Package Health

pdsinterop/solid-auth

OAuth2, OpenID and OIDC for Solid Server implementations.

Latest v0.15.0PackagistPackagist

63%

Total Score

caution

Active releases and organization backing are offset by one active contributor and high-confidence workflow pinning and permission gaps.

Health Score Breakdown

Repo bus factorcaution

Only one contributor made commits in the last 3 months, accounting for 100% of the 7 commits; organization backing provides some handoff capacity, but no second active contributor is shown.

Security policycaution

The repository has no published security policy, leaving reporting and response expectations unclear for an authentication-focused library.

Version stabilitycaution

Version v0.15.0 is not a stable major release, so its pre-1.0 status implies less API stability, although it is not marked as a prerelease.

Workflow auditcaution

All 11 action references are unpinned, all four workflows grant top-level write permissions, and the audit found five high-confidence unpinned container-image findings. No untrusted checkout or script-injection sink was detected, but the workflow supply-chain and token hygiene remain significant concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
lcobucci/jwt
Version ^4.1
—
—
web-token/jwt-core
Version ^2.2
—
—
league/oauth2-server
Version ^8.5.5
—
—
laminas/laminas-diactoros
Version ^3.8
—
—

Weekly Downloads

Info

Last Published
4 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform