Package Health

grafana/foundation-sdk

This release appears suitable to depend on, with strong transparency and active project backing: it is Apache-2.0 licensed, has a substantial source tree, regular releases, recent repository activity, security tooling, a security policy, and no deprecation or archive status. The main reservations are that the package is still on an unstable 0.x major version, recent commits are highly concentrated in one of two contributors, and three release workflows lack top-level token permissions while one has top-level write access. These are meaningful maintenance and release-hygiene concerns, but they are mitigated by Grafana organization ownership, a second active contributor, ongoing merged pull requests, and the absence of detected dangerous workflow patterns.

Latest v0.0.20PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 days ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform