1 of 15

Project

Client name

Report date

CARDANO

Toptal

Tuesday, 04 October 2022

Engineering Report

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

2 of 15

Business Risks

Business Risks Review Details

Category

Type

Grade

Description

Code Quality

Defects

0.0% code lines contain major issues

Code Quality

Code Smells

0.0% code lines contain blocker code smells

Code Quality

Duplications

0.8% code lines are duplicated

Code Quality

Hardcoded Items

0.1% code lines contain hardcoded items

Security

Vulnerabilities

5.3 vulnerabilities per 10K code lines

Security

Hotspots

1.4 security hotspots per 10K code lines

License Compliance

License Risks

0 reciprocal license risks, 4 total license risks

Packages

Total

308 total: 165 Npm, 138 Yarn, 4 Pip, 1 NuGet

Packages

Outdated

287 outdated: 152 Npm, 130 Yarn, 4 Pip, 1 NuGet

Development Team

Active contributors

1128 developers have been working on the code base during past year.

Development Team

Top performers

70% of top 10 developers are still active.

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

3 of 15

Security�Dashboard

Security

Vulnerability Score

Vulnerable Packages

Severity Distribution

Aging Vulnerable Packages

License Risk and Compliance

License Distribution

License Risk Distribution

Outdated Versions

86 Outdated Packages

101 Up-to-date Packages

42 Multi-versioned Packages

HIGH

129

Vulnerable

(0 outdated)

179

Not Vulnerable

Total License Types: 17, Total Packages: 308

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

4 of 15

Team

1,128 developers have been working on the code base during past year.

46.5% of those developers are still active (they have committed code during past 6 months).

Contributors Overview

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

5 of 15

Team

Name

Commits

Fixes

Features

Languages

olgahryniuk <67585499+olgahryniuk@users.noreply.github.com>

113

1

112

Markdown

Markl Jenkins <quickbeam@outlook.com>

58

0

58

JSON

Fillips Ickevics <60065019+fill-the-fill@users.noreply.github.com>

51

6

45

JavaScript, Markdown, TypeScript

markl-jenkins <97963265+markl-jenkins@users.noreply.github.com>

42

0

42

JSON

Tommy Kammerer <31965230+katomm@users.noreply.github.com>

40

2

38

Markdown, JavaScript

Niamh Ahern <34340946+nahern@users.noreply.github.com>

35

3

32

Markdown

Frederic J <58846030+crptmppt@users.noreply.github.com>

32

14

18

Markdown, JSON

Tommy <31965230+katomm@users.noreply.github.com>

28

4

24

JavaScript, Markdown, CSS, JSON

Martin Hunt <martin.hunt@iohk.io>

27

4

23

JavaScript, Markdown, JSON

Leo42 <leantrosh@gmail.com>

23

0

23

JSON

Top 10 Contributors

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

6 of 15

Team

Top 5 Active Contributors by Commits

Active contributor is someone who has committed code during the last 6 months

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

7 of 15

Package

Type

Version

Latest Version

Message

Yarn

2.7.4

0.0.0

ejs: server-side template injection in outputFunctionName. Package: ejs, installed version 2.7.4, fixed version 3.1.7. https://avd.aquasec.com/nvd/cve…

Npm

0.1.6

0.0.0

eventsource: Exposure of Sensitive Information. Package: eventsource, installed version 0.1.6, fixed version 2.0.2, 1.1.1. https://avd.aquasec.com/nvd…

Npm

1.10.0

0.0.0

nodejs-immer: prototype pollution may lead to DoS or remote code execution. Package: immer, installed version 1.10.0, fixed version 9.0.6. https://avd…

Yarn

0.2.3

0.0.0

nodejs-json-schema: Prototype pollution vulnerability. Package: json-schema, installed version 0.2.3, fixed version 0.4.0. https://avd.aquasec.com/nvd…

Npm

0.0.8

0.0.0

nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload. Package: mini…

Npm

0.8.3

0.0.0

mpath: type confusion can lead to a bypass of CVE-2018-16490. Package: mpath, installed version 0.8.3, fixed version 0.8.4. https://avd.aquasec.com/nv…

Npm

5.0.1

0.0.0

Cross site scripting in parse-url. Package: parse-url, installed version 5.0.1, fixed version 6.0.1. https://avd.aquasec.com/nvd/cve-2022-2218. npm: X…

Npm

1.6.1

0.0.0

The shell-quote package before 1.7.3 for Node.js allows command inject .... Package: shell-quote, installed version 1.6.1, fixed version 1.7.3. https:…

Npm

1.4.7

0.0.0

npm-url-parse: authorization bypass through user-controlled key. Package: url-parse, installed version 1.4.7, fixed version 1.5.9. https://avd.aquasec…

Npm

1.5.5

0.0.0

nodejs-xmlhttprequest: Code injection through user input to xhr.send. Package: xmlhttprequest-ssl, installed version 1.5.5, fixed version 1.6.2. https…

Yarn

17.4.0, 27 May 2019

18.6.4, 22 Oct 2020

Package is 1 major version behind the latest. Package version is more than 3 years old.

Yarn

24.9.1, 23 Jan 2020

28.1.6, 15 Jul 2022

Package is 4 major versions behind the latest. Package version is more than 2 years old.

Packages

Outdated Packages

287 outdated packages (152 Npm, 130 Yarn, 4 Pip, 1 NuGet).

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

8 of 15

Package

Type

Version

Latest Version

Message

Yarn

14.14.28, 14 Feb 2021

18.6.1, 25 Jul 2022

Package is 4 major versions behind the latest. Package version is more than 1 year old.

Pip

2.8.0

0.0.0

CVE-2021-20095 CVE-2021-42771 python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code. Package…

Pip

2.6.1

0.0.0

python-pygments: ReDoS in multiple lexers. Package: Pygments, installed version 2.6.1, fixed version 2.7.4. https://avd.aquasec.com/nvd/cve-2021-27291…

NuGet

7.0.0, 14 Mar 2021

11.0.0, 22 Jul 2022

Package is 4 major versions behind the latest. Package version is more than 1 year old.

Npm

7.1.0

0.0.0

Regular Expression Denial of Service in Acorn. Package: acorn, installed version 7.1.0, fixed version 5.7.4, 7.1.1, 6.4.1. https://github.com/advisori…

Npm

0.0.7

0.0.0

nodejs-ansi-html: ReDoS via crafted string. Package: ansi-html, installed version 0.0.7, fixed version 0.0.8. https://avd.aquasec.com/nvd/cve-2021-234…

Npm

3.0.0

0.0.0

nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes. Package: ansi-regex, installed version 3.0.0, fixed versio…

Yarn

2.6.3

0.0.0

Prototype Pollution in async. Package: async, installed version 2.6.3, fixed version 2.6.4, 3.2.2. https://avd.aquasec.com/nvd/cve-2021-43138.

Npm

0.19.2

0.0.0

nodejs-axios: Regular expression denial of service in trim function. Package: axios, installed version 0.19.2, fixed version 0.21.2. https://avd.aquas…

Yarn

24.9.0, 16 Aug 2019

28.1.3, 13 Jul 2022

Package is 4 major versions behind the latest. Package version is more than 3 years old.

Yarn

1.6.2, 25 Nov 2018

1.6.2, 25 Nov 2018

Package version is more than 3 years old.

Yarn

5.2.6, 11 May 2019

5.2.6, 11 May 2019

Package version is more than 3 years old.

Packages

Outdated Packages (continued)

287 outdated packages (152 Npm, 130 Yarn, 4 Pip, 1 NuGet).

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

9 of 15

Package

Type

Description

Fixed Version

Npm

eventsource: Exposure of Sensitive Information, CVE-2022-1650

2.0.2, 1.1.1

Npm

eventsource: Exposure of Sensitive Information, CVE-2022-1650

2.0.2, 1.1.1

Npm

immer: type confusion vulnerability can lead to a bypass of CVE-2020-28477, CVE-2021-23436

9.0.6

Npm

minimist: prototype pollution, CVE-2021-44906

1.2.6

Npm

minimist: prototype pollution, CVE-2021-44906

1.2.6

Npm

minimist: prototype pollution, CVE-2021-44906

1.2.6

Npm

mpath: type confusion can lead to a bypass of CVE-2018-16490, CVE-2021-23438

0.8.4

Npm

Server-Side Request Forgery in parse-url, CVE-2022-2216

6.0.1

Npm

The shell-quote package before 1.7.3 for Node.js allows command inject ..., CVE-2021-42740

1.7.3

Npm

The shell-quote package before 1.7.3 for Node.js allows command inject ..., CVE-2021-42740

1.7.3

Security

Package Vulnerabilities

209 vulnerabilities (137 Npm, 67 Yarn, 5 Pip).

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

10 of 15

Package

Type

Description

Fixed Version

Npm

npm-url-parse: Authorization bypass through user-controlled key, CVE-2022-0686

1.5.8

Npm

xmlhttprequest-ssl: SSL certificate validation disabled by default, CVE-2021-31597

1.6.1

Yarn

ejs: server-side template injection in outputFunctionName, CVE-2022-29078

3.1.7

Yarn

eventsource: Exposure of Sensitive Information, CVE-2022-1650

2.0.2, 1.1.1

Yarn

nodejs-json-schema: Prototype pollution vulnerability, CVE-2021-3918

0.4.0

Yarn

minimist: prototype pollution, CVE-2021-44906

1.2.6

Yarn

npm-url-parse: Authorization bypass through user-controlled key, CVE-2022-0686

1.5.8

Yarn

Prototype Pollution in async, CVE-2021-43138

2.6.4, 3.2.2

Pip

CVE-2021-20095 CVE-2021-42771 python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code, CVE-2021-42771

2.9.1

Pip

python-pygments: ReDoS in multiple lexers, CVE-2021-27291

2.7.4

Security

Package Vulnerabilities (continued)

209 vulnerabilities (137 Npm, 67 Yarn, 5 Pip).

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

11 of 15

Rule

Count

Risks

Using regular expressions is security-sensitive

23

Using command line arguments is security-sensitive

13

Using pseudorandom number generators (PRNGs) is security-sensitive

4

Permissive Cross-Origin Resource Sharing policy is security-sensitive

3

Hashing data is security-sensitive

2

Security

Security Rule Violations

0 vulnerabilities, 45 security hotspots.

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

12 of 15

Code Quality

Defects

13 bugs (13 Major), 67 code smells (67 Major).

File

Type

Message

Rule Description

node/gatsby/onPreInit.js:38

Major Code Smell

'key' is already declared in the upper scope.

Overriding or shadowing a variable declared in an outer scope can strongly impact the readability, and therefore the maintainability, of a piece of code. Further, it could lead maintainers to introduc…

_typedoc/custom-theme/assets/css/main.css:2339

Major Code Smell

Unexpected duplicate selector ".tsd-signature.tsd-kind-icon:before", first used at line 630

Duplication of selectors might indicate a copy-paste mistake. The rule detects the following kinds of duplications: within a list of selectors in a single rule set for duplicated selectors in differen…

src/components/showcase/ShowcaseTagSelect/index.js:63

Major Bug

Expected an assignment or function call and instead saw an expression.

Any statement (other than a null statement, which means a statement containing only a semicolon ;) which has no side effect and does not result in a change of control flow will normally indicate a pro…

assets/css/styles.css:226

Major Bug

Unexpected duplicate "color"

CSS allows duplicate property names but only the last instance of a duplicated name determines the actual value that will be used for it. Therefore, changing values of other occurrences of a duplicate…

src/pages/showcase/index.js:118

Major Code Smell

Remove this useless assignment to variable "setSelectedTags".

A dead store happens when a local variable is assigned a value that is not read by any subsequent instruction. Calculating or retrieving a value only to then overwrite it or throw it away, could indic…

public/index.html:7

Major Code Smell

Remove this commented out code.

Programmers should not comment out code as it bloats programs and reduces readability. Unused code should be deleted and can be retrieved from source control history if required.

static/admin/index.html:2

Major Bug

Add "lang" and/or "xml:lang" attributes to this "<html>" element

The &lt;html&gt;&nbsp;element should provide the lang and/or xml:lang attribute in order to identify the default language of a document. It enables assistive technologies, such as screen readers,&nbsp…

src/signTx.c:177

Major Bug

'(void*)wireDataBuffer' is of type 'void *'. When using void pointers in calculations, the behaviour is undefined.

When using void pointers in calculations, the behaviour is undefined. Arithmetic operations on 'void *' is a GNU C extension, which defines the 'sizeof(void)' to be 1.

src/data/showcases.js:193

Major Bug

Rename or remove duplicate property name 'ecosystem'.

JavaScript allows duplicate property names in classes and object literals, but only the last instance of a duplicated name determines the actual value that will be used for it. Therefore, changing val…

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

13 of 15

Licenses

Licenses

283 licenses: 259 permissive, 7 reciprocal, 17 uncertain.

License

Risk

Count

Allows SaaS

Allows Distribution

Allows Modification

171

True

True

True

41

True

True

True

28

True

True

True

10

True

True

True

7

True

True

False

6

True

True

Uncertain

5

True

True

True

3

Uncertain

Uncertain

Uncertain

2

True

True

True

2

Uncertain

Uncertain

Uncertain

2

Uncertain

Uncertain

Uncertain

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

14 of 15

Licenses

Licenses (continued)

283 licenses: 259 permissive, 7 reciprocal, 17 uncertain.

License

Risk

Count

Allows SaaS

Allows Distribution

Allows Modification

1

Uncertain

Uncertain

Uncertain

1

Uncertain

Uncertain

Uncertain

1

Uncertain

Uncertain

Uncertain

1

Uncertain

Uncertain

Uncertain

1

True

True

True

1

True

True

True

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022

15 of 15

Contact Us

Get Support

If you need help interpreting the report, assessing the risk and prioritizing the refactoring activities, please contact us at info@codewetrust.com.

We will be happy to help you maximize your codebase’s potential.

Download CodeWeTrust’s M&A paper: codewetrust.com/download-whitepaper

Project

CARDANO

Client name

Toptal

Report date

Tuesday, 04 October 2022