Package Health

k2gl/slsa-provenance

This is a young but actively maintained and transparently structured release: it has six releases over 96 days, a stable 1.3.1 version, a non-deprecated registry status, a matching source repository, repository tests and releases, security documentation, and no install-time lifecycle scripts. The main concerns are that all 20 recent commits came from one contributor, repository popularity is currently negligible, and workflow permissions are not uniformly least-privilege; these warrant monitoring but do not by themselves make the package unfit to depend on.

Latest 1.3.1PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dangerous workflowscaution

One of three workflows uses pull_request_target, which requires careful review because it can run with elevated repository context; no untrusted checkout or script-injection findings were detected.

Project backingcaution

The repository is owned by a user account rather than an organization, so the concentrated contributor activity is not offset by visible organizational maintenance backing.

Repo bus factorcaution

One contributor made all 20 commits in the last three months, creating a material single-maintainer continuity risk for a user-owned repository.

Repo popularitycaution

The repository has zero stars and forks and only one watcher; this is weak supporting evidence for adoption and community visibility, though the package is still young.

Token permissionscaution

One workflow has top-level write permissions and another lacks top-level permissions, so workflow authorization is not uniformly explicit or least-privilege.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nick Harin

Direct Dependencies

DependencyLast ReleaseScore
k2gl/in-toto-attestation
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
22 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform