[](https://www.npmjs.com/package/ts-proto) [](https://github.com/stephenh/ts-proto/actions)
88%
Total Score
healthy
Active releases, recent repository work, and a healthy contributor base outweigh license metadata and workflow pinning gaps.
The artifact and repository both contain license files, but the manifest declares ISC while the detected artifact license is Apache-2.0; the mismatch warrants clarification.
The package has a prepare lifecycle script, which adds install-time behavior and deserves awareness, but this signal alone does not show harmful or unnecessary execution.
The project uses TypeScript and npm build tooling, but no security scanning tools were detected; this is a modest transparency gap rather than evidence of abandonment.
No repository security policy was found, reducing guidance for reporting vulnerabilities, though active maintenance and provenance provide compensating signals.
All 3 workflows were analyzed with no audit findings or untrusted checkouts, and one workflow has read-only permissions. However, all 7 action references are unpinned, so workflow supply-chain hygiene is weaker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ts-poet Version ^6.12.0 | — | — |
case-anything Version ^2.1.13 | — | — |
@bufbuild/protobuf Version ^2.14.1 | — | — |
ts-proto-descriptors Version 2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.