Package Health

@turbo/workspaces

Tools for working with package managers

Latest 2.11.7NPMNPM

82%

Total Score

healthy

Healthy, backed by active maintenance and releases, with workflow security hygiene as the main caveat.

Health Score Breakdown

Repo bus factorcaution

One contributor made about 84% of recent commits, creating concentration risk, though 27 other contributors were active and the repository is organization-owned.

Repo package mentioncaution

The repository name does not match the package and its README does not mention `@turbo/workspaces`, which creates some package-to-repository transparency concern; the organization-owned Turborepo monorepo context partly explains the mismatch.

Workflow auditcaution

All 12 workflows were analyzed with no untrusted checkout or script-injection findings, and 11 use read-only permissions. High-confidence template injection, inherited secrets, ad hoc package installation, and trusted-publishing findings are concrete workflow hygiene risks, though the workflow-run trigger has no identified untrusted sink.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
ora
Version 4.1.1
—
—
execa
Version 5.1.1
—
—
semver
Version 7.6.2
—
—
js-yaml
Version 4.3.2
—
—
fs-extra
Version 10.1.0
—
—

Weekly Downloads

Info

Last Published
9 days ago
Created
3 years ago
Unpacked Size
1.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform