitions.
npm install @types/spdx-correct
Typescript
Module System
84.4
Supply Chain
50.2
Quality
75.4
Maintenance
100
Vulnerability
100
License
TypeScript (99.84%)
JavaScript (0.15%)
Shell (0.01%)
Total Downloads
17,787,335
Last Day
671
Last Week
17,276
Last Month
71,281
Last Year
701,051
NOASSERTION License
49,959 Stars
89,619 Commits
30,421 Forks
641 Watchers
7 Branches
9,958 Contributors
Updated on Jun 26, 2025
Latest Version
3.1.3
Package Id
@types/spdx-correct@3.1.3
Unpacked Size
2.73 kB
Size
1.54 kB
File Count
5
Published on
Nov 07, 2023
Cumulative downloads
Total Downloads
Last Day
-4.3%
671
Compared to previous day
Last Week
-3.6%
17,276
Compared to previous week
Last Month
21.8%
71,281
Compared to previous month
Last Year
-39.6%
701,051
Compared to previous year
npm install --save @types/spdx-correct
This package contains type definitions for spdx-correct (https://github.com/jslicense/spdx-correct.js#readme).
Files were exported from https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/spdx-correct.
1declare function spdxCorrect(identifier: string, options?: { upgrade: boolean }): string | null;
2export = spdxCorrect;
3
These definitions were written by Jinwoo Lee.
No vulnerabilities found.
Reason
30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Reason
security policy file detected
Details
Reason
no dangerous workflow patterns detected
Reason
0 existing vulnerabilities detected
Reason
no binaries found in the repo
Reason
Found 27/30 approved changesets -- score normalized to 9
Reason
license file detected
Details
Reason
dependency not pinned by hash detected -- score normalized to 8
Details
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
detected GitHub workflow tokens with excessive permissions
Details
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
Reason
project is not fuzzed
Details
Score
Last Scanned on 2025-06-23
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More