Package Health

@yarnpkg/libzip

Latest 3.2.2NPMNPM

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

95

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Health Score Breakdown

Build provenancecaution

No registry build attestation or trusted-publisher identity is present, reducing publication transparency, although this is not evidence of a maintenance failure by itself.

Dangerous workflowscaution

One workflow uses pull_request_target with an untrusted checkout, creating a meaningful CI exposure even though no script-injection workflows were detected.

Repo issue activitycaution

The repository continues to receive issues and pull requests, though none of seven new pull requests were merged in the measured month and the backlog is large.

Repo toolingcaution

The repository uses established build tools, but no security-scanning tools were detected, leaving a modest security-process gap.

Token permissionscaution

All 30 analyzed workflows lack top-level token permissions, and none declare read-only permissions; although no workflow has top-level write access, least-privilege configuration is not consistently explicit.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tslib
Version ^2.4.0
—
—
@yarnpkg/fslib
Version ^3.1.3
—
—
@types/emscripten
Version ^1.39.6
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
7 years ago
Unpacked Size
0.6 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform