{"date":"2026-04-15T17:00:25Z","repo":{"name":"github.com/nodejs/node","commit":"0dceddde2cb2010cccf80cc195189196b83cba12"},"scorecard":{"version":"v5.3.0","commit":"c22063e786c11f9dd714d777a687ff7c4599b600"},"score":6.2,"checks":[{"name":"Maintained","score":10,"reason":"30 commit(s) and 14 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#maintained"}},{"name":"Code-Review","score":8,"reason":"Found 25/30 approved changesets -- score normalized to 8","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#code-review"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dependency-update-tool"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dangerous-workflow"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#packaging"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#security-policy"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#license"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/auto-start-ci.yml:22","Info: jobLevel 'contents' permission set to 'read': .github/workflows/auto-start-ci.yml:42","Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql.yml:15","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:16","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/commit-queue.yml:27","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/license-builder.yml:15","Info: jobLevel 'contents' permission set to 'read': .github/workflows/lint-release-proposal.yml:23","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/lint-release-proposal.yml:24","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/timezone-update.yml:15","Info: topLevel 'contents' permission set to 'read': .github/workflows/auto-start-ci.yml:17","Info: topLevel 'contents' permission set to 'read': .github/workflows/build-tarball.yml:70","Info: topLevel 'contents' permission set to 'read': .github/workflows/close-stale-feature-requests.yml:34","Info: topLevel 'contents' permission set to 'read': .github/workflows/close-stale-pull-requests.yml:29","Info: topLevel 'contents' permission set to 'read': .github/workflows/close-stalled.yml:13","Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:8","Info: topLevel 'contents' permission set to 'read': .github/workflows/comment-labeled.yml:19","Info: topLevel 'contents' permission set to 'read': .github/workflows/commit-lint.yml:13","Info: topLevel 'contents' permission set to 'read': .github/workflows/commit-queue.yml:22","Info: topLevel 'contents' permission set to 'read': .github/workflows/coverage-linux-without-intl.yml:46","Info: topLevel 'contents' permission set to 'read': .github/workflows/coverage-linux.yml:46","Info: topLevel 'contents' permission set to 'read': .github/workflows/coverage-windows.yml:65","Warn: topLevel 'contents' permission set to 'write': .github/workflows/create-release-proposal.yml:24","Info: topLevel 'contents' permission set to 'read': .github/workflows/daily-wpt-fyi.yml:19","Info: topLevel 'contents' permission set to 'read': .github/workflows/daily.yml:12","Info: topLevel 'contents' permission set to 'read': .github/workflows/doc.yml:20","Info: topLevel 'contents' permission set to 'read': .github/workflows/find-inactive-collaborators.yml:14","Info: topLevel 'contents' permission set to 'read': .github/workflows/find-inactive-tsc.yml:14","Info: topLevel 'contents' permission set to 'read': .github/workflows/label-flaky-test-issue.yml:8","Info: topLevel 'contents' permission set to 'read': .github/workflows/label-pr.yml:8","Info: topLevel 'contents' permission set to 'read': .github/workflows/license-builder.yml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/lint-release-proposal.yml:17","Info: topLevel 'contents' permission set to 'read': .github/workflows/linters.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/major-release.yml:8","Info: topLevel 'contents' permission set to 'read': .github/workflows/notify-on-push.yml:8","Info: topLevel 'contents' permission set to 'read': .github/workflows/notify-on-review-wanted.yml:9","Info: topLevel 'contents' permission set to 'read': .github/workflows/post-release.yml:14","Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:19","Info: topLevel 'contents' permission set to 'read': .github/workflows/test-internet.yml:43","Info: topLevel 'contents' permission set to 'read': .github/workflows/test-linux.yml:44","Info: topLevel 'contents' permission set to 'read': .github/workflows/test-macos.yml:72","Info: topLevel 'contents' permission set to 'read': .github/workflows/test-shared.yml:109","Info: topLevel 'contents' permission set to 'read': .github/workflows/timezone-update.yml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/tools.yml:52","Info: topLevel 'contents' permission set to 'read': .github/workflows/update-openssl.yml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/update-v8.yml:12","Info: topLevel 'contents' permission set to 'read': .github/workflows/update-wpt.yml:15"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":5,"reason":"badge detected: Passing","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":0,"reason":"binaries present in source code","details":["Warn: binary detected: deps/undici/src/lib/llhttp/llhttp.wasm:1","Warn: binary detected: deps/undici/src/lib/llhttp/llhttp_simd.wasm:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/async/regress-1115431.wasm:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/async/regress-1405322.wasm:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/async/regression-761784.wasm:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/async/valid.wasm:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/module/regress-1115280.wasm:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/module/regress-1127717.wasm:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/module/regress-1191853.wasm:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/module/regress-1404619.wasm:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/module/regress-1464231.wasm:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/module/regress-406925416.wasm:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/module/regress-419085592.wasm:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/module/regress-449299112.wasm:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/streaming/empty_module:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/streaming/regress-1334577:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/streaming/regress-1335023:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/streaming/regress-1427898:1","Warn: binary detected: deps/v8/test/fuzzer/wasm/streaming/regress-1429613:1","Warn: binary detected: deps/v8/test/mjsunit/wasm/incrementer.wasm:1","Warn: binary detected: deps/v8/third_party/ittapi/include/fortran/posix/x86/ittfortran.o:1","Warn: binary detected: deps/v8/third_party/ittapi/include/fortran/posix/x86_64/ittfortran.o:1","Warn: binary detected: deps/v8/third_party/wasm-api/example/callback.wasm:1","Warn: binary detected: deps/v8/third_party/wasm-api/example/finalize.wasm:1","Warn: binary detected: deps/v8/third_party/wasm-api/example/global.wasm:1","Warn: binary detected: deps/v8/third_party/wasm-api/example/hello.wasm:1","Warn: binary detected: deps/v8/third_party/wasm-api/example/hostref.wasm:1","Warn: binary detected: deps/v8/third_party/wasm-api/example/memory.wasm:1","Warn: binary detected: deps/v8/third_party/wasm-api/example/multi.wasm:1","Warn: binary detected: deps/v8/third_party/wasm-api/example/reflect.wasm:1","Warn: binary detected: deps/v8/third_party/wasm-api/example/serialize.wasm:1","Warn: binary detected: deps/v8/third_party/wasm-api/example/start.wasm:1","Warn: binary detected: deps/v8/third_party/wasm-api/example/table.wasm:1","Warn: binary detected: deps/v8/third_party/wasm-api/example/threads.wasm:1","Warn: binary detected: deps/v8/third_party/wasm-api/example/trap.wasm:1","Warn: binary detected: deps/zlib/google/test/data/evil_via_invalid_utf8.zip:1","Warn: binary detected: test/fixtures/crash.wasm:1","Warn: binary detected: test/fixtures/es-modules/dep.wasm:1","Warn: binary detected: test/fixtures/es-modules/export-name-code-injection.wasm:1","Warn: binary detected: test/fixtures/es-modules/export-name-syntax-error.wasm:1","Warn: binary detected: test/fixtures/es-modules/globals.wasm:1","Warn: binary detected: test/fixtures/es-modules/import-name.wasm:1","Warn: binary detected: test/fixtures/es-modules/invalid-export-name-wasm-js.wasm:1","Warn: binary detected: test/fixtures/es-modules/invalid-export-name.wasm:1","Warn: binary detected: test/fixtures/es-modules/invalid-import-module.wasm:1","Warn: binary detected: test/fixtures/es-modules/invalid-import-name-wasm-js.wasm:1","Warn: binary detected: test/fixtures/es-modules/invalid-import-name.wasm:1","Warn: binary detected: test/fixtures/es-modules/js-string-builtins.wasm:1","Warn: binary detected: test/fixtures/es-modules/noext-wasm:1","Warn: binary detected: test/fixtures/es-modules/package-type-module/node_modules/dep-with-package-json-type-module/noext-wasm:1","Warn: binary detected: test/fixtures/es-modules/package-type-module/noext-wasm:1","Warn: binary detected: test/fixtures/es-modules/simple.wasm:1","Warn: binary detected: test/fixtures/es-modules/top-level-wasm.wasm:1","Warn: binary detected: test/fixtures/es-modules/unimportable.wasm:1","Warn: binary detected: test/fixtures/out-of-bound.wasm:1","Warn: binary detected: test/fixtures/shared-memory.wasm:1","Warn: binary detected: test/fixtures/simple.wasm:1","Warn: binary detected: test/fixtures/wasm/jspi.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/dep.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/exports.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/globals.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/invalid-export-name-wasm-js.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/invalid-export-name.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/invalid-import-module.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/invalid-import-name-wasm-js.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/invalid-import-name.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/js-string-builtins.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/js-wasm-cycle.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/mutable-global-export.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/mutable-global-reexport.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/resolve-export.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/wasm-export-to-wasm.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/jsapi/esm-integration/resources/wasm-import-from-wasm.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/execute-start.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/exported-names.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/invalid-bytecode.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/invalid-module.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/js-wasm-cycle-function-error.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/js-wasm-cycle-global.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/js-wasm-cycle-memory.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/js-wasm-cycle-table.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/js-wasm-cycle-value.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/js-wasm-cycle.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/resolve-export.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/wasm-export-i64-global.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/wasm-export-to-wasm.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/wasm-import-error-from-wasm.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/wasm-import-from-wasm.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/wasm-import-func.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/wasm-import-global.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/wasm-import-memory.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/wasm-import-table.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/wasm-js-cycle.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/esm-integration/resources/worker.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/resources/incrementer.no_mime_type.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/resources/incrementer.wasm:1","Warn: binary detected: test/fixtures/wpt/wasm/webapi/resources/incrementer.wrong_mime_type.wasm:1","Warn: binary detected: test/wasi/wasm/cant_dotdot.wasm:1","Warn: binary detected: test/wasi/wasm/clock_getres.wasm:1","Warn: binary detected: test/wasi/wasm/create_symlink.wasm:1","Warn: binary detected: test/wasi/wasm/exitcode.wasm:1","Warn: binary detected: test/wasi/wasm/fd_prestat_get_refresh.wasm:1","Warn: binary detected: test/wasi/wasm/follow_symlink.wasm:1","Warn: binary detected: test/wasi/wasm/freopen.wasm:1","Warn: binary detected: test/wasi/wasm/ftruncate.wasm:1","Warn: binary detected: test/wasi/wasm/getentropy.wasm:1","Warn: binary detected: test/wasi/wasm/getrusage.wasm:1","Warn: binary detected: test/wasi/wasm/gettimeofday.wasm:1","Warn: binary detected: test/wasi/wasm/link.wasm:1","Warn: binary detected: test/wasi/wasm/main_args.wasm:1","Warn: binary detected: test/wasi/wasm/notdir.wasm:1","Warn: binary detected: test/wasi/wasm/poll.wasm:1","Warn: binary detected: test/wasi/wasm/poll_win.wasm:1","Warn: binary detected: test/wasi/wasm/preopen_populates.wasm:1","Warn: binary detected: test/wasi/wasm/pthread.wasm:1","Warn: binary detected: test/wasi/wasm/read_file.wasm:1","Warn: binary detected: test/wasi/wasm/read_file_twice.wasm:1","Warn: binary detected: test/wasi/wasm/readdir.wasm:1","Warn: binary detected: test/wasi/wasm/sock.wasm:1","Warn: binary detected: test/wasi/wasm/stat.wasm:1","Warn: binary detected: test/wasi/wasm/stdin.wasm:1","Warn: binary detected: test/wasi/wasm/symlink_escape.wasm:1","Warn: binary detected: test/wasi/wasm/symlink_loop.wasm:1","Warn: binary detected: test/wasi/wasm/write_file.wasm:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#binary-artifacts"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#signed-releases"}},{"name":"Pinned-Dependencies","score":7,"reason":"dependency not pinned by hash detected -- score normalized to 7","details":["Info: Possibly incomplete results: error parsing shell code: \"foo(\" must be followed by ): android-configure:0","Info: Possibly incomplete results: error parsing shell code: \"foo(\" must be followed by ): configure:0","Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: deps/openssl/openssl/util/shlib_wrap.sh.in:0","Warn: containerImage not pinned by hash: deps/ngtcp2/ngtcp2/third-party/urlparse/.clusterfuzzlite/Dockerfile:1: pin your Docker image by updating gcr.io/oss-fuzz-base/base-builder:v1 to gcr.io/oss-fuzz-base/base-builder:v1@sha256:c38656eefbe0a69879d8f5e3dba3fb8f9fd30f2a49fcbc097742fd4a0ef819b9","Warn: containerImage not pinned by hash: deps/openssl/config/Dockerfile:1: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:eb29ed27b0821dca09c2e28b39135e185fc1302036427d5f4d70a41ce8fd7659","Warn: npmCommand not pinned by hash: test/fixtures/wpt/resources/webidl2/build.sh:7","Warn: npmCommand not pinned by hash: tools/dep_updaters/update-llhttp.sh:61","Warn: npmCommand not pinned by hash: tools/dep_updaters/update-llhttp.sh:79","Warn: npmCommand not pinned by hash: .github/workflows/auto-start-ci.yml:55","Warn: downloadThenRun not pinned by hash: .github/workflows/auto-start-ci.yml:70","Warn: npmCommand not pinned by hash: .github/workflows/commit-queue.yml:77","Warn: pipCommand not pinned by hash: .github/workflows/coverage-linux-without-intl.yml:74","Warn: pipCommand not pinned by hash: .github/workflows/coverage-linux.yml:74","Warn: npmCommand not pinned by hash: .github/workflows/create-release-proposal.yml:49","Warn: downloadThenRun not pinned by hash: .github/workflows/create-release-proposal.yml:76","Warn: npmCommand not pinned by hash: .github/workflows/update-v8.yml:38","Warn: npmCommand not pinned by hash: .github/workflows/update-wpt.yml:41","Info:  83 out of  83 GitHub-owned GitHubAction dependencies pinned","Info:  30 out of  30 third-party GitHubAction dependencies pinned","Info:   0 out of   2 pipCommand dependencies pinned","Info:   0 out of   2 containerImage dependencies pinned","Info:   0 out of   8 npmCommand dependencies pinned","Info:   0 out of   2 downloadThenRun dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#pinned-dependencies"}},{"name":"Branch-Protection","score":1,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'main'","Warn: 'force pushes' enabled on branch 'main'","Warn: 'branch protection settings apply to administrators' is disabled on branch 'main'","Warn: 'stale review dismissal' is disabled on branch 'main'","Warn: required approving review count is 1 on branch 'main'","Warn: codeowners review is not required on branch 'main'","Info: 'last push approval' is required to merge on branch 'main'","Warn: no status checks found to merge onto branch 'main'","Info: PRs are required in order to make changes on branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#branch-protection"}},{"name":"Fuzzing","score":10,"reason":"project is fuzzed","details":["Info: OSSFuzz integration found","Info: CppLibFuzzer integration found: deps/ngtcp2/ngtcp2/third-party/urlparse/fuzz/parser.cc:65","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/fuzzer.cc:13","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/fuzzer.cc:58","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/inspector-fuzzer.cc:645","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/json.cc:22","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/multi-return.cc:157","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/parser.cc:66","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/regexp.cc:36","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/async.cc:57","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/code.cc:38","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/compile-all.cc:38","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/compile-revec.cc:32","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/compile-simd.cc:32","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/compile-wasmgc.cc:38","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/compile.cc:31","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/deopt.cc:421","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/init-expr.cc:248","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/fast-interpreter.cc:24","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-all-multiple-modules.cc:33","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-all.cc:30","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-all.cc:31","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-base.cc:29","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-base.cc:30","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-code.cc:33","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-code.cc:34","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-diff.cc:30","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-fuzzer-common.cc:556","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-init-expr.cc:382","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-simd.cc:29","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-simd.cc:30","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-wasmgc.cc:28","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-wasmgc.cc:29","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/module.cc:29","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/streaming.cc:152","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/compress_fuzzer.cc:20","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/deflate_fuzzer.cc:24","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/deflate_set_dictionary_fuzzer.cc:15","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/inflate_fuzzer.cc:16","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/inflate_with_header_fuzzer.cc:59","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/minizip_unzip_fuzzer.cc:23","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/streaming_inflate_fuzzer.cc:22","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/uncompress_fuzzer.cc:14","Info: CppLibFuzzer integration found: test/fuzzers/fuzz_ClientHelloParser.cc:8","Info: CppLibFuzzer integration found: test/fuzzers/fuzz_env.cc:100","Info: CppLibFuzzer integration found: test/fuzzers/fuzz_strings.cc:127","Info: CppLibFuzzer integration found: deps/ngtcp2/ngtcp2/third-party/urlparse/fuzz/parser.cc:65","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/fuzzer.cc:13","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/fuzzer.cc:58","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/inspector-fuzzer.cc:645","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/json.cc:22","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/multi-return.cc:157","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/parser.cc:66","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/regexp.cc:36","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/async.cc:57","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/code.cc:38","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/compile-all.cc:38","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/compile-revec.cc:32","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/compile-simd.cc:32","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/compile-wasmgc.cc:38","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/compile.cc:31","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/deopt.cc:421","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/init-expr.cc:248","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/fast-interpreter.cc:24","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-all-multiple-modules.cc:33","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-all.cc:30","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-all.cc:31","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-base.cc:29","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-base.cc:30","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-code.cc:33","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-code.cc:34","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-diff.cc:30","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-fuzzer-common.cc:556","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-init-expr.cc:382","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-simd.cc:29","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-simd.cc:30","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-wasmgc.cc:28","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/interpreter/interpreter-wasmgc.cc:29","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/module.cc:29","Info: CppLibFuzzer integration found: deps/v8/test/fuzzer/wasm/streaming.cc:152","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/compress_fuzzer.cc:20","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/deflate_fuzzer.cc:24","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/deflate_set_dictionary_fuzzer.cc:15","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/inflate_fuzzer.cc:16","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/inflate_with_header_fuzzer.cc:59","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/minizip_unzip_fuzzer.cc:23","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/streaming_inflate_fuzzer.cc:22","Info: CppLibFuzzer integration found: deps/zlib/contrib/tests/fuzzers/uncompress_fuzzer.cc:14","Info: CppLibFuzzer integration found: test/fuzzers/fuzz_ClientHelloParser.cc:8","Info: CppLibFuzzer integration found: test/fuzzers/fuzz_env.cc:100","Info: CppLibFuzzer integration found: test/fuzzers/fuzz_strings.cc:127","Info: CLibFuzzer integration found: deps/ngtcp2/ngtcp2/third-party/urlparse/http-parser/fuzzers/fuzz_parser.c:6","Info: CLibFuzzer integration found: deps/ngtcp2/ngtcp2/third-party/urlparse/http-parser/fuzzers/fuzz_url.c:6","Info: CLibFuzzer integration found: deps/openssl/openssl/fuzz/driver.c:19","Info: CLibFuzzer integration found: deps/openssl/openssl/fuzz/driver.c:26"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#fuzzing"}},{"name":"SAST","score":7,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 0 commits out of 25 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#sast"}},{"name":"CI-Tests","score":9,"reason":"24 out of 25 merged PRs checked by a CI test -- score normalized to 9","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#ci-tests"}},{"name":"Contributors","score":10,"reason":"project has 111 contributing companies or organizations","details":["Info: found contributions from: CasparCG, CloudNativeJS, DataDog, DxWnd, ES-Community, Empeeric, GonzagaAccess, IBM, Jasig, Level, LyraSearch, NodeRedis, NodeSummit, RuntimeTools, TrainingPlay, WebAssembly, WinterTC55, X-Profiler, activitystreams, ada-url, adonisjs, ataraxia consulting, bloomberg, browserify, cheminfo, cheminfo-js, cloudflare, cloudflare-whatwg, datadog, denoland, digitalocean, drogue-iot, ender-js, fastify, filecoin-project, flarelabs-net, fm-venues, getsentry, ggml-org, github-beta, gypified, h3js, huggingface, ibm, image-js, ipfs, ipld, istanbuljs, js-js, jstat, libuv, linuxfoundationorg, maia-tool, malijs, minibuf, mljs, mongodb, multiformats, netty, node-forward, node-inspector, node4good, nodejs, nodejs-private, nodeshift, nodesource, nubjs, nujs, nxtedition, oftc, open-telemetry, openjs-foundation, ossf, paketo-buildpacks, paketo-community, peerlinks, piscinajs, pkgjs, pnpm, polyhack, primus, propelml, redhat-developer, relevantfruit, reportico, require.io, requireio, rh-ai-quickstart, sagemath, sclorg, signalapp, simdutf, socket, strongloop, strongloop-community, strongloop-forks, taphub, tapjs, tc39, tc39-transfer, trustification, tu wien, ucsf-ckm, unshiftio, w3c, wasm-signatures, web-platform-tests, websockets, xai, zakodium, zakodium-oss"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#contributors"}},{"name":"Vulnerabilities","score":0,"reason":"74 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: CVE-2025-15504","Warn: Project is vulnerable to: RUSTSEC-2021-0139","Warn: Project is vulnerable to: RUSTSEC-2020-0095","Warn: Project is vulnerable to: RUSTSEC-2025-0141","Warn: Project is vulnerable to: RUSTSEC-2026-0007 / GHSA-434x-w66g-qw3r","Warn: Project is vulnerable to: RUSTSEC-2026-0097 / GHSA-cq8v-f236-94qc","Warn: Project is vulnerable to: RUSTSEC-2026-0001","Warn: Project is vulnerable to: OSV-2023-1328","Warn: Project is vulnerable to: CVE-2026-27135","Warn: Project is vulnerable to: CVE-2025-11187","Warn: Project is vulnerable to: CVE-2025-15467","Warn: Project is vulnerable to: CVE-2025-15468","Warn: Project is vulnerable to: CVE-2025-15469","Warn: Project is vulnerable to: CVE-2025-66199","Warn: Project is vulnerable to: CVE-2025-68160","Warn: Project is vulnerable to: CVE-2025-69418","Warn: Project is vulnerable to: CVE-2025-69419","Warn: Project is vulnerable to: CVE-2025-69420","Warn: Project is vulnerable to: CVE-2025-69421","Warn: Project is vulnerable to: CVE-2026-22795","Warn: Project is vulnerable to: CVE-2026-22796","Warn: Project is vulnerable to: CVE-2026-2673","Warn: Project is vulnerable to: GHSA-5239-wwwm-4pmq","Warn: Project is vulnerable to: GHSA-9hjg-9r4m-mvj7","Warn: Project is vulnerable to: GHSA-gc5v-m9x4-r6x2","Warn: Project is vulnerable to: GHSA-2xpw-w6gg-jr37","Warn: Project is vulnerable to: GHSA-38jv-5279-wg99","Warn: Project is vulnerable to: GHSA-48p4-8xcf-vxj5","Warn: Project is vulnerable to: GHSA-gm62-xv2j-4w53","Warn: Project is vulnerable to: GHSA-pq67-6m6q-mj2v","Warn: Project is vulnerable to: V8-FRESHNESS","Warn: Project is vulnerable to: GHSA-cpwx-vrp4-4pq7","Warn: Project is vulnerable to: GHSA-gmj6-6f8f-6699","Warn: Project is vulnerable to: GHSA-h5c8-rqwp-cp95","Warn: Project is vulnerable to: GHSA-h75v-3vvj-5mfj","Warn: Project is vulnerable to: GHSA-q2x7-8rv6-6q7h","Warn: Project is vulnerable to: CVE-2026-22184","Warn: Project is vulnerable to: CVE-2026-27171","Warn: Project is vulnerable to: CVE-2026-3381","Warn: Project is vulnerable to: GHSA-2g4f-4pwh-qvx6","Warn: Project is vulnerable to: GHSA-f886-m6hf-6m8v","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-9vvw-cc9w-f27h","Warn: Project is vulnerable to: GHSA-gxpj-cx7g-858c","Warn: Project is vulnerable to: GHSA-73rr-hh4g-fpgx","Warn: Project is vulnerable to: GHSA-h6ch-v84p-w6p9","Warn: Project is vulnerable to: GHSA-25h7-pfq9-p65f","Warn: Project is vulnerable to: GHSA-rf6f-7fwh-wjgh","Warn: Project is vulnerable to: GHSA-qh2h-chj9-jffq","Warn: Project is vulnerable to: GHSA-mh29-5h37-fv8m","Warn: Project is vulnerable to: GHSA-f23m-r3pf-42rh","Warn: Project is vulnerable to: GHSA-r5fr-rjxr-66jc","Warn: Project is vulnerable to: GHSA-xxjr-mmjv-4gpg","Warn: Project is vulnerable to: GHSA-23c5-xmqv-rm74","Warn: Project is vulnerable to: GHSA-3ppc-4f35-3m26","Warn: Project is vulnerable to: GHSA-7r86-cg39-jmmj","Warn: Project is vulnerable to: GHSA-vh95-rmgr-6w4m","Warn: Project is vulnerable to: GHSA-xvch-5gv4-984h","Warn: Project is vulnerable to: GHSA-3v7f-55p6-f55p","Warn: Project is vulnerable to: GHSA-c2c7-rcm5-vvqj","Warn: Project is vulnerable to: GHSA-22r3-9w55-cj54","Warn: Project is vulnerable to: GHSA-8cj5-5rvv-wf4v","Warn: Project is vulnerable to: GHSA-vj76-c3g6-qr5v","Warn: Project is vulnerable to: GHSA-52f5-9888-hmc6","Warn: Project is vulnerable to: GHSA-vpq2-c234-7xj6","Warn: Project is vulnerable to: GHSA-7gcc-r8m5-44qm","Warn: Project is vulnerable to: GHSA-jgmv-j7ww-jx2x","Warn: Project is vulnerable to: GHSA-76c9-3jph-rj3q","Warn: Project is vulnerable to: GHSA-6rw7-vpxm-498p","Warn: Project is vulnerable to: GHSA-w7fw-mjwx-w883","Warn: Project is vulnerable to: GHSA-36jr-mh4h-2g58","Warn: Project is vulnerable to: GHSA-mw96-cpmx-2vgc","Warn: Project is vulnerable to: GHSA-5c6j-r48x-rmvq","Warn: Project is vulnerable to: GHSA-qj8w-gfj5-8c6v"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#vulnerabilities"}}]}
