3 ms·
Yes, we (internally) call this a "Bill of Health" and believe that all packages should have this kind of diff-able information available. Understanding what's
by clarkbw 7y ago
Yes, we (internally) call this a "Bill of Health" and believe that all packages should have this kind of diff-able information available. Understanding what's happening at the source level is key to being able to trust any package published.
- mceachen 7y agoNICE! It would be wonderful to expose that information! Somewhat related, I believe NPM pulled in (or co-opted) some of the heuristics from this: https://github.com/npms-io/npms-analyzer https://github.com/npms-io/npms-analyzer (but those don't seem to include any of the aspects I suggested above).