MarkdownLint Command Line Interface
82%
Total Score
75
100
100
67
50
No build attestation or trusted-publisher provenance is provided, leaving publication origin less independently verifiable despite the package's established release history.
The repository is owned by an individual rather than an organization, so the concentrated recent commit activity has less visible institutional redundancy.
Two contributors were active recently, but one made 8 of 9 commits, so maintenance is substantially concentrated in a single contributor.
The repository has no published security policy, reducing transparency about how vulnerabilities should be reported and handled.
Both workflows were fully analyzed with no reported audit findings and no untrusted checkouts or script injection. However, all 8 action references are unpinned, which weakens build reproducibility and action supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ignore Version ~7.0.6 | — | — |
js-yaml Version ~5.2.1 | — | — |
run-con Version ~1.3.3 | — | — |
commander Version ~15.0.0 | — | — |
minimatch Version ~10.2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.