@nenlp/modelina-cli

Apache-2.0License declared in the package manifest.

CLI to work with Modelina

90

Security score

0 known advisories in v5.3.7-charp-prognamefix-3

OpenSSF Scorecard 6.8/10

0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.advisory penalty −0 · staleness penalty −0 · scorecard component 68/100 (30% weight)

Weekly downloads

Downloads across all versions in the last 7 days, from the official npm downloads API (api.npmjs.org).

Unpacked size

Size of v5.3.7-charp-prognamefix-3 on disk after npm install extracts the tarball, as reported by the npm registry.

132.4 kB

Dependencies

Direct runtime dependencies declared by v5.3.7-charp-prognamefix-3. Transitive dependencies are not counted here — use the lockfile audit for the full tree.

10

Last publish

When v5.3.7-charp-prognamefix-3 was published to the registry. Long gaps can indicate an unmaintained package.

12 months ago

Security advisories

Vulnerabilities affecting v5.3.7-charp-prognamefix-3 specifically, from OSV.dev — the open database aggregating the GitHub Advisory Database (GHSA) and CVEs. Links open the full advisory.

No known vulnerabilities affect v5.3.7-charp-prognamefix-3.

OpenSSF ScorecardJul 27, 2026

OpenSSF Scorecard is an automated audit of the source repository's security practices, run by the Open Source Security Foundation. Each check scores 0-10; hover a check for what it means. Data via deps.dev.
  • Code-ReviewChanges are reviewed by another maintainer before landing on the main branch.Result: all changesets reviewed10
  • MaintainedThe project shows recent activity: commits or issue triage within the last 90 days.Result: 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 1010
  • CII-Best-PracticesThe project holds an OpenSSF Best Practices badge, a self-certification of security practices.Result: badge detected: InProgress2
  • Binary-ArtifactsNo compiled binaries are committed to the repository — binaries can't be reviewed and may hide malicious code.Result: binaries present in source code8
  • LicenseThe project publishes a license file.Result: license file detected10
  • FuzzingThe project is fuzz-tested (e.g. OSS-Fuzz), which finds crashes and memory bugs automatically.Result: project is not fuzzed0
  • Signed-ReleasesRelease artifacts are cryptographically signed so consumers can verify their origin.Result: Project has not signed or included provenance with any releases.0
  • Security-PolicyA SECURITY.md explains how to report vulnerabilities privately.Result: security policy file detected10
  • PackagingReleases are published through an automated CI/CD pipeline rather than by hand.Result: packaging workflow detected10