Package Health

conduction/hydra-gates

This release shows strong operational activity and reasonable baseline hygiene: it is not deprecated, has a stable major version, a license, tests, a changelog, no install-time lifecycle scripts, active organizational backing, substantial recent commit activity, security tooling, and a security policy. However, the package is only 37 days old, its linked repository is the organization-wide `.github` repository rather than a package-specific repository and does not mention `hydra-gates`, which creates a meaningful transparency and provenance concern. Workflow script-injection findings and incomplete or broad GitHub Actions token-permission declarations add security-maintenance caution, while the high concentration of commits in one contributor modestly increases continuity risk despite the organization and other active contributors. It is usable, but I would verify the package-to-source relationship and CI release controls before making it a critical dependency.

Latest v1.18.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo package mentiondanger

The linked repository name does not match the package and its README does not mention `hydra-gates`, so the source relationship is not transparently established and the package may be using an unrelated organization repository.

Dangerous workflowscaution

All 21 workflows were analyzed with no pull-request-target or untrusted-checkout findings, but two workflows contain script-injection patterns, creating a concrete CI security-hygiene concern.

Release historycaution

Thirty releases in the first 37 days indicates active publishing, but the very short history and median interval of about 10 hours leave limited evidence of long-term maturity.

Repo issue activitycaution

The repository is highly active, with 70 new issues, 30 closed issues, 4 new pull requests, and 302 merged pull requests in one month; the open-issue imbalance warrants some caution about backlog management.

Token permissionscaution

Nine workflows use job-level permissions only, ten lack top-level permissions declarations, and two declare top-level write access; although nine workflows are read-only, the inconsistent and sometimes broad permission posture merits caution.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Conduction

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
25 days ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform