Package Health

k2gl/sigstore-bundle

Build Sigstore bundles (.sigstore.json) in PHP — the counterpart to verification, emitting DSSE and message-signature bundles.

Latest 1.0.1PackagistPackagist

67%

Total Score

caution

Usable with caveats: one maintainer and a high-confidence workflow check weaken an otherwise recent, documented release.

Health Score Breakdown

Project backingcaution

The repository is owned by a user account rather than an organization, so the single-contributor concentration has no shown organizational handoff to compensate for it.

Release historycaution

The package is only 79 days old and has two releases, both within the last 12 months; the short history limits evidence of long-term maintenance, although the releases were closely spaced.

Repo bus factorcaution

All 10 recent commits came from one contributor, leaving maintenance dependent on a single active person and increasing continuity risk.

Workflow auditcaution

The audit covered all three workflows and found no untrusted checkout or script-injection paths, but it reported a high-confidence bot-conditions issue and two of five unpinned action references. The pull_request_target workflow also has top-level write permissions, so the automation should be tightened.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nick Harin

Direct Dependencies

DependencyLast ReleaseScore
k2gl/dsse
Version ^1.3
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform