Shareable commitlint config enforcing conventional commits
88%
Total Score
100
100
94
67
50
The release has no build attestation or trusted-publisher provenance. This is a supply-chain transparency gap, but it is not evidence that the release is unsafe by itself.
The repository uses TypeScript, Vitest, npm scripts, Vite, and SWC, providing an established build and test toolchain. No security scanning tools were detected, leaving a modest security-process gap.
No repository security policy was detected. This reduces transparency about vulnerability reporting and response, although active maintenance provides some compensation.
All five workflows were analyzed with no untrusted checkouts or script injection, but 20 of 25 action uses are unpinned, one workflow has top-level write permissions, and a high-confidence low-severity finding reports an ad hoc package install. These are workflow hygiene concerns rather than severe risks on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@commitlint/types Version ^21.2.3 | — | — |
conventional-changelog-conventionalcommits Version ^10.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.