it-at-m / digiwf-core

central workflow automation and integration platform based on the free process framework Camunda.
MIT License
19 stars 7 forks source link

test dependency review #1838

Closed simonhir closed 4 months ago

simonhir commented 4 months ago

Description

Test for dependency review

Reference

Issues: #xxx

Screenshots (If UI changed)

Check-List

github-actions[bot] commented 4 months ago

Dependency Review

The following issues were found:

See the Details below.

License Issues

digiwf-apps/package-lock.json

PackageVersionLicenseIssue Type
node-forge1.3.1BSD-3-Clause OR GPL-2.0 OR (BSD-3-Clause AND GPL-2.0)Incompatible License

digiwf-apps/package.json

PackageVersionLicenseIssue Type
node-forge^1.3.1NullUnknown License
Denied Licenses: GPL-1.0-or-later, LGPL-2.0-or-later, AGPL-1.0-or-later
Excluded from license check: pkg:npm/escape-string-regexp, pkg:npm/path-exists, pkg:npm/slash, pkg:npm/yocto-queue, pkg:npm/load-script, pkg:maven/com.puppycrawl.tools/checkstyle, pkg:maven/com.hazelcast/hazelcast-spring

OpenSSF Scorecard

PackageVersionScoreDetails
npm/node-forge 1.3.1 :green_circle: 4.4
Details
CheckScoreReason
Code-Review:warning: 0Found 1/24 approved changesets -- score normalized to 0
Maintained:warning: 00 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 0
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 9license file detected
Signed-Releases:warning: -1no releases found
Packaging:warning: -1packaging workflow not detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Security-Policy:green_circle: 9security policy file detected
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts:green_circle: 10no binaries found in the repo
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
Fuzzing:warning: 0project is not fuzzed
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
npm/node-forge ^1.3.1 :green_circle: 4.4
Details
CheckScoreReason
Code-Review:warning: 0Found 1/24 approved changesets -- score normalized to 0
Maintained:warning: 00 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 0
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 9license file detected
Signed-Releases:warning: -1no releases found
Packaging:warning: -1packaging workflow not detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Security-Policy:green_circle: 9security policy file detected
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts:green_circle: 10no binaries found in the repo
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
Fuzzing:warning: 0project is not fuzzed
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0

Scanned Manifest Files

digiwf-apps/package-lock.json
  • @vue/compiler-core@3.4.31
  • @vue/compiler-dom@3.4.31
  • @vue/compiler-sfc@2.7.16
  • @vue/compiler-sfc@3.4.31
  • @vue/compiler-ssr@3.4.31
  • @vue/shared@3.4.31
  • csstype@3.1.3
  • entities@4.5.0
  • magic-string@0.30.10
  • node-forge@1.3.1
  • prettier@2.8.8
  • vue@2.7.16
digiwf-apps/package.json
  • node-forge@^1.3.1
simonhir commented 4 months ago

Just for testing