Project
Client name
Report date
CARDANO
Toptal
Tuesday, 04 October 2022
Engineering Report
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Business Risks
Business Risks Review Details
Category | Type | Grade | Description |
Code Quality | Defects | ● | 0.0% code lines contain major issues |
Code Quality | Code Smells | ● | 0.0% code lines contain blocker code smells |
Code Quality | Duplications | ● | 0.8% code lines are duplicated |
Code Quality | Hardcoded Items | ● | 0.1% code lines contain hardcoded items |
Security | Vulnerabilities | ● | 5.3 vulnerabilities per 10K code lines |
Security | Hotspots | ● | 1.4 security hotspots per 10K code lines |
License Compliance | License Risks | ● | 0 reciprocal license risks, 4 total license risks |
Packages | Total | ● | 308 total: 165 Npm, 138 Yarn, 4 Pip, 1 NuGet |
Packages | Outdated | ● | 287 outdated: 152 Npm, 130 Yarn, 4 Pip, 1 NuGet |
Development Team | Active contributors | ● | 1128 developers have been working on the code base during past year. |
Development Team | Top performers | ● | 70% of top 10 developers are still active. |
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Security�Dashboard
Security
Vulnerability Score
Vulnerable Packages
Severity Distribution
Aging Vulnerable Packages
License Risk and Compliance
License Distribution
License Risk Distribution
Outdated Versions
86 Outdated Packages
101 Up-to-date Packages
42 Multi-versioned Packages
HIGH
129
Vulnerable
(0 outdated)
179
Not Vulnerable
Total License Types: 17, Total Packages: 308
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Team
1,128 developers have been working on the code base during past year.
46.5% of those developers are still active (they have committed code during past 6 months).
Contributors Overview
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Team
Name | Commits | Fixes | Features | Languages |
olgahryniuk <67585499+olgahryniuk@users.noreply.github.com> | 113 | 1 | 112 | Markdown |
Markl Jenkins <quickbeam@outlook.com> | 58 | 0 | 58 | JSON |
Fillips Ickevics <60065019+fill-the-fill@users.noreply.github.com> | 51 | 6 | 45 | JavaScript, Markdown, TypeScript |
markl-jenkins <97963265+markl-jenkins@users.noreply.github.com> | 42 | 0 | 42 | JSON |
Tommy Kammerer <31965230+katomm@users.noreply.github.com> | 40 | 2 | 38 | Markdown, JavaScript |
Niamh Ahern <34340946+nahern@users.noreply.github.com> | 35 | 3 | 32 | Markdown |
Frederic J <58846030+crptmppt@users.noreply.github.com> | 32 | 14 | 18 | Markdown, JSON |
Tommy <31965230+katomm@users.noreply.github.com> | 28 | 4 | 24 | JavaScript, Markdown, CSS, JSON |
Martin Hunt <martin.hunt@iohk.io> | 27 | 4 | 23 | JavaScript, Markdown, JSON |
Leo42 <leantrosh@gmail.com> | 23 | 0 | 23 | JSON |
Top 10 Contributors
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Team
Top 5 Active Contributors by Commits
Active contributor is someone who has committed code during the last 6 months
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Package | Type | Version | Latest Version | Message |
Yarn | 2.7.4 | 0.0.0 | ejs: server-side template injection in outputFunctionName. Package: ejs, installed version 2.7.4, fixed version 3.1.7. https://avd.aquasec.com/nvd/cve… | |
Npm | 0.1.6 | 0.0.0 | eventsource: Exposure of Sensitive Information. Package: eventsource, installed version 0.1.6, fixed version 2.0.2, 1.1.1. https://avd.aquasec.com/nvd… | |
Npm | 1.10.0 | 0.0.0 | nodejs-immer: prototype pollution may lead to DoS or remote code execution. Package: immer, installed version 1.10.0, fixed version 9.0.6. https://avd… | |
Yarn | 0.2.3 | 0.0.0 | nodejs-json-schema: Prototype pollution vulnerability. Package: json-schema, installed version 0.2.3, fixed version 0.4.0. https://avd.aquasec.com/nvd… | |
Npm | 0.0.8 | 0.0.0 | nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload. Package: mini… | |
Npm | 0.8.3 | 0.0.0 | mpath: type confusion can lead to a bypass of CVE-2018-16490. Package: mpath, installed version 0.8.3, fixed version 0.8.4. https://avd.aquasec.com/nv… | |
Npm | 5.0.1 | 0.0.0 | Cross site scripting in parse-url. Package: parse-url, installed version 5.0.1, fixed version 6.0.1. https://avd.aquasec.com/nvd/cve-2022-2218. npm: X… | |
Npm | 1.6.1 | 0.0.0 | The shell-quote package before 1.7.3 for Node.js allows command inject .... Package: shell-quote, installed version 1.6.1, fixed version 1.7.3. https:… | |
Npm | 1.4.7 | 0.0.0 | npm-url-parse: authorization bypass through user-controlled key. Package: url-parse, installed version 1.4.7, fixed version 1.5.9. https://avd.aquasec… | |
Npm | 1.5.5 | 0.0.0 | nodejs-xmlhttprequest: Code injection through user input to xhr.send. Package: xmlhttprequest-ssl, installed version 1.5.5, fixed version 1.6.2. https… | |
Yarn | 17.4.0, 27 May 2019 | 18.6.4, 22 Oct 2020 | Package is 1 major version behind the latest. Package version is more than 3 years old. | |
Yarn | 24.9.1, 23 Jan 2020 | 28.1.6, 15 Jul 2022 | Package is 4 major versions behind the latest. Package version is more than 2 years old. |
Packages
Outdated Packages
287 outdated packages (152 Npm, 130 Yarn, 4 Pip, 1 NuGet).
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Package | Type | Version | Latest Version | Message |
Yarn | 14.14.28, 14 Feb 2021 | 18.6.1, 25 Jul 2022 | Package is 4 major versions behind the latest. Package version is more than 1 year old. | |
Pip | 2.8.0 | 0.0.0 | CVE-2021-20095 CVE-2021-42771 python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code. Package… | |
Pip | 2.6.1 | 0.0.0 | python-pygments: ReDoS in multiple lexers. Package: Pygments, installed version 2.6.1, fixed version 2.7.4. https://avd.aquasec.com/nvd/cve-2021-27291… | |
NuGet | 7.0.0, 14 Mar 2021 | 11.0.0, 22 Jul 2022 | Package is 4 major versions behind the latest. Package version is more than 1 year old. | |
Npm | 7.1.0 | 0.0.0 | Regular Expression Denial of Service in Acorn. Package: acorn, installed version 7.1.0, fixed version 5.7.4, 7.1.1, 6.4.1. https://github.com/advisori… | |
Npm | 0.0.7 | 0.0.0 | nodejs-ansi-html: ReDoS via crafted string. Package: ansi-html, installed version 0.0.7, fixed version 0.0.8. https://avd.aquasec.com/nvd/cve-2021-234… | |
Npm | 3.0.0 | 0.0.0 | nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes. Package: ansi-regex, installed version 3.0.0, fixed versio… | |
Yarn | 2.6.3 | 0.0.0 | Prototype Pollution in async. Package: async, installed version 2.6.3, fixed version 2.6.4, 3.2.2. https://avd.aquasec.com/nvd/cve-2021-43138. | |
Npm | 0.19.2 | 0.0.0 | nodejs-axios: Regular expression denial of service in trim function. Package: axios, installed version 0.19.2, fixed version 0.21.2. https://avd.aquas… | |
Yarn | 24.9.0, 16 Aug 2019 | 28.1.3, 13 Jul 2022 | Package is 4 major versions behind the latest. Package version is more than 3 years old. | |
Yarn | 1.6.2, 25 Nov 2018 | 1.6.2, 25 Nov 2018 | Package version is more than 3 years old. | |
Yarn | 5.2.6, 11 May 2019 | 5.2.6, 11 May 2019 | Package version is more than 3 years old. |
Packages
Outdated Packages (continued)
287 outdated packages (152 Npm, 130 Yarn, 4 Pip, 1 NuGet).
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Package | Type | Description | Fixed Version |
Npm | eventsource: Exposure of Sensitive Information, CVE-2022-1650 | 2.0.2, 1.1.1 | |
Npm | eventsource: Exposure of Sensitive Information, CVE-2022-1650 | 2.0.2, 1.1.1 | |
Npm | immer: type confusion vulnerability can lead to a bypass of CVE-2020-28477, CVE-2021-23436 | 9.0.6 | |
Npm | minimist: prototype pollution, CVE-2021-44906 | 1.2.6 | |
Npm | minimist: prototype pollution, CVE-2021-44906 | 1.2.6 | |
Npm | minimist: prototype pollution, CVE-2021-44906 | 1.2.6 | |
Npm | mpath: type confusion can lead to a bypass of CVE-2018-16490, CVE-2021-23438 | 0.8.4 | |
Npm | Server-Side Request Forgery in parse-url, CVE-2022-2216 | 6.0.1 | |
Npm | The shell-quote package before 1.7.3 for Node.js allows command inject ..., CVE-2021-42740 | 1.7.3 | |
Npm | The shell-quote package before 1.7.3 for Node.js allows command inject ..., CVE-2021-42740 | 1.7.3 |
Security
Package Vulnerabilities
209 vulnerabilities (137 Npm, 67 Yarn, 5 Pip).
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Package | Type | Description | Fixed Version |
Npm | npm-url-parse: Authorization bypass through user-controlled key, CVE-2022-0686 | 1.5.8 | |
Npm | xmlhttprequest-ssl: SSL certificate validation disabled by default, CVE-2021-31597 | 1.6.1 | |
Yarn | ejs: server-side template injection in outputFunctionName, CVE-2022-29078 | 3.1.7 | |
Yarn | eventsource: Exposure of Sensitive Information, CVE-2022-1650 | 2.0.2, 1.1.1 | |
Yarn | nodejs-json-schema: Prototype pollution vulnerability, CVE-2021-3918 | 0.4.0 | |
Yarn | minimist: prototype pollution, CVE-2021-44906 | 1.2.6 | |
Yarn | npm-url-parse: Authorization bypass through user-controlled key, CVE-2022-0686 | 1.5.8 | |
Yarn | Prototype Pollution in async, CVE-2021-43138 | 2.6.4, 3.2.2 | |
Pip | CVE-2021-20095 CVE-2021-42771 python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code, CVE-2021-42771 | 2.9.1 | |
Pip | python-pygments: ReDoS in multiple lexers, CVE-2021-27291 | 2.7.4 |
Security
Package Vulnerabilities (continued)
209 vulnerabilities (137 Npm, 67 Yarn, 5 Pip).
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Rule | Count | Risks |
Using regular expressions is security-sensitive | 23 | |
Using command line arguments is security-sensitive | 13 | |
Using pseudorandom number generators (PRNGs) is security-sensitive | 4 | |
Permissive Cross-Origin Resource Sharing policy is security-sensitive | 3 | |
Hashing data is security-sensitive | 2 |
Security
Security Rule Violations
0 vulnerabilities, 45 security hotspots.
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Code Quality
Defects
13 bugs (13 Major), 67 code smells (67 Major).
File | Type | Message | Rule Description |
node/gatsby/onPreInit.js:38 | Major Code Smell | 'key' is already declared in the upper scope. | Overriding or shadowing a variable declared in an outer scope can strongly impact the readability, and therefore the maintainability, of a piece of code. Further, it could lead maintainers to introduc… |
_typedoc/custom-theme/assets/css/main.css:2339 | Major Code Smell | Unexpected duplicate selector ".tsd-signature.tsd-kind-icon:before", first used at line 630 | Duplication of selectors might indicate a copy-paste mistake. The rule detects the following kinds of duplications: within a list of selectors in a single rule set for duplicated selectors in differen… |
src/components/showcase/ShowcaseTagSelect/index.js:63 | Major Bug | Expected an assignment or function call and instead saw an expression. | Any statement (other than a null statement, which means a statement containing only a semicolon ;) which has no side effect and does not result in a change of control flow will normally indicate a pro… |
assets/css/styles.css:226 | Major Bug | Unexpected duplicate "color" | CSS allows duplicate property names but only the last instance of a duplicated name determines the actual value that will be used for it. Therefore, changing values of other occurrences of a duplicate… |
src/pages/showcase/index.js:118 | Major Code Smell | Remove this useless assignment to variable "setSelectedTags". | A dead store happens when a local variable is assigned a value that is not read by any subsequent instruction. Calculating or retrieving a value only to then overwrite it or throw it away, could indic… |
public/index.html:7 | Major Code Smell | Remove this commented out code. | Programmers should not comment out code as it bloats programs and reduces readability. Unused code should be deleted and can be retrieved from source control history if required. |
static/admin/index.html:2 | Major Bug | Add "lang" and/or "xml:lang" attributes to this "<html>" element | The <html> element should provide the lang and/or xml:lang attribute in order to identify the default language of a document. It enables assistive technologies, such as screen readers, … |
src/signTx.c:177 | Major Bug | '(void*)wireDataBuffer' is of type 'void *'. When using void pointers in calculations, the behaviour is undefined. | When using void pointers in calculations, the behaviour is undefined. Arithmetic operations on 'void *' is a GNU C extension, which defines the 'sizeof(void)' to be 1. |
src/data/showcases.js:193 | Major Bug | Rename or remove duplicate property name 'ecosystem'. | JavaScript allows duplicate property names in classes and object literals, but only the last instance of a duplicated name determines the actual value that will be used for it. Therefore, changing val… |
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Licenses
Licenses
283 licenses: 259 permissive, 7 reciprocal, 17 uncertain.
License | Risk | Count | Allows SaaS | Allows Distribution | Allows Modification |
● | 171 | True | True | True | |
● | 41 | True | True | True | |
● | 28 | True | True | True | |
● | 10 | True | True | True | |
● | 7 | True | True | False | |
● | 6 | True | True | Uncertain | |
● | 5 | True | True | True | |
● | 3 | Uncertain | Uncertain | Uncertain | |
● | 2 | True | True | True | |
● | 2 | Uncertain | Uncertain | Uncertain | |
● | 2 | Uncertain | Uncertain | Uncertain |
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Licenses
Licenses (continued)
283 licenses: 259 permissive, 7 reciprocal, 17 uncertain.
License | Risk | Count | Allows SaaS | Allows Distribution | Allows Modification |
● | 1 | Uncertain | Uncertain | Uncertain | |
● | 1 | Uncertain | Uncertain | Uncertain | |
● | 1 | Uncertain | Uncertain | Uncertain | |
● | 1 | Uncertain | Uncertain | Uncertain | |
● | 1 | True | True | True | |
● | 1 | True | True | True |
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022
Contact Us
Get Support
If you need help interpreting the report, assessing the risk and prioritizing the refactoring activities, please contact us at info@codewetrust.com.
We will be happy to help you maximize your codebase’s potential.
Download CodeWeTrust’s M&A paper: codewetrust.com/download-whitepaper
Project
CARDANO
Client name
Toptal
Report date
Tuesday, 04 October 2022