@vates/json-hashnpm
- latest 0.2.0
- licence ISC
- stars 988
- checked yesterday
- registry ↗
- repository ↗
Vulnerabilities, end of life and next steps
Check a specific version for known advisories, documented mitigations and evidence-backed earlier-version options. Maintenance health is separate from vulnerability status.
Review remediation options →Maintenance trends
Loading historical repository activity…
Signals · last 1 check
The first observation is recorded. Trend lines appear once at least two checks have data for the same signal.
Commits 90d
100
Open issues
289
Unanswered
103
Contributors
23
What the project says about itself
- Build provenance — the latest release carries no provenance attestation. Source: the registry.
- Supported runtime — node >=14.18.0. Source: the registry.
- Publishers on the registry — 15. Source: the registry.
- Security policy — published. Source: the repository.
- Open milestones — v6 51/181 done; backup 32/51 done; Pyrgos v1 (due 2024-06-28) 1/4 done; 2025 - Q1 (due 2025-03-31) 3/9 done; Somewhere in 2025 (due 2025-12-31) 5/29 done. Source: the repository's milestones.
- OpenSSF Scorecard — 5.1 / 10 on 2026-08-24. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.
Third-party facts checked yesterday; registry facts on every crawl.
State history 1
| When | Change |
|---|---|
| 2026-09-18 | first verdict: active |
Badge
Drop this in your README. It re-renders itself as the verdict changes.
[](https://isitdeadyet.dev/npm/@vates/json-hash)
Watch it
Get told when @vates/json-hash changes state, changes licence, or is deprecated — instead of finding out during an incident.
Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.