Package Health

@ucast/mongo2js

git@github.com:stalniy/ucast.git

Latest 2.0.0NPMNPM

78%

Total Score

healthy

Healthy release backed by recent maintenance and solid package documentation, with single-contributor and workflow-hygiene caveats.

Health Score Breakdown

Build provenancecaution

No build attestation, trusted publisher, or staged publishing is recorded, limiting verification of how the artifact was produced.

Repo bus factorcaution

All three recent commits came from one contributor, leaving maintenance concentrated and creating a meaningful continuity risk.

Security policycaution

The repository has no security policy, which leaves vulnerability reporting and response expectations undocumented.

Workflow auditcaution

Both workflows were analyzed without dangerous triggers, untrusted checkouts, script injection, or audit findings, and one scopes permissions at job level. However, all four action references are unpinned, creating a workflow supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
@ucast/js
Version 4.0.1
—
—
@ucast/core
Version 2.0.0
—
—
@ucast/mongo
Version 3.0.0
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
6 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform