Package Health

@orval/mock

Latest 8.41.0NPMNPM

82%

Total Score

healthy

Frequent releases, active contributions, and broad project participation outweigh workflow and repository-identification cautions.

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher identity is recorded, leaving release provenance less independently verifiable; the active repository and release workflows partly compensate.

Repo package mentioncaution

The repository name does not match @orval/mock and its README does not mention the package, creating a package-identification caution; the organization-backed monorepo context partly offsets it but does not remove the gap.

Workflow auditcaution

All seven workflows were analyzed, but all 23 action references are unpinned and four workflows grant top-level write permissions. High-confidence template-injection findings and trusted-publishing findings warrant workflow hygiene caution, while the low-confidence cache finding is not decisive.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-24132
@orval/mock is vulnerable to Improper Neutralization of Special Elements used in a Command ('Command Injection') in versions 0.0.0 - 7.20.0 and 8.0.0-rc.0 - 8.0.3.
0.0.0 - 7.20.08.0.0-rc.0 - 8.0.3
High

Package versions

Direct Dependencies

DependencyLast ReleaseScore
@orval/core
Version 8.41.0
—
—

Weekly Downloads

Info

Last Published
2 days ago
Created
2 years ago
Unpacked Size
0.4 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform