Package Health

@vercel/static-build

Latest 20.0.1NPMNPM

82%

Total Score

healthy

Active, well-supported project with a repository-reference mismatch and incomplete workflow hygiene.

Health Score Breakdown

Build provenancecaution

No build attestation is present, leaving publication provenance less verifiable even though the trusted publisher identity is GitHub.

Repo package mentioncaution

The repository name does not match the package and its README does not mention @vercel/static-build, so the package-to-repository association is less transparent; the monorepo context partly explains the name mismatch but not the missing README mention.

Workflow auditcaution

All 24 workflows were analyzed, but one file failed auditing; 75 of 156 action references are unpinned, and high-confidence template-injection findings plus ad hoc package installs indicate workflow hygiene gaps. The workflow_run trigger is in a different path from the reported template-injection findings, so this is caution rather than a standalone severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
ts-morph
Version 12.0.0
—
—
@vercel/static-config
Version 3.4.4
—
—
@vercel/gatsby-plugin-vercel-builder
Version 2.2.71
—
—
@vercel/gatsby-plugin-vercel-analytics
Version 1.0.12
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
6 years ago
Unpacked Size
2.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform