Package Health

@stoplight/spectral-runtime

Latest 1.1.6NPMNPM

80%

Total Score

healthy

Healthy: active organization-backed maintenance outweighs workflow pinning and credential-hygiene concerns.

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher provenance was recorded. This weakens release transparency, although the active organization-owned repository provides some compensating context.

Repo package mentioncaution

The repository name does not match the package and its README does not mention the package, so the linkage is less explicit. Because the repository is organization-backed and appears to be a broader project repository, this is a limited caution rather than a severe concern.

Repo toolingcaution

The project uses TypeScript, npm scripts, and SWC for builds, showing established build tooling. No security scanning tools were detected, leaving a modest transparency gap.

Security policycaution

The repository has no security policy, so vulnerability reporting and response expectations are less transparent. Active maintenance and organizational backing partly reduce the concern but do not remove it.

Workflow auditcaution

All six workflows were analyzed without dangerous trigger-and-sink combinations, but 18 of 20 action references are unpinned. High-confidence secrets inheritance and ad hoc package installation add workflow hygiene concerns, though no high-severity findings were reported.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tslib
Version ^2.8.1
—
—
lodash
Version ^4.18.1
—
—
node-fetch
Version ^2.7.0
—
—
@stoplight/json
Version ^3.20.1
—
—
@stoplight/path
Version ^1.3.2
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
5 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform