CSpell Config library
78%
Total Score
healthy
Healthy, supported by frequent releases and active development despite workflow permissions and unclear package association.
One contributor made about 87% of recent commits, which is concentrated, but nine active contributors and organization ownership provide some handoff capacity.
The repository name does not match this package and its README does not mention cspell-config-lib, so the package's association with the linked monorepository is not explicit. This is a transparency concern even though name mismatches can occur for subpackages.
The audit found a high-confidence high-severity github-app issue where an app token inherits blanket installation permissions. Four workflows have top-level write access, and only 30 of 37 workflows were analyzed, although no untrusted checkout or script-injection paths were found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yaml Version ^2.9.0 | — | — |
smol-toml Version ^1.8.0 | — | — |
comment-json Version ^5.0.0 | — | — |
@cspell/cspell-types Version 10.3.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.