Package Health

ts-proto

[![npm](https://img.shields.io/npm/v/ts-proto)](https://www.npmjs.com/package/ts-proto) [![build](https://github.com/stephenh/ts-proto/workflows/Build/badge.svg)](https://github.com/stephenh/ts-proto/actions)

Latest 2.13.3NPMNPM

88%

Total Score

healthy

Active releases, recent repository work, and a healthy contributor base outweigh license metadata and workflow pinning gaps.

Health Score Breakdown

Licensecaution

The artifact and repository both contain license files, but the manifest declares ISC while the detected artifact license is Apache-2.0; the mismatch warrants clarification.

Lifecycle scriptscaution

The package has a prepare lifecycle script, which adds install-time behavior and deserves awareness, but this signal alone does not show harmful or unnecessary execution.

Repo toolingcaution

The project uses TypeScript and npm build tooling, but no security scanning tools were detected; this is a modest transparency gap rather than evidence of abandonment.

Security policycaution

No repository security policy was found, reducing guidance for reporting vulnerabilities, though active maintenance and provenance provide compensating signals.

Workflow auditcaution

All 3 workflows were analyzed with no audit findings or untrusted checkouts, and one workflow has read-only permissions. However, all 7 action references are unpinned, so workflow supply-chain hygiene is weaker.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
ts-poet
Version ^6.12.0
—
—
case-anything
Version ^2.1.13
—
—
@bufbuild/protobuf
Version ^2.14.1
—
—
ts-proto-descriptors
Version 2.1.0
—
—

Weekly Downloads

Info

Last Published
17 minutes ago
Created
7 years ago
Unpacked Size
0.8 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform