Dependency health Workspace

@pulumi/gcp-nativenpm

Vulnerabilities, end of life and next steps

Check a specific version for known advisories, documented mitigations and evidence-backed earlier-version options. Maintenance health is separate from vulnerability status.

Review remediation options →
What the project says about itself
  • Build provenance — the latest release carries no provenance attestation. Source: the registry.
  • Publishers on the registry — 2. Source: the registry.
  • Open milestones — 0.133 (due 2026-03-05); 0.134 (due 2026-03-20); 0.135 (due 2026-04-12); 0.136 (due 2026-04-27); 0.137 (due 2026-05-11). Source: the repository's milestones.
  • OpenSSF Scorecard — 4.9 / 10 on 2026-08-24. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.

Third-party facts checked 6 days ago; registry facts on every crawl.

State history 1
WhenChange
2026-09-19 first verdict: abandoned

Badge

maintenance: abandoned

Drop this in your README. It re-renders itself as the verdict changes.

[![maintenance](https://isitdeadyet.dev/badge/npm/@pulumi/gcp-native.svg)](https://isitdeadyet.dev/npm/@pulumi/gcp-native)

Watch it

Get told when @pulumi/gcp-native changes state, changes licence, or is deprecated — instead of finding out during an incident.

Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.