Package Health

@stoplight/spectral-functions

Latest 1.11.0NPMNPM

78%

Total Score

healthy

Healthy release, supported by active maintenance and an unarchived project despite workflow and package-linkage concerns.

Health Score Breakdown

Build provenancecaution

The release has no build attestation or trusted-publisher provenance, so consumers have less independent evidence connecting the published artifact to its source build.

Dependency profilecaution

Twelve runtime dependencies create a meaningful transitive maintenance surface for a utility package, though the profile is not unusually large enough to indicate severe risk.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention this package. Although a name mismatch can be normal for a monorepo, the absence of both signals creates uncertainty that this repository is the package's intended source.

Repo toolingcaution

The project uses TypeScript, npm scripts, and SWC for builds, but the collected repository tooling includes no security-scanning tools. That is a modest transparency and hygiene gap, not evidence of abandonment.

Security policycaution

No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
ajv
Version ^8.18.0
—
—
tslib
Version ^2.8.1
—
—
lodash
Version ^4.18.1
—
—
ajv-errors
Version ~3.0.0
—
—
ajv-formats
Version ~2.1.1
—
—

Weekly Downloads

Info

Last Published
10 days ago
Created
5 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform