# Flow library being hammered?

**URL:** <https://discourse.nodered.org/t/flow-library-being-hammered/81579>\
**Category:** General\
**Created:** [25 September 2023 19:31 UTC](https://discourse.nodered.org/t/flow-library-being-hammered/81579 "2023-09-25T19:31:08Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [25 September 2023 19:31 UTC](https://discourse.nodered.org/t/flow-library-being-hammered/81579/1 "2023-09-25T19:31:08Z")

</div>

I am only bringing this is up, as it caused a few performance issues last time.

But I have been seeing this all day, up until the last 1 hour?  
seems like an automated run - it goes for a few pages

 ![Screenshot 2023-09-25 at 20.28.13](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/3/c/3cf485c582daeddcdf1efd091ce222bea338a3d6.png)

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [25 September 2023 19:38 UTC](https://discourse.nodered.org/t/flow-library-being-hammered/81579/2 "2023-09-25T19:38:03Z")

</div>

Mmm... maybe not? - it seems to be spread over the last few day(s).

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [25 September 2023 20:04 UTC](https://discourse.nodered.org/t/flow-library-being-hammered/81579/3 "2023-09-25T20:04:15Z")

</div>

I note that though the @softwaredevelopment nodes purport to have github repos, the links do not work (on some of them at least).

The Scorecard tests don't appear to check for that.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [25 September 2023 20:06 UTC](https://discourse.nodered.org/t/flow-library-being-hammered/81579/4 "2023-09-25T20:06:09Z")

</div>

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/4/4/4455935dd7c57719ce2f5753f5b306f313abf844.png)

@knolleary, @Steve-Mcl ?

[Bodhi | Building Intelligence](https://bodhi.software/)

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [25 September 2023 20:10 UTC](https://discourse.nodered.org/t/flow-library-being-hammered/81579/5 "2023-09-25T20:10:55Z")

</div>

> [@Colin](#):
>
> I note that though the @softwaredevelopment nodes purport to have github repos, the links do not work (on some of them at least).

Yeah noted that also! all private repos, yet stated in `package.json`as such.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [26 September 2023 07:59 UTC](https://discourse.nodered.org/t/flow-library-being-hammered/81579/6 "2023-09-26T07:59:36Z")

</div>

I don't see anything wrong here. They have published a bunch of nodes to the library. The fact they are closed-source is their choice - we don't require modules to be open-source to be listed on the library.

We did originally look at getting the scorecard to validate the github repo - but it proved a more complex task so we backed off. In this instance, checking it doesn't 404 would be sufficient. It gets harder to answer the question when it doesn't 404 - assessing whether the url points to a git repository (across multiple hosted git providers), and whether that git repo contains the code for the node in question. There are examples of git repos (node-red-nodes for example) that are monorepos that contain multiple nodes... and so on. Plenty of edge cases that could give an incorrect result with the scorecard.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [25 November 2023 07:59 UTC](https://discourse.nodered.org/t/flow-library-being-hammered/81579/7 "2023-11-25T07:59:42Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
