Package Health

@cspell/cspell-resolver

Library to help resolve module locations.

Latest 10.3.6NPMNPM

82%

Total Score

healthy

Healthy, with a high-confidence workflow permission finding as the main caveat.

Health Score Breakdown

Repo bus factorcaution

One contributor made about 87% of recent commits, which concentrates operational knowledge. However, the repository is organization-owned and eight other contributors were active, partly compensating for that concentration.

Repo package mentioncaution

The repository name differs from the package name and its README does not mention this package, creating some uncertainty about the package-to-repository linkage. The package is scoped under the same project family, so this is a caution rather than a severe concern.

Workflow auditcaution

The audit found a high-confidence github-app issue where an app token inherits blanket installation permissions, and only 30 of 37 workflows were analyzed. The pull_request_target triggers had no reported untrusted checkout or script-injection sinks, but the credential scope remains a real hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
global-directory
Version ^5.0.0
—
—

Weekly Downloads

Info

Last Published
12 days ago
Created
3 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform