Installations
npm install aiot-parse5-htmlparser2-tree-adapter
Developer Guide
Typescript
Yes
Module System
ESM
Node Version
20.12.2
NPM Version
10.5.0
Releases
Contributors
Languages
TypeScript (97.82%)
JavaScript (2.16%)
Shell (0.01%)
Developer
inikulin
Download Statistics
Total Downloads
450
Last Day
2
Last Week
2
Last Month
9
Last Year
450
GitHub Statistics
3,718 Stars
1,558 Commits
237 Forks
43 Watching
5 Branches
37 Contributors
Bundle Size
6.17 kB
Minified
2.07 kB
Minified + Gzipped
Sponsor this package
Package Meta Information
Latest Version
1.0.0
Package Id
aiot-parse5-htmlparser2-tree-adapter@1.0.0
Unpacked Size
18.46 kB
Size
3.73 kB
File Count
8
NPM Version
10.5.0
Node Version
20.12.2
Publised On
19 Apr 2024
Total Downloads
Cumulative downloads
Total Downloads
450
Last day
0%
2
Compared to previous day
Last week
-60%
2
Compared to previous week
Last month
200%
9
Compared to previous month
Last year
0%
450
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Dependencies
2
npm install --save parse5-htmlparser2-tree-adapter
📖 Documentation 📖
No vulnerabilities found.
Reason
no dangerous workflow patterns detected
Reason
security policy file detected
Details
- Info: security policy file detected: SECURITY.md:1
- Info: Found linked content: SECURITY.md:1
- Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1
- Info: Found text in security policy: SECURITY.md:1
Reason
30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Reason
all changesets reviewed
Reason
no binaries found in the repo
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: MIT License: LICENSE:0
Reason
SAST tool is run on all commits
Details
- Info: SAST configuration detected: CodeQL
- Info: all commits (30) are checked with a SAST tool
Reason
0 existing vulnerabilities detected
Reason
dependency not pinned by hash detected -- score normalized to 4
Details
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/inikulin/parse5/codeql-analysis.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/inikulin/parse5/codeql-analysis.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/inikulin/parse5/codeql-analysis.yml/master?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/dependabot-automerge.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/inikulin/parse5/dependabot-automerge.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nodejs-test.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/inikulin/parse5/nodejs-test.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nodejs-test.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/inikulin/parse5/nodejs-test.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nodejs-test.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/inikulin/parse5/nodejs-test.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nodejs-test.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/inikulin/parse5/nodejs-test.yml/master?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/nodejs-test.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/inikulin/parse5/nodejs-test.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pages.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/inikulin/parse5/pages.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pages.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/inikulin/parse5/pages.yml/master?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/pages.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/inikulin/parse5/pages.yml/master?enable=pin
- Info: 0 out of 9 GitHub-owned GitHubAction dependencies pinned
- Info: 0 out of 3 third-party GitHubAction dependencies pinned
- Info: 3 out of 3 npmCommand dependencies pinned
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql-analysis.yml:17
- Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:18
- Info: jobLevel 'contents' permission set to 'read': .github/workflows/nodejs-test.yml:34
- Warn: jobLevel 'checks' permission set to 'write': .github/workflows/nodejs-test.yml:35
- Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1
- Warn: topLevel 'contents' permission set to 'write': .github/workflows/dependabot-automerge.yml:7
- Info: topLevel 'contents' permission set to 'read': .github/workflows/nodejs-test.yml:15
- Warn: no topLevel permission defined: .github/workflows/pages.yml:1
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Score
7.5
/10
Last Scanned on 2025-01-27
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More