Gathering detailed insights and metrics for verdaccio-audit
Gathering detailed insights and metrics for verdaccio-audit
Gathering detailed insights and metrics for verdaccio-audit
Gathering detailed insights and metrics for verdaccio-audit
🏰 Core dependencies and plugins for verdaccio 5.x branch ⚠️ DEPRECATED
npm install verdaccio-audit
49.3
Supply Chain
71.3
Quality
91.3
Maintenance
50
Vulnerability
100
License
verdaccio-aws-s3-storage@10.4.0
Published on 03 May 2024
@verdaccio/local-storage-legacy@11.0.2
Published on 16 Mar 2024
@verdaccio/local-storage-legacy@11.0.1
Published on 16 Mar 2024
@verdaccio/active-directory@10.2.2
Published on 17 Feb 2024
verdaccio-aws-s3-storage@10.3.3
Published on 17 Feb 2024
verdaccio-aws-s3-storage@10.3.2
Published on 02 Sept 2023
Module System
Min. Node Version
Typescript Support
Node Version
NPM Version
81 Stars
1,767 Commits
62 Forks
6 Watching
3 Branches
84 Contributors
Updated on 22 May 2024
Minified
Minified + Gzipped
TypeScript (97.7%)
JavaScript (2.13%)
Dockerfile (0.17%)
Cumulative downloads
Total Downloads
Last day
9.9%
43,245
Compared to previous day
Last week
16.2%
242,505
Compared to previous week
Last month
13.3%
918,625
Compared to previous month
Last year
47.7%
8,727,111
Compared to previous year
4
1
This monorepo contains all the packages that composes the Verdaccio 5.x architecture, except Verdaccio itself and UI.
⚠️ DEPRECATED All packages were moved to verdaccio/verdaccio/
master branch, only security vulnerabilities will be commited on this repo until verdaccio@5.x.x is being is replaced by major release. Features please refer to the main repository. Only bugs and security updates are allowed on this repository.
Please, refer to our CONTRIBUTING to learn how to contribute.
Verdaccio Monorepo is an open source project with MIT license
No vulnerabilities found.
Reason
no dangerous workflow patterns detected
Reason
no binaries found in the repo
Reason
license file detected
Details
Reason
Found 3/10 approved changesets -- score normalized to 3
Reason
0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Reason
detected GitHub workflow tokens with excessive permissions
Details
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
project is not fuzzed
Details
Reason
security policy file not detected
Details
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
Reason
20 existing vulnerabilities detected
Details
Score
Last Scanned on 2024-11-18
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More