config validator for commitlint.config.js
88%
Total Score
100
89
75
The repository name and README do not directly mention this package, which creates a package-identity transparency gap; the extensive monorepo file tree does show the @commitlint package family, partly reducing that concern.
The project uses TypeScript, Vitest, build tooling, and npm scripts, supporting a structured development process, though no security-scanning tools were detected.
The repository has no security policy, leaving vulnerability-reporting expectations unclear despite otherwise active maintenance.
All five workflows were analyzed with no untrusted checkouts or script injection, but 20 of 25 action references are unpinned and a high-confidence audit found ad hoc package installation; one workflow also grants top-level write access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ajv Version ^8.11.0 | — | — |
@commitlint/types Version ^21.2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.