Dependency health Workspace

@vates/json-hashnpm

Vulnerabilities, end of life and next steps

Check a specific version for known advisories, documented mitigations and evidence-backed earlier-version options. Maintenance health is separate from vulnerability status.

Review remediation options →
What the project says about itself
  • Build provenance — the latest release carries no provenance attestation. Source: the registry.
  • Supported runtimenode >=14.18.0. Source: the registry.
  • Publishers on the registry — 15. Source: the registry.
  • Security policypublished. Source: the repository.
  • Open milestonesv6 51/181 done; backup 32/51 done; Pyrgos v1 (due 2024-06-28) 1/4 done; 2025 - Q1 (due 2025-03-31) 3/9 done; Somewhere in 2025 (due 2025-12-31) 5/29 done. Source: the repository's milestones.
  • OpenSSF Scorecard5.1 / 10 on 2026-08-24. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.

Third-party facts checked yesterday; registry facts on every crawl.

State history 1
WhenChange
2026-09-18 first verdict: active

Badge

maintenance: active

Drop this in your README. It re-renders itself as the verdict changes.

[![maintenance](https://isitdeadyet.dev/badge/npm/@vates/json-hash.svg)](https://isitdeadyet.dev/npm/@vates/json-hash)

Watch it

Get told when @vates/json-hash changes state, changes licence, or is deprecated — instead of finding out during an incident.

Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.