{"id":21429740,"url":"https://github.com/limechain/mongoose-immutable-plugin","last_synced_at":"2025-08-24T16:11:38.762Z","repository":{"id":52067186,"uuid":"152110825","full_name":"LimeChain/mongoose-immutable-plugin","owner":"LimeChain","description":"Mongoose plugin guarding fields from modifications","archived":false,"fork":false,"pushed_at":"2023-04-29T14:13:02.000Z","size":5119,"stargazers_count":2,"open_issues_count":3,"forks_count":2,"subscribers_count":6,"default_branch":"master","last_synced_at":"2025-08-16T11:30:40.812Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/LimeChain.png","metadata":{"files":{"readme":"Readme.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2018-10-08T16:21:13.000Z","updated_at":"2025-05-20T13:16:48.000Z","dependencies_parsed_at":"2024-11-22T22:19:05.563Z","dependency_job_id":"3f4a603e-9403-4f3f-8fed-38c8db4af4cf","html_url":"https://github.com/LimeChain/mongoose-immutable-plugin","commit_stats":{"total_commits":18,"total_committers":3,"mean_commits":6.0,"dds":"0.33333333333333337","last_synced_commit":"792cc2318764b7ddef68b5b04a9ca3cc8e60ff78"},"previous_names":[],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/LimeChain/mongoose-immutable-plugin","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LimeChain%2Fmongoose-immutable-plugin","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LimeChain%2Fmongoose-immutable-plugin/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LimeChain%2Fmongoose-immutable-plugin/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LimeChain%2Fmongoose-immutable-plugin/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/LimeChain","download_url":"https://codeload.github.com/LimeChain/mongoose-immutable-plugin/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LimeChain%2Fmongoose-immutable-plugin/sbom","scorecard":{"id":84368,"data":{"date":"2025-08-11","repo":{"name":"github.com/LimeChain/mongoose-immutable-plugin","commit":"792cc2318764b7ddef68b5b04a9ca3cc8e60ff78"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":1.3,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":0,"reason":"Found 0/15 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":0,"reason":"license file not detected","details":["Warn: project does not have a license file"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 6 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"25 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-6chw-6frg-f759","Warn: Project is vulnerable to: GHSA-v88g-cgmw-v5xw","Warn: Project is vulnerable to: GHSA-93q8-gq69-wqmw","Warn: Project is vulnerable to: GHSA-fwr7-v2mv-hh25","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-4jwp-vfvf-657p","Warn: Project is vulnerable to: GHSA-v8w9-2789-6hhr","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-29mw-wpgm-hmr9","Warn: Project is vulnerable to: GHSA-35jh-r3h4-6jhm","Warn: Project is vulnerable to: GHSA-f8q6-p94x-37v3","Warn: Project is vulnerable to: GHSA-vh95-rmgr-6w4m","Warn: Project is vulnerable to: GHSA-xvch-5gv4-984h","Warn: Project is vulnerable to: GHSA-mh5c-679w-hh4r","Warn: Project is vulnerable to: GHSA-8687-vv9j-hgph","Warn: Project is vulnerable to: GHSA-f825-f98c-gj3g","Warn: Project is vulnerable to: GHSA-h8hf-x3f4-xwgp","Warn: Project is vulnerable to: GHSA-9m93-w8w6-76hh","Warn: Project is vulnerable to: GHSA-m7xq-9374-9rvx","Warn: Project is vulnerable to: GHSA-vg7j-7cwx-8wgw","Warn: Project is vulnerable to: GHSA-h466-j336-74wx","Warn: Project is vulnerable to: GHSA-p92x-r36w-9395","Warn: Project is vulnerable to: GHSA-45q2-34rf-mr94","Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw","Warn: Project is vulnerable to: GHSA-52f5-9888-hmc6"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-15T06:36:12.589Z","repository_id":52067186,"created_at":"2025-08-15T06:36:12.590Z","updated_at":"2025-08-15T06:36:12.590Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":271901382,"owners_count":24841116,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-24T02:00:11.135Z","response_time":111,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-22T22:19:01.806Z","updated_at":"2025-08-24T16:11:38.715Z","avatar_url":"https://github.com/LimeChain.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"[![npm version](https://badge.fury.io/js/mongoose-immutable-plugin.svg)](https://badge.fury.io/js/mongoose-immutable-plugin.svg) \n[![codecov](https://codecov.io/gh/LimeChain/mongoose-immutable-plugin/branch/master/graph/badge.svg)](https://codecov.io/gh/LimeChain/mongoose-immutable-plugin)\n\n# Mongoose immutable fields plugin\n\nImmutable property guards modifications on a field **after document creation**.\n\nMongoose immutable fields plugin was born when I had hard time trying to guard a field from modifications after document creation.\nI could not find something, which does that for me (maybe the mongoose concept in my head is wrong), but I had need of some way to \nprotect my fields (from developers - myself included).\n\n### Operations-Guard\nThe plugin guards fields modification for following operations :\n* re-save\n* update\n* updateOne\n* updateMany\n* findAndUpdate\n\n### Usage\n\n**Note!** Immutable-plugin is tested only for below types of fields. **The behavior of other types is unknown**\n\n\n| object | array | number | string |\n| ------ | :---: | :----: | -----: |\n\n---\n\n1. Simple Field Schema\n\n```javascript\nlet SimpleFieldSchema = new Schema({\n    id: Schema.Types.ObjectId,\n    simpleFieldA: {\n      type: String,\n      immutable: true\n    },\n    simpleFieldB: Number\n});\n\nSimpleFieldSchema.plugin(require('mongoose-immutable-plugin'));\n```  \n\n2. Nested Field Schema\n\n```javascript\nlet NestedFieldSchema = new Schema({\n  id: Schema.Types.ObjectId,\n  levelA: {\n    levelB: {\n      levelC1: {\n        type: String,\n        immutable: true\n      },\n      levelC2: String\n  \t}\n  }\n});\n\nNestedFieldSchema.plugin(require('mongoose-immutable-plugin'));\n```\n\n3. Array Field Schema\n\n**Note!**  Array-type field can be immutable, but the plugin will be triggered on array-level, not for array's items properties.\nThat means if you have for example an array of objects and mark an object(array item) property as immutable, plugin wont handle that. \n\nIf you mark an array as immutable one, before db update, the whole array will be removed with all modifications on it\n\n```javascript\nlet ArrayFieldSchema = new Schema({\n  id: Schema.Types.ObjectId,\n  arr: {\n    immutable: true\n    type: [\n    \t{ item: String }\n    ]\n  }\n});\n\nArrayFieldSchema.plugin(require('mongoose-immutable-plugin'));\n```\n\n4. Mixed Schema \n```javascript\nlet MixedImmutabilitySchema = new Schema({\n    id: Schema.Types.ObjectId,\n    parentA: {\n        arr: {\n            immutable: true,\n            type: [\n                { item: String }\n            ]\n        },\n        childA: String,\n        childB: {\n            arr1: {\n                immutable: true,\n                type: [\n                    { item: String }\n                ]\n            },\n            arr2: {\n                type: [\n                    { item: String }\n                ]\n            }\n        },\n        childC: {\n            type: String,\n            immutable: true,\n        }\n    },\n    parentB: String,\n    parentC: {\n        type: Number,\n        immutable: true,\n    }\n});\n\nMixedImmutabilitySchema.plugin(require('mongoose-immutable-plugin'));\n```\n\n\n\n### Tests\nYou need to have installed and run **mongodb**  \nRun tests -\u003e run the test file with **npm run test**\n\n### Limitations\n\n   * If you use re-save as a way to update a document, you will get back the document in the state before update (field will be updated although it is immutable) but if you retrieve it, it won't be\n       \n       ##### Example :\n       \t```javascript  \n            // You have defined someProp as immutable one\n            let doc = new DOCModel({ someProp: 5 });\n            let createdDOC = await doc.save();\n\n            // createdDOC.someProp =\u003e 5\n            \n            doc.someProp = 6;\n            let updatedDOC = await doc.save();\n            \n            // updatedDOC.someProp =\u003e 6\n\n            let retrievedDOCAfterUpdate = await DOCModel.findById(doc._id);\n\n            // retrievedDOCAfterUpdate.someProp =\u003e 5\n        ```\n            \n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Flimechain%2Fmongoose-immutable-plugin","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Flimechain%2Fmongoose-immutable-plugin","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Flimechain%2Fmongoose-immutable-plugin/lists"}