Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
qrisk2-2014
Advanced tools
Javascript implementation of the QRisk2-2014 10 year cardiovascular risk prediction algorithms.
For further details of the algorithm see the QRisk website
npm install qrisk2-2014
To execute unit tests:
mocha spec/*.js
An additional set of regression tests can be found at qrisk2-2014-regression
var qrisk2 = require('qrisk2-2014');
var args = {
age: 30,
b_AF: 0,
b_ra: 0,
b_renal: 0,
b_treatedhyp: 0,
b_type1: 0,
b_type2: 0,
bmi: 25,
ethrisk: 1,
fh_cvd: 0,
rati: 1,
sbp: 120,
smoke_cat: 0,
surv: 10,
town: 0
};
var risk = qrisk2.male(args);
console.log('10 year cardiovascular risk = ', risk.score, '%');
console.log(risk);
QRISK2-2014 is free software: you can redistribute it and/or modify it under the terms of the GNU Lesser General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.
QRISK2-2014 is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.
You should have received a copy of the GNU Lesser General Public License along with QRISK2-2014. If not, see http://www.gnu.org/licenses/.
Additional terms:
The following disclaimer must be held together with any risk score score generated by this code. If the score is displayed, then this disclaimer must be displayed or otherwise be made easily accessible, e.g. by a prominent link alongside it.
The initial version of this file, to be found at http://svn.clinrisk.co.uk/opensource/qrisk2, faithfully implements QRISK2-2014.
ClinRisk Ltd. have released this code under the GNU Lesser General Public License to enable others to implement the algorithm faithfully.
However, the nature of the GNU Lesser General Public License is such that we cannot prevent, for example, someone accidentally altering the coefficients, getting the inputs wrong, or just poor programming.
ClinRisk Ltd. stress, therefore, that it is the responsibility of the end user to check that the source that they receive produces the same results as the original code posted at http://svn.clinrisk.co.uk/opensource/qrisk2.
Inaccurate implementations of risk scores can lead to wrong patients being given the wrong treatment.
Supported by Black Pear Software Ltd
FAQs
QRisk2-2014 10 year cardiovascular risk prediction algorithms
The npm package qrisk2-2014 receives a total of 4 weekly downloads. As such, qrisk2-2014 popularity was classified as not popular.
We found that qrisk2-2014 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.