ambolt

CRA Index / npm / @jridgewell/resolve-uri

@jridgewell/resolve-uri and the Cyber Resilience Act

3 of 9 readable security signals are in place for @jridgewell/resolve-uri 3.1.2 (npm). Data checked 2026-10-05.

@jridgewell/resolve-uri 3.1.23 of 9 signals
Signals from public data, not a compliance assessment. A missing signal can mean the project keeps it elsewhere.

@jridgewell/resolve-uri 3.1.2 is the current default version of this npm package, published on 2024-02-14. The registry lists 15 versions in total and the licence declared is MIT. The source repository is jridgewell/resolve-uri with 11 stars.

The OpenSSF Scorecard for the repository was last computed on 2026-08-24 and gives an overall 2.8/10. Signals that are not in place today: actively maintained; security policy; code review before merge; ci workflow hygiene; signed releases or provenance; automated security testing.

As of 2026-10-05, deps.dev lists no known advisories for this version. That is a snapshot and not a promise: new advisories can be published at any time.

If you ship a product that includes @jridgewell/resolve-uri, the Cyber Resilience Act expects you to know which components you ship, to follow their vulnerabilities and to exercise due diligence on third-party components (Annex I, Part II and Article 13). In practice: list @jridgewell/resolve-uri 3.1.2 in your SBOM with its package URL pkg:npm/%40jridgewell/[email protected], watch for new advisories, and note that you have no published security contact upstream, so plan how you would report a problem. With several signals missing, consider whether a better-maintained alternative exists.

Put the badge in your README

CRA signals for @jridgewell/resolve-uri

Check your own project

Run the repository check on jridgewell/resolve-uri, or check your own SBOM and create the licence notices.

More in the index

shebang-command, has-symbols, es-errors, call-bind-apply-helpers, es-define-property, get-proto · all npm packages

Sources and method

Package and version facts, licences, advisories and provenance: deps.dev (generated data under CC BY 4.0; advisories from OSV). Repository signals: the OpenSSF Scorecard. We read them on 2026-10-05 and show them without scoring the people behind a project. The nine signals are our selection; every signal could be read for this package.

Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.