Package Health

luxon

Immutable date wrapper

Latest 3.7.2NPMNPM

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No registry build attestation or trusted-publisher provenance is present, leaving the relationship between source and published artifact less independently verifiable.

Release historycaution

The project has 151 releases over more than nine years, but it has had no registry release in the last 12 months despite repository activity, so release maintenance appears slower than its historical cadence.

Repo issue activitycaution

The repository has only one new issue and no closed issues in the last month, while three pull requests were opened and none merged, suggesting some current workflow sluggishness.

Repo toolingcaution

The repository uses established build tooling including Babel, npm scripts, and Rollup, but reports no security scanning tools, leaving a modest security-process gap.

Security policycaution

The repository has no security policy, so consumers lack a clearly documented channel and process for reporting vulnerabilities.

Vulnerabilities

TitleVersionsSeverity
CVE-2023-22467
luxon is vulnerable to Inefficient Regular Expression Complexity in versions 2.0.0 - 2.5.2, 3.0.0 - 3.2.1 and 1.0.0 - 1.28.1.
1.0.0 - 1.28.12.0.0 - 2.5.23.0.0 - 3.2.1
High

Package versions

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 year ago
Created
9 years ago
Unpacked Size
4.4 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform