Package Health

@peculiar/asn1-cms

ASN.1 schema for Cryptographic Message Syntax (CMS) defined in RFC 5652.

Latest 2.10.0NPMNPM

78%

Total Score

healthy

Healthy release with active maintenance and provenance; workflow pinning and injection findings warrant caution.

Health Score Breakdown

Repo package mentioncaution

The repository name does not match the package and its README does not mention the package, creating some uncertainty about package-to-repository alignment; the package is visibly part of a larger monorepo, which partly explains the mismatch.

Repo toolingcaution

The project uses TypeScript, Vitest, and npm build tooling, but no security-scanning tools were detected; this is a modest transparency gap rather than a release blocker.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.

Workflow auditcaution

All nine workflow action references are unpinned, and the release workflow has three high-confidence template-injection findings. The workflows have no untrusted checkout or pull_request_target trigger, so these remain workflow-hygiene concerns rather than an independently severe dependency risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tslib
Version ^2.8.1
—
—
asn1js
Version ^3.0.10
—
—
@peculiar/asn1-x509
Version ^2.10.0
—
—
@peculiar/asn1-schema
Version ^2.10.0
—
—
@peculiar/asn1-x509-attr
Version ^2.10.0
—
—

Weekly Downloads

Info

Last Published
14 days ago
Created
6 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform