Package Health

@redocly/cli

It includes an MIT license, a clear README, and release notes for this version. Build provenance is present; workflow hygiene is mostly sound, with only minor package-install findings.

Latest 2.57.0NPMNPM

92%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Repo toolingcaution

The project uses TypeScript, Vitest, and npm scripts for its build and tests. No security-scanning tools were detected, which is a modest transparency gap but not enough to outweigh the active project evidence.

Security policycaution

The repository has no security policy. This weakens vulnerability-reporting transparency, though the active organization-backed project and other release evidence partly compensate.

Workflow auditcaution

All 13 workflows were analyzed with no high- or medium-severity findings and no untrusted checkout or script-injection paths. Three high-confidence low-severity adhoc-package findings and two unpinned action references leave minor hygiene concerns.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-63225
@redocly/cli is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 1.34.17 and 2.0.0 - 2.33.2.
0.0.0 - 1.34.172.0.0 - 2.33.2
Medium

Package versions

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 days ago
Created
4 years ago
Unpacked Size
9.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform