Gathering detailed insights and metrics for @types/spdx-correct
Gathering detailed insights and metrics for @types/spdx-correct
Gathering detailed insights and metrics for @types/spdx-correct
Gathering detailed insights and metrics for @types/spdx-correct
The repository for high quality TypeScript type definitions.
npm install @types/spdx-correct
Typescript
Module System
82.4
Supply Chain
50.2
Quality
75.4
Maintenance
100
Vulnerability
100
License
TypeScript (99.9%)
JavaScript (0.09%)
Shell (0.01%)
Total Downloads
17,524,553
Last Day
2,233
Last Week
11,690
Last Month
40,622
Last Year
785,178
49,025 Stars
88,492 Commits
30,261 Forks
641 Watching
5 Branches
9,977 Contributors
Latest Version
3.1.3
Package Id
@types/spdx-correct@3.1.3
Unpacked Size
2.73 kB
Size
1.54 kB
File Count
5
Publised On
07 Nov 2023
Cumulative downloads
Total Downloads
Last day
5.4%
2,233
Compared to previous day
Last week
35.4%
11,690
Compared to previous week
Last month
-19.8%
40,622
Compared to previous month
Last year
-36.7%
785,178
Compared to previous year
npm install --save @types/spdx-correct
This package contains type definitions for spdx-correct (https://github.com/jslicense/spdx-correct.js#readme).
Files were exported from https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/spdx-correct.
1declare function spdxCorrect(identifier: string, options?: { upgrade: boolean }): string | null;
2export = spdxCorrect;
3
These definitions were written by Jinwoo Lee.
No vulnerabilities found.
Reason
30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Reason
security policy file detected
Details
Reason
no dangerous workflow patterns detected
Reason
0 existing vulnerabilities detected
Reason
no binaries found in the repo
Reason
license file detected
Details
Reason
Found 26/30 approved changesets -- score normalized to 8
Reason
dependency not pinned by hash detected -- score normalized to 8
Details
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
detected GitHub workflow tokens with excessive permissions
Details
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
Reason
project is not fuzzed
Details
Score
Last Scanned on 2025-01-13
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More