Package Health

@globalart/nestjs-logger

A advanced logger for NestJS

Latest 4.3.0NPMNPM

68%

Total Score

caution

Usable with caveats: rapid releases and organization backing offset a one-contributor repository, unclear package linkage, and weak workflow pinning.

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher provenance is recorded, leaving the connection between source and published artifact less transparent.

Repo bus factorcaution

All 17 recent commits came from one contributor, giving the project a thin active contributor base. Organization backing partly compensates, but not enough to remove the maintenance risk.

Repo package mentioncaution

The repository name does not match the package and its README does not mention the package, so the package-to-source relationship is not clearly demonstrated despite the monorepo containing a similarly named documentation path.

Security policycaution

No security policy is present in the repository. This is a transparency and vulnerability-reporting gap, though it is not evidence of unsafe code by itself.

Workflow auditcaution

Both workflows were analyzed with no dangerous sinks or audit findings, but 4 of 5 action references are unpinned and one workflow grants top-level write access. These are workflow hygiene concerns rather than a severe risk because no untrusted checkout or injection path was found.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
nanoid
Version ^6.0.0
—
—
express
Version ^5.2.1
—
—

Weekly Downloads

Info

Last Published
10 days ago
Created
1 year ago
Unpacked Size
1.6 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform