Package Health

@expo/code-signing-certificates

A library for working with expo-updates code signing certificates

Latest 0.0.7NPMNPM

68%

Total Score

caution

Usable with caveats: maintenance has gone quiet recently and workflow dependencies are unpinned.

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher identity is provided, limiting publication transparency, though this is a provenance gap rather than evidence of unsafe code.

Maintainerscaution

The package is backed by the expo organization, which makes a short company-domain maintainer base expected; however, publish access also includes outside accounts such as ide (jameside.com), bycedric (bycedric.com), tsapeta (tsapeta.com), and philpl (kitten.sh), creating account-hygiene risk.

Repo commit activitycaution

The repository shows zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern despite the recent push and merged pull requests.

Repo toolingcaution

The repository uses TypeScript and npm scripts, but no security scanning tools were detected, leaving a modest security-process gap.

Security policycaution

The repository has no security policy, so vulnerability reporting and response expectations are not documented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
node-forge
Version ^1.4.0
—
—

Weekly Downloads

Info

Last Published
11 days ago
Created
4 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform