Package Health

electron-publish

Latest 26.15.3NPMNPM

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

95

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Health Score Breakdown

Repo bus factorcaution

One contributor made about 89% of the recent commits, creating a real concentration risk. However, five other contributors were active during the same period and the repository is organization-owned, which partly compensates for the concentration.

Repo package mentioncaution

The repository name does not match electron-publish and its README does not mention the package, so the package-to-repository relationship is less explicit. The package description identifies it as part of electron-builder, which makes a monorepo relationship plausible but does not fully remove the transparency gap.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations less transparent. This is a documentation gap, not evidence of abandonment.

Token permissionscaution

Six workflows declare read-only permissions, but one lacks top-level permissions and two declare top-level write access. The mixed permissions posture warrants caution even though the workflow risk scan found no dangerous patterns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
aws4
Version ^1.13.2
—
—
mime
Version ^2.5.2
—
—
chalk
Version ^4.1.2
—
—
fs-extra
Version ^10.1.0
—
—
lazy-val
Version ^1.0.5
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
9 years ago
Unpacked Size
0.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform