Package Health

@stoplight/spectral-formatters

This project exposes the available formatters from the CLI for users that perform custom validation through Javascript.

Latest 1.6.0NPMNPM

82%

Total Score

healthy

Healthy; active organization-backed maintenance outweighs workflow hygiene and security-transparency gaps.

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher identity is recorded, leaving release origin less independently verifiable even though other maintenance signals are strong.

Repo package mentioncaution

The repository name does not match the package and its README does not mention it, which warrants caution about package-to-source linkage; the organization-backed monorepo context partly explains the mismatch.

Repo toolingcaution

The repository uses TypeScript, npm scripts, and SWC, but no security scanning tools were detected, leaving a security-process gap.

Security policycaution

The linked repository has no security policy, reducing clarity about how users should report vulnerabilities and how maintainers handle them.

Workflow auditcaution

All six workflows were analyzed with no untrusted checkout or script-injection findings, but 18 of 20 action references are unpinned; a high-confidence secrets-inherit finding and an adhoc package installation add workflow hygiene concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
chalk
Version 4.1.2
—
—
cliui
Version 7.0.4
—
—
tslib
Version ^2.8.1
—
—
lodash
Version ^4.18.1
—
—
strip-ansi
Version 6.0
—
—

Weekly Downloads

Info

Last Published
10 days ago
Created
3 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform