Package Health

@whatwg-node/node-fetch

Fetch API implementation for Node

Latest 0.9.1NPMNPM

84%

Total Score

healthy

Healthy, with frequent releases and active repository work; unpinned workflow images are the main caveat.

Health Score Breakdown

Repo bus factorcaution

Four contributors were active in three months, but one contributor made about 84% of commits. That concentration creates some continuity risk because the repository owner is an individual.

Security policycaution

The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent.

Version stabilitycaution

Version 0.9.1 is not a stable major release, and 95% of recent releases are prereleases, which increases compatibility uncertainty for dependents.

Workflow auditcaution

All five workflows were analyzed, with no untrusted checkout or script-injection paths. However, four high-confidence findings identify unpinned container images, leaving build inputs less reproducible and requiring workflow hygiene improvements.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tslib
Version ^2.6.3
—
—
@fastify/busboy
Version ^3.1.1
—
—
@whatwg-node/disposablestack
Version ^0.1.0
—
—
@whatwg-node/promise-helpers
Version ^2.0.0
—
—

Weekly Downloads

Info

Last Published
10 days ago
Created
4 years ago
Unpacked Size
0.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform