Package Health

keboola/job-queue-artifacts

The MIT license, tests, release notes, and matching organization-owned repository improve transparency. A security policy is absent, while recent activity remains sparse and concentrated in one contributor, so ongoing maintenance deserves attention.

Latest 4.1.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs a pre-autoload-dump install-time script, which adds execution during dependency installation and warrants more scrutiny than a package without lifecycle scripts.

Release historycaution

The package has only 3 releases over about 1 year, with 1 release in the past 12 months and a typical interval of about 5 months. This indicates a modest maintenance cadence rather than an abandoned package.

Repo bus factorcaution

All recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown to reduce the immediate concentration risk.

Repo commit activitycaution

The repository had 1 commit in the past 3 months, showing recent activity but limited ongoing development evidence.

Security policycaution

The repository has no documented security policy, leaving vulnerability reporting and response expectations less transparent.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Keboola

Direct Dependencies

DependencyLast ReleaseScore
symfony/finder
Version ^6.2|^7.0
—
—
symfony/filesystem
Version ^6.2|^7.0
—
—
keboola/storage-api-client
Version ^15.1|^16.0|^17.0|^18.0
—
—
keboola/job-queue-job-configuration
Version ^3.0.0|*@dev
—
—
keboola/storage-api-php-client-branch-wrapper
Version ^7.0
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform