Installations
npm install devextreme-quill
Developer
Developer Guide
Module System
CommonJS
Min. Node Version
Typescript Support
No
Node Version
18.20.2
NPM Version
10.5.0
Statistics
18 Stars
5,362 Commits
16 Forks
3 Watching
13 Branches
Updated on 25 Oct 2024
Bundle Size
344.84 kB
Minified
68.48 kB
Minified + Gzipped
Languages
JavaScript (92.29%)
Stylus (3%)
TypeScript (2.71%)
HTML (2%)
Total Downloads
Cumulative downloads
Total Downloads
15,822,741
Last day
-8%
22,805
Compared to previous day
Last week
-3%
120,470
Compared to previous week
Last month
0.5%
534,822
Compared to previous month
Last year
26.1%
5,800,965
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Dev Dependencies
41
DevExtreme Quill
The DevExtreme Quill is a fork of Quill, based on the 2.0 branch.
In comparison with the original library, DevExtreme Quill supports basic table operations and enhances lists rendering.
API
Formats
Modules
Modules allow users to customize the DevExtreme Quill's behavior and functionality. The following are official modules:
Guides
Download
- npm -
npm install devextreme-quill
- tar - https://github.com/DevExpress/DevExtreme-quill/releases
CDN
Please refer to the DevExtreme Distribution Channels Guide
License
BSD 3-clause
No vulnerabilities found.
Reason
all changesets reviewed
Reason
no dangerous workflow patterns detected
Reason
no binaries found in the repo
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: BSD 3-Clause "New" or "Revised" License: LICENSE:0
Reason
packaging workflow detected
Details
- Info: Project packages its releases by way of GitHub Actions.: .github/workflows/publish.yml:12
Reason
security policy file detected
Details
- Info: security policy file detected: SECURITY.md:1
- Info: Found linked content: SECURITY.md:1
- Warn: One or no descriptive hints of disclosure, vulnerability, and/or timelines in security policy
- Info: Found text in security policy: SECURITY.md:1
Reason
SAST tool detected but not run on all commits
Details
- Info: SAST configuration detected: CodeQL
- Warn: 0 commits out of 30 are checked with a SAST tool
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql-analysis.yml:26
- Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:27
- Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1
- Warn: no topLevel permission defined: .github/workflows/html-editor-checks.yml:1
- Warn: no topLevel permission defined: .github/workflows/publish.yml:1
- Warn: no topLevel permission defined: .github/workflows/quill-checks.yml:1
- Info: no jobLevel write permissions found
Reason
0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/codeql-analysis.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/codeql-analysis.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/codeql-analysis.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/codeql-analysis.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/html-editor-checks.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/html-editor-checks.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/html-editor-checks.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/html-editor-checks.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/html-editor-checks.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/html-editor-checks.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/html-editor-checks.yml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/html-editor-checks.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/publish.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/publish.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/quill-checks.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/quill-checks.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/quill-checks.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/quill-checks.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/quill-checks.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/quill-checks.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/quill-checks.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/DevExpress/devextreme-quill/quill-checks.yml/master?enable=pin
- Info: 0 out of 14 GitHub-owned GitHubAction dependencies pinned
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Reason
17 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-8hc4-vh64-cxmj
- Warn: Project is vulnerable to: GHSA-qwcr-r2fm-qrc7
- Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg
- Warn: Project is vulnerable to: GHSA-pxg6-pf52-xh8x
- Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275
- Warn: Project is vulnerable to: GHSA-rv95-896h-c2vc
- Warn: Project is vulnerable to: GHSA-qw6h-vgh9-j6wx
- Warn: Project is vulnerable to: GHSA-cxjh-pqwp-8mfp
- Warn: Project is vulnerable to: GHSA-c7qv-q95q-8v27
- Warn: Project is vulnerable to: GHSA-2p57-rm9w-gvfp
- Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv
- Warn: Project is vulnerable to: GHSA-9wv6-86v2-598j
- Warn: Project is vulnerable to: GHSA-m6fv-jmcg-4jfg
- Warn: Project is vulnerable to: GHSA-cm22-4g7w-348p
- Warn: Project is vulnerable to: GHSA-4vvj-4cpr-p986
- Warn: Project is vulnerable to: GHSA-wr3j-pwj9-hqq6
- Warn: Project is vulnerable to: GHSA-3h5v-q93c-6h6q
Score
5.2
/10
Last Scanned on 2024-11-25
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More