Package Health

SharpYaml

It includes a substantial README, exact-version release notes, and a permissive MIT license. The single-contributor repository and unpinned workflow actions leave some operational risk.

Latest 3.14.0NuGetNuGet

81%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Are you affected? Scan for Free

Health Score Breakdown

Project backingcaution

The repository is owned by an individual rather than an organization, so the one-person publishing and commit profile is not buffered by visible organizational backing.

Repo bus factorcaution

All 15 recent commits came from one contributor, so maintenance depends heavily on a single person and has a meaningful continuity risk.

Repo toolingcaution

No build or security-scanning tools were detected in the repository. This is a transparency and assurance gap, though active releases and repository activity partly compensate for it.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations unclear; this is a moderate transparency gap rather than evidence of abandonment.

Workflow auditcaution

Both workflows were analyzed without failed files or audit findings, and one scopes permissions at job level. However, both action references are unpinned and one workflow grants top-level write access, creating workflow hygiene and token-scope concerns.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-918851
SharpYaml is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 2.1.4 and 3.0.0 - 3.3.0.
0.0.1 - 2.1.43.0.0 - 3.3.0
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
system.collections.immutable
Version [9.0.0, )
—
—
system.buffers
Version [4.6.1, )
—
—
system.text.json
Version [10.0.3, )
—
—

Weekly Downloads

Info

Last Published
15 days ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform