Package Health

p-queue

Promise queue with concurrency control

Latest 9.3.5NPMNPM

78%

Total Score

healthy

Regular releases and a maintained repository support adoption, despite one active contributor and unpinned workflow actions.

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher provenance was detected, leaving publication origin less independently verifiable despite the otherwise matching source repository.

Project backingcaution

The repository is owned by an individual rather than an organization, so the single-contributor maintenance concentration is not offset by visible organizational backing.

Repo bus factorcaution

All six recent commits came from one contributor, giving the project a concentrated maintenance dependency and increasing continuity risk.

Repo toolingcaution

The repository uses TypeScript and npm build tooling, but no security scanning tools were detected; this is a modest transparency gap rather than evidence of abandonment.

Workflow auditcaution

The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both of its two action references are unpinned, which weakens build reproducibility.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
p-timeout
Version ^7.0.0
—
—
eventemitter3
Version ^5.0.4
—
—

Weekly Downloads

Info

Last Published
4 hours ago
Created
9 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform