Package Health

mdast-util-to-markdown

mdast utility to serialize markdown

Latest 2.2.0NPMNPM

88%

Total Score

healthy

Healthy: active organization-backed maintenance and a recent release outweigh minor workflow pinning gaps.

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher provenance is recorded, leaving publication origin less independently verifiable despite the package's otherwise healthy maintenance evidence.

Repo toolingcaution

The project uses TypeScript and npm build tooling, but no repository security-scanning tool was detected. This is a modest transparency and hygiene gap, not evidence of abandonment.

Workflow auditcaution

Both workflows were analyzed without failed files or dangerous findings, and the pull_request_target workflow has no untrusted checkout or script-injection sink. However, all four action references are unpinned, which weakens reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
zwitch
Version ^2.0.0
—
—
@types/mdast
Version ^4.0.0
—
—
@types/unist
Version ^3.0.0
—
—
longest-streak
Version ^3.0.0
—
—
unist-util-visit
Version ^5.0.0
—
—

Weekly Downloads

Info

Last Published
8 days ago
Created
6 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform