Package Health

pretty-format

Stringify any JavaScript value.

Latest 30.5.1NPMNPM

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher provenance is reported, which leaves publication origin less verifiable, but the repository and release history provide substantial compensating transparency.

Repo bus factorcaution

One contributor made about 96% of the recent commits, creating a meaningful concentration risk despite two other active contributors and organization backing.

Repo package mentioncaution

The repository name does not match pretty-format and its README does not mention the package, so the package-to-repository relationship is less transparent; the organization-backed Jest monorepo context partly offsets this concern.

Workflow auditcaution

All 11 workflows were analyzed, all 48 action references are pinned, and no untrusted checkout or script-injection paths were found. The high-confidence use-trusted-publishing finding and three workflows with top-level write permissions are workflow hygiene concerns, though no high- or medium-severity issue was reported.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
ansi-styles
Version ^5.2.0
—
—
@jest/schemas
Version 30.5.0
—
—
@jest/react-is-18
Version npm:react-is@^18.3.1
—
—
@jest/react-is-19
Version npm:react-is@^19.2.5
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
11 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform