{"id":1727853,"name":"flow-parser","ecosystem":"npm","description":"JavaScript parser written in OCaml. Produces ESTree AST","homepage":"https://flow.org","licenses":"MIT","normalized_licenses":["MIT"],"repository_url":"https://github.com/facebook/flow","keywords_array":[],"namespace":null,"versions_count":418,"first_release_published_at":"2015-02-05T22:22:24.580Z","latest_release_published_at":"2026-06-03T23:46:47.755Z","latest_release_number":"0.317.0","last_synced_at":"2026-06-06T15:30:18.631Z","created_at":"2022-04-09T15:43:35.115Z","updated_at":"2026-06-06T15:30:18.632Z","registry_url":"https://www.npmjs.com/package/flow-parser","install_command":"npm install flow-parser","documentation_url":null,"metadata":{"funding":null,"dist-tags":{"latest":"0.317.0"}},"repo_metadata":{"id":22540078,"uuid":"25880891","full_name":"facebook/flow","owner":"facebook","description":"Adds static typing to JavaScript to improve developer productivity and code quality.","archived":false,"fork":false,"pushed_at":"2026-05-30T00:41:56.000Z","size":174085,"stargazers_count":22214,"open_issues_count":604,"forks_count":1889,"subscribers_count":378,"default_branch":"main","last_synced_at":"2026-05-30T01:05:42.128Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://flow.org/","language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/facebook.png","metadata":{"files":{"readme":"README.md","changelog":"Changelog.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2014-10-28T17:17:45.000Z","updated_at":"2026-05-30T00:32:44.000Z","dependencies_parsed_at":"2023-12-20T07:29:32.567Z","dependency_job_id":"d5038328-6d7e-44b8-a7ae-2ff2da9b27f1","html_url":"https://github.com/facebook/flow","commit_stats":{"total_commits":18409,"total_committers":999,"mean_commits":18.42742742742743,"dds":0.8518659351404204,"last_synced_commit":"69ecebc7bdb05918d524afb62194e03682d4a845"},"previous_names":[],"tags_count":460,"template":false,"template_full_name":null,"purl":"pkg:github/facebook/flow","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/facebook%2Fflow","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/facebook%2Fflow/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/facebook%2Fflow/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/facebook%2Fflow/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/facebook","download_url":"https://codeload.github.com/facebook/flow/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/facebook%2Fflow/sbom","scorecard":{"id":390798,"data":{"date":"2025-08-11","repo":{"name":"github.com/facebook/flow","commit":"ef26687b03eb64966c00b65bb29d585ced148680"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.9,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/build_and_test.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Security-Policy","score":9,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/facebook/.github/SECURITY.md:1","Info: Found linked content: github.com/facebook/.github/SECURITY.md:1","Warn: One or no descriptive hints of disclosure, vulnerability, and/or timelines in security policy","Info: Found text in security policy: github.com/facebook/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.278.0 not signed: https://api.github.com/repos/facebook/flow/releases/236746287","Warn: release artifact v0.277.1 not signed: https://api.github.com/repos/facebook/flow/releases/234989241","Warn: release artifact v0.276.0 not signed: https://api.github.com/repos/facebook/flow/releases/233635608","Warn: release artifact v0.275.0 not signed: https://api.github.com/repos/facebook/flow/releases/230073771","Warn: release artifact v0.278.0 does not have provenance: https://api.github.com/repos/facebook/flow/releases/236746287","Warn: release artifact v0.277.1 does not have provenance: https://api.github.com/repos/facebook/flow/releases/234989241","Warn: release artifact v0.276.0 does not have provenance: https://api.github.com/repos/facebook/flow/releases/233635608","Warn: release artifact v0.275.0 does not have provenance: https://api.github.com/repos/facebook/flow/releases/230073771"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during GetBranch(v0.274): error during branchesHandler.query: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:135: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:156: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:403: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:406: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:407: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:502: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:503: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:637: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:638: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:646: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:654: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:662: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:670: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:372: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:375: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:376: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:442: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:451: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:524: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:525: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:529: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:533: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:537: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:541: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:545: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:549: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:553: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:557: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:581: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:211: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:212: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:224: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:245: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:249: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:260: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:267: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:325: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:331: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:343: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:344: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:388: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:389: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:421: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:422: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:682: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:685: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:697: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:698: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:164: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:165: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:177: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:198: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:202: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:356: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:359: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:360: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:469: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:470: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:482: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:599: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:600: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:604: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:609: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_and_test.yml:613: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/flow/build_and_test.yml/main?enable=pin","Info:   0 out of  66 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   8 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Vulnerabilities","score":0,"reason":"30 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-968p-4wvh-cqc8","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv","Warn: Project is vulnerable to: GHSA-3h5v-q93c-6h6q","Warn: Project is vulnerable to: GHSA-fjxv-7rqg-78g4","Warn: Project is vulnerable to: GHSA-67hx-6x53-jw92","Warn: Project is vulnerable to: GHSA-67mh-4wv8-2f99","Warn: Project is vulnerable to: GHSA-9c47-m6qq-7p4h","Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw","Warn: Project is vulnerable to: GHSA-776f-qx25-q3cc","Warn: Project is vulnerable to: GHSA-93q8-gq69-wqmw","Warn: Project is vulnerable to: CVE-2019-17543","Warn: Project is vulnerable to: CVE-2021-3520","Warn: Project is vulnerable to: GHSA-h5c3-5r3r-rr8q","Warn: Project is vulnerable to: GHSA-rmvr-2pp2-xj38","Warn: Project is vulnerable to: GHSA-xx4v-prfh-6cgc","Warn: Project is vulnerable to: GHSA-pxg6-pf52-xh8x","Warn: Project is vulnerable to: GHSA-jrvm-mcxc-mf6m","Warn: Project is vulnerable to: GHSA-vhxf-7vqr-mrjg","Warn: Project is vulnerable to: GHSA-3rfm-jhwj-7488","Warn: Project is vulnerable to: GHSA-hhq3-ff78-jv3g","Warn: Project is vulnerable to: GHSA-f8q6-p94x-37v3","Warn: Project is vulnerable to: GHSA-rp65-9cf3-cjxr","Warn: Project is vulnerable to: GHSA-76c9-3jph-rj3q","Warn: Project is vulnerable to: GHSA-rhx6-c78j-4q9w","Warn: Project is vulnerable to: GHSA-9wv6-86v2-598j","Warn: Project is vulnerable to: GHSA-4v9v-hfq4-rm2v","Warn: Project is vulnerable to: GHSA-9jgg-88mc-972h"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-18T17:44:44.757Z","repository_id":22540078,"created_at":"2025-08-18T17:44:44.757Z","updated_at":"2025-08-18T17:44:44.757Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33705207,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-05-30T02:00:06.278Z","response_time":92,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"facebook","name":"Meta","uuid":"69631","kind":"organization","description":"We are working to build community through open source technology. NB: members must have two-factor auth.","email":null,"website":"https://opensource.fb.com","location":"Menlo Park, California","twitter":"MetaOpenSource","company":null,"icon_url":"https://avatars.githubusercontent.com/u/69631?v=4","repositories_count":163,"last_synced_at":"2026-05-16T15:59:08.947Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/facebook","funding_links":[],"total_stars":964404,"followers":35470,"following":0,"created_at":"2022-11-02T16:18:58.639Z","updated_at":"2026-05-16T15:59:08.947Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/facebook","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/facebook/repositories"},"tags":[]},"repo_metadata_updated_at":"2026-06-06T15:30:16.317Z","dependent_packages_count":468,"downloads":29982453,"downloads_period":"last-month","dependent_repos_count":171865,"rankings":{"downloads":0.05232284978003047,"dependent_repos_count":0.07948363836286157,"dependent_packages_count":0.12142953363392733,"stargazers_count":0.6289420106211825,"forks_count":0.9092840613264321,"docker_downloads_count":0.09325569144468016,"average":0.314119630861519},"purl":"pkg:npm/flow-parser","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/npm/flow-parser","docker_dependents_count":616,"docker_downloads_count":586487835,"usage_url":"https://repos.ecosyste.ms/usage/npm/flow-parser","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/npm/flow-parser/dependencies","status":null,"funding_links":[],"critical":true,"issue_metadata":{"last_synced_at":"2026-05-26T08:55:37.209Z","issues_count":1268,"pull_requests_count":433,"avg_time_to_close_issue":181307503.64793387,"avg_time_to_close_pull_request":32383052.985221677,"issues_closed_count":1208,"pull_requests_closed_count":406,"pull_request_authors_count":78,"issue_authors_count":797,"avg_comments_per_issue":3.8525236593059935,"avg_comments_per_pull_request":3.3418013856812934,"merged_pull_requests_count":0,"bot_issues_count":1,"bot_pull_requests_count":83,"past_year_issues_count":21,"past_year_pull_requests_count":71,"past_year_avg_time_to_close_issue":1697095.25,"past_year_avg_time_to_close_pull_request":85598.95,"past_year_issues_closed_count":12,"past_year_pull_requests_closed_count":60,"past_year_pull_request_authors_count":12,"past_year_issue_authors_count":11,"past_year_avg_comments_per_issue":1.2380952380952381,"past_year_avg_comments_per_pull_request":1.7464788732394365,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":19,"past_year_merged_pull_requests_count":0,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/facebook%2Fflow/issues","maintainers":[{"login":"samwgoldman","count":5,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/samwgoldman"},{"login":"zpao","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zpao"},{"login":"bigfootjon","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bigfootjon"},{"login":"zertosh","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zertosh"},{"login":"gkz","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/gkz"},{"login":"Daniel15","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Daniel15"}],"active_maintainers":[{"login":"gkz","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/gkz"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/flow-parser/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/flow-parser/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/flow-parser/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/flow-parser/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/flow-parser/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/flow-parser/codemeta","maintainers":[{"uuid":"mroch","login":"mroch","name":null,"email":"marshall@roch.com","url":null,"packages_count":8,"html_url":"https://www.npmjs.com/~mroch","role":null,"created_at":"2022-11-10T11:27:56.241Z","updated_at":"2022-11-10T11:27:56.241Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/mroch/packages"},{"uuid":"gabelevi","login":"gabelevi","name":null,"email":"gabelevi@gmail.com","url":null,"packages_count":6,"html_url":"https://www.npmjs.com/~gabelevi","role":null,"created_at":"2022-11-10T11:27:56.246Z","updated_at":"2022-11-10T11:27:56.246Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/gabelevi/packages"},{"uuid":"nmote","login":"nmote","name":null,"email":"nat@natmote.net","url":null,"packages_count":5,"html_url":"https://www.npmjs.com/~nmote","role":null,"created_at":"2022-11-10T11:27:56.249Z","updated_at":"2022-11-10T11:27:56.249Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/nmote/packages"},{"uuid":"flowtype","login":"flowtype","name":null,"email":"flow@fb.com","url":null,"packages_count":15,"html_url":"https://www.npmjs.com/~flowtype","role":null,"created_at":"2022-11-10T11:27:56.252Z","updated_at":"2022-11-10T11:27:56.252Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/flowtype/packages"},{"uuid":"samwgoldman","login":"samwgoldman","name":null,"email":"samwgoldman@gmail.com","url":null,"packages_count":3,"html_url":"https://www.npmjs.com/~samwgoldman","role":null,"created_at":"2022-11-10T11:27:56.255Z","updated_at":"2022-11-10T11:27:56.255Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/samwgoldman/packages"},{"uuid":"avikchaudhuri","login":"avikchaudhuri","name":null,"email":"avik.ch@gmail.com","url":null,"packages_count":3,"html_url":"https://www.npmjs.com/~avikchaudhuri","role":null,"created_at":"2022-11-10T11:27:56.257Z","updated_at":"2022-11-10T11:27:56.257Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/avikchaudhuri/packages"},{"uuid":"marcoww","login":"marcoww","name":null,"email":"mwang267@gmail.com","url":null,"packages_count":2,"html_url":"https://www.npmjs.com/~marcoww","role":null,"created_at":"2025-12-11T22:42:32.428Z","updated_at":"2025-12-11T22:42:32.428Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/marcoww/packages"}]}