遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。 显示详细资料
[](https://www.bestpractices.dev/projects/9058)
<a href="https://www.bestpractices.dev/projects/9058"><img src="https://www.bestpractices.dev/projects/9058/badge"></a>
A querystring parser with nesting support
https://github.com/ljharb/.github/blob/main/CONTRIBUTING.md
This requirement is too high and unnecessary. The DCO is implicit with all contributions, imo.
https://github.com/ljharb/qs?tab=coc-ov-file#readme
https://github.com/ljharb/qs
i18n does not apply.
no passwords are stored.
qs maintains all previous minor lines, generally. the changelog and linked PRs describe how to make changes or migrate.
github issues
no vulns in the last 12 months
https://github.com/ljharb/qs/security/policy
eslint, implicitly. https://github.com/ljharb/qs/blob/main/.eslintrc
eslint
no native binaries
there's a build system, but this item doesn't apply to this library.
It recursively builds subdirectories, but does not build any dependencies.
npm run dist
npm install
npm install && npm test
https://github.com/ljharb/qs/blob/main/package.json
https://github.com/ljharb/qs/blob/29dda211e8b02654f60975bdb703bcc73a8ee409/package.json#L75 runs in CI
we avoid using deprecated things when possible.
github actions
we do this
we use codecov
警告:需要更长的理由。
these concerns don't apply.
npm does this automatically
each version tag is signed.
Doesn't apply.
后退