Package Health

@microsoft/applicationinsights-dependencies-js

Microsoft Application Insights XHR dependencies plugin

Latest 3.4.5NPMNPM

86%

Total Score

healthy

Frequent releases and active Microsoft-backed maintenance outweigh concentrated commits and workflow hygiene concerns.

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher provenance is reported, leaving publication origin less independently verifiable than it could be. This is a transparency gap, not evidence that the release is unsafe.

Workflow auditcaution

All seven workflows were analyzed, all 18 action references are pinned, and no untrusted checkout or script-injection paths were found. However, five workflows use top-level write permissions and high-severity cache-poisoning findings have low confidence, while high-confidence adhoc-package findings show installs outside a lockfile; together these are workflow hygiene cautions rather than a severe dependency risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
@nevware21/ts-async
Version >= 0.5.5 < 0.6.0
—
—
@nevware21/ts-utils
Version >= 0.14.0 < 2.x
—
—
@microsoft/dynamicproto-js
Version ^2.0.3
—
—
@microsoft/applicationinsights-shims
Version 3.0.1
—
—
@microsoft/applicationinsights-core-js
Version 3.4.5
—
—

Weekly Downloads

Info

Last Published
4 days ago
Created
7 years ago
Unpacked Size
8.8 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform