@swc/helpers

Apache-2.0License declared in the package manifest.

External helpers for the swc project.

91

Security score

0 known advisories in v0.5.23

OpenSSF Scorecard 7.1/10

0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.advisory penalty −0 · staleness penalty −0 · scorecard component 71/100 (30% weight)

Weekly downloads

Downloads across all versions in the last 7 days, from the official npm downloads API (api.npmjs.org).

Unpacked size

Size of v0.5.23 on disk after npm install extracts the tarball, as reported by the npm registry.

275.7 kB

Dependencies

Direct runtime dependencies declared by v0.5.23. Transitive dependencies are not counted here — use the lockfile audit for the full tree.

1

Last publish

When v0.5.23 was published to the registry. Long gaps can indicate an unmaintained package.

2 months ago

Security advisories

Vulnerabilities affecting v0.5.23 specifically, from OSV.dev — the open database aggregating the GitHub Advisory Database (GHSA) and CVEs. Links open the full advisory.

No known vulnerabilities affect v0.5.23.

OpenSSF ScorecardJul 20, 2026

OpenSSF Scorecard is an automated audit of the source repository's security practices, run by the Open Source Security Foundation. Each check scores 0-10; hover a check for what it means. Data via deps.dev.
  • Code-ReviewChanges are reviewed by another maintainer before landing on the main branch.Result: Found 19/30 approved changesets -- score normalized to 66
  • CII-Best-PracticesThe project holds an OpenSSF Best Practices badge, a self-certification of security practices.Result: no effort to earn an OpenSSF best practices badge detected0
  • MaintainedThe project shows recent activity: commits or issue triage within the last 90 days.Result: 30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 1010
  • Dangerous-WorkflowGitHub Actions workflows avoid dangerous patterns such as untrusted code checkout or script injection.Result: no dangerous workflow patterns detected10
  • Security-PolicyA SECURITY.md explains how to report vulnerabilities privately.Result: security policy file detected10
  • LicenseThe project publishes a license file.Result: license file detected10
  • Token-PermissionsCI workflow tokens follow least privilege — read-only unless a job needs more.Result: GitHub workflow tokens follow principle of least privilege10
  • FuzzingThe project is fuzz-tested (e.g. OSS-Fuzz), which finds crashes and memory bugs automatically.Result: project is fuzzed10
  • Branch-ProtectionThe default branch is protected: force pushes are blocked and changes require review before merging.Result: branch protection is not maximal on development and all release branches4
  • Signed-ReleasesRelease artifacts are cryptographically signed so consumers can verify their origin.Result: Project has not signed or included provenance with any releases.0
  • PackagingReleases are published through an automated CI/CD pipeline rather than by hand.Result: packaging workflow detected10
  • SASTStatic analysis (e.g. CodeQL) runs on pull requests to catch bugs before merge.Result: SAST tool is not run on all commits -- score normalized to 00
  • Pinned-DependenciesBuild dependencies are pinned to exact versions or hashes, preventing silent supply-chain swaps.Result: dependency not pinned by hash detected -- score normalized to 66
  • Binary-ArtifactsNo compiled binaries are committed to the repository — binaries can't be reviewed and may hide malicious code.Result: no binaries found in the repo10