Package Health

style-dictionary

Style once, use everywhere. A build system for creating cross-platform styles.

Latest 5.6.1NPMNPM

88%

Total Score

healthy

Frequent releases and active contributors support this package; unpinned workflow actions and missing security policy are the main concerns.

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

A prepare script runs during installation, adding install-time behavior that deserves review even though the signal does not show malicious behavior.

Repo toolingcaution

The repository uses established build tools, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.

Security policycaution

No repository security policy was found, reducing clarity about vulnerability reporting and response expectations.

Workflow auditcaution

Both workflows were audited successfully with no reported findings or untrusted checkout and injection sinks, but all seven action references are unpinned and one workflow has top-level write permissions; without an untrusted trigger, this is workflow hygiene rather than a severe risk.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-580810
style-dictionary is vulnerable to Prototype Pollution in versions 5.5.0 - 5.5.0.
5.5.0 - 5.5.0
High
CVE-2026-54639
style-dictionary is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 4.3.0 - 5.4.4.
4.3.0 - 5.4.4
High

Package versions

Direct Dependencies

DependencyLast ReleaseScore
chalk
Version ^5.3.0
—
—
json5
Version ^2.2.2
—
—
prettier
Version ^3.3.3
—
—
commander
Version ^12.1.0
—
—
colorjs.io
Version ^0.5.2
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
9 years ago
Unpacked Size
4.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform