Package Health

yargs-parser

the mighty option parser used by yargs

Latest 22.0.0NPMNPM

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

85

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

A prepare install lifecycle script adds some installation complexity and supply-chain exposure, but the available workflow analysis shows no dangerous workflow patterns to compound that concern.

Release historycaution

This is a mature package with 84 releases over more than 10 years, but it has had no registry release in about 16 months despite earlier releases roughly every 10 days, so current release cadence is a modest concern.

Repo toolingcaution

The repository uses TypeScript, npm scripts, and Babel for builds, but no security-scanning tools were detected, leaving a modest process gap.

Token permissionscaution

Neither workflow declares top-level token permissions, so the repository does not clearly document least-privilege automation access; no workflow was observed with explicit top-level write permissions.

Type declarationscaution

No type declarations are published, which is a usability gap for TypeScript consumers of this library; the package otherwise includes source type definitions in its repository but does not ship declarations.

Vulnerabilities

TitleVersionsSeverity
CVE-2020-7608
yargs-parser is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in versions 6.0.0 - 13.1.2, 14.0.0 - 15.0.1, 0.0.0 - 5.0.0 and 16.0.0 - 18.1.1.
0.0.0 - 5.0.06.0.0 - 13.1.214.0.0 - 15.0.1 +1 more
Medium

Package versions

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 year ago
Created
10 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform