Package Health

@firebase/ai

The Firebase AI SDK

Latest 3.0.0NPMNPM

86%

Total Score

healthy

Active organization-backed project with strong release activity; workflow hygiene and package-to-repository linkage need attention.

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher identity is present, leaving publication provenance less transparent than it could be. This is moderated by the active organization-backed project and strong release history.

Maintainerscaution

Three of four publishing accounts use the Google domain, consistent with the organization-backed repository. feiyang.chen (gmail.com) is an outside consumer account, so account hygiene is a minor caution rather than evidence of weak maintenance capacity.

Repo package mentioncaution

The repository name does not match @firebase/ai and its README does not mention the package. Although a monorepo name mismatch is normal, the absence of a package mention leaves a small linkage concern.

Repo toolingcaution

The repository uses established build tooling including Nx, TypeScript, Rollup, Webpack, and Babel. No security-scanning tooling was detected, which is a modest transparency gap for a widely used SDK.

Workflow auditcaution

All 21 workflows were analyzed, all 106 action references are pinned, permissions are read-only or job-scoped, and no untrusted checkout or script injection was found. The audit still found high-confidence low-severity adhoc package installation and a low-confidence cache-poisoning pattern, so workflow hygiene is a minor caution.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tslib
Version ^2.1.0
—
—
@firebase/util
Version 1.15.3
—
—
@firebase/logger
Version 0.5.2
—
—
@firebase/component
Version 0.7.5
—
—
@firebase/app-check-interop-types
Version 0.3.5
—
—

Weekly Downloads

Info

Last Published
3 days ago
Created
1 year ago
Unpacked Size
2.6 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform