Package Health

rrdom

`rrdom` is a virtual dom library that is used by `rrweb` to replay DOM mutations. It is a standalone library that can be used to create a virtual dom tree and apply patches to the real dom. It's used in `rrweb` to optimize replay performance especially wh

Latest 2.1.7NPMNPM

78%

Total Score

healthy

Healthy release with active maintenance and provenance, despite workflow secret exposure and an unclear package-to-repository link.

Health Score Breakdown

Lifecycle scriptscaution

A prepublish lifecycle script is present. This is a mild supply-chain and reproducibility concern, although the package also has build provenance and an active source project.

Repo package mentioncaution

The repository name does not match rrdom and its README does not mention the package. While a monorepo can explain the name mismatch, the absence of a package mention leaves the linkage less transparent.

Workflow auditcaution

All seven workflows were analyzed and scope permissions at job level, with no untrusted checkout or script-injection findings. However, 18 of 25 action references are unpinned and a high-confidence overprovisioned-secrets finding exposes the entire secrets context; the trusted-publishing finding also warrants caution.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
rrweb-snapshot
Version ^2.1.7
—
—

Weekly Downloads

Info

Last Published
9 days ago
Created
4 years ago
Unpacked Size
2.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform