Package Health

conventional-changelog-writer

Write logs based on conventional commits and templates.

Latest 9.3.0NPMNPM

91%

Total Score

healthy

Active, well-backed project with frequent releases and strong packaging; only workflow pinning and security-policy gaps temper the score.

Health Score Breakdown

Repo toolingcaution

The project uses TypeScript, Vite, and npm scripts, but no security-scanning tools were detected; this is a modest transparency and hygiene gap.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting guidance unclear.

Workflow auditcaution

All 5 workflows were analyzed with no audit findings or untrusted checkout/script-injection sinks. However, all 37 action references are unpinned and one workflow grants top-level write permissions, creating a CI supply-chain hygiene concern without evidence of an active exploit path.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
verkit
Version ^0.5.0
—
—
argue-cli
Version ^3.1.0
—
—
@simple-libs/stream-utils
Version ^2.0.0
—
—
conventional-commits-filter
Version ^6.0.1
—
—
@conventional-changelog/template
Version ^1.4.0
—
—

Weekly Downloads

Info

Last Published
6 days ago
Created
11 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform