{"_id":"@barissozudogru/dep-health","_rev":"3-f5e0a62ddfceb17712c8fc508e965d3b","name":"@barissozudogru/dep-health","dist-tags":{"latest":"0.5.1"},"versions":{"0.4.0":{"name":"@barissozudogru/dep-health","version":"0.4.0","keywords":["npm","dependencies","health","audit","maintenance","cli"],"author":{"name":"Baris Sozudogru"},"license":"MIT","_id":"@barissozudogru/dep-health@0.4.0","maintainers":[{"name":"barissozudogru","email":"barissozudogru@gmail.com"}],"homepage":"https://github.com/barissozudogru/dep-health#readme","bugs":{"url":"https://github.com/barissozudogru/dep-health/issues"},"bin":{"dep-health":"dist/cli.js"},"dist":{"shasum":"1b6eeb32b8b33bc16fdabe3e61c8d0b6363bf644","tarball":"https://registry.npmjs.org/@barissozudogru/dep-health/-/dep-health-0.4.0.tgz","fileCount":9,"integrity":"sha512-ljQ351fbIzvbZTmVwPnFd9eKqikfZ0321OrgHHBB85ptllH3XXrLURel284xliu3Tu1v+RDv639EwWD+8mY6lA==","signatures":[{"sig":"MEYCIQCAbQqg35YPESPv7prtQ+Chm4ej7lSdj0lFh0r5tQyIUQIhALoGrEwYdFFTO57VA3XMYGJPrj6jRlbvwmIxYLag/WEw","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34815},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"afecf0c07cc286a60e0d6f1af7b93c0a1725298e","scripts":{"test":"npm run build && node --test test/*.test.js","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"barissozudogru","email":"barissozudogru@gmail.com"},"repository":{"url":"git+https://github.com/barissozudogru/dep-health.git","type":"git"},"_npmVersion":"11.6.2","description":"Health score for npm dependencies combining freshness, security, and maintenance","directories":{},"_nodeVersion":"25.2.1","publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3","@types/node":"^22.19.15"},"_npmOperationalInternal":{"tmp":"tmp/dep-health_0.4.0_1787176160731_0.5956494035651616","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@barissozudogru/dep-health","version":"0.5.0","keywords":["npm","dependencies","health","maintenance","package-health","dependency-management","ci","cli"],"author":{"name":"Baris Sozudogru"},"license":"MIT","_id":"@barissozudogru/dep-health@0.5.0","maintainers":[{"name":"barissozudogru","email":"barissozudogru@gmail.com"}],"homepage":"https://petri-labs.org/tools/dep-health/","bugs":{"url":"https://github.com/barissozudogru/dep-health/issues"},"bin":{"dep-health":"dist/cli.js"},"dist":{"shasum":"d740871cabb851040e5966f3b4d2af8ba5847224","tarball":"https://registry.npmjs.org/@barissozudogru/dep-health/-/dep-health-0.5.0.tgz","fileCount":9,"integrity":"sha512-2Tfph8nlEjX142ry/UY6cuHBH3kKgMwL8S0N6yFD2jZh+oUyydLnJgjF29/8pDHIeA47HGHCtIkxR9UiLyZO/w==","signatures":[{"sig":"MEYCIQClhZtXWinmxF/lJqBQYa4zvUsoDLBNK9BaWlg4PY4YrgIhAOg+CLDhAaaDRKwFYnWt8w3m2EYSC4SIHztN7ECeX8KQ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":35723},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"94ee38ecee36675aaefaca0aaa5da9506156833a","scripts":{"test":"npm run build && node --test test/*.test.js","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"barissozudogru","email":"barissozudogru@gmail.com"},"repository":{"url":"git+https://github.com/barissozudogru/dep-health.git","type":"git"},"_npmVersion":"11.6.2","description":"Score npm dependency health using freshness, recency, deprecation, and adoption signals","directories":{},"_nodeVersion":"25.2.1","publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3","@types/node":"^22.19.15"},"_npmOperationalInternal":{"tmp":"tmp/dep-health_0.5.0_1787699110399_0.6757355040364867","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"@barissozudogru/dep-health","version":"0.5.1","description":"Score npm dependency health using freshness, recency, deprecation, and adoption signals","bin":{"dep-health":"dist/cli.js"},"main":"dist/index.js","types":"dist/index.d.ts","type":"module","scripts":{"build":"tsc","prepublishOnly":"npm run build","test":"npm run build && node --test test/*.test.js"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"repository":{"type":"git","url":"git+https://github.com/barissozudogru/dep-health.git"},"homepage":"https://petri-labs.org/tools/dep-health/","bugs":{"url":"https://github.com/barissozudogru/dep-health/issues"},"keywords":["npm","dependencies","health","maintenance","package-health","dependency-management","ci","cli"],"author":{"name":"Baris Sozudogru"},"license":"MIT","engines":{"node":">=18.0.0"},"devDependencies":{"@types/node":"^22.19.15","typescript":"^5.9.3"},"gitHead":"aa268cffd2ff4b9e75d077c54bb5c1eaf629efb8","_id":"@barissozudogru/dep-health@0.5.1","_nodeVersion":"25.2.1","_npmVersion":"11.6.2","dist":{"integrity":"sha512-+SvCV4Vi6VaEsRTfQuCAzbIpDTCinnq3Zolt8nsOvX3b+pBkWT6ZfHrOy//qFbfsY/SQabnpI6T/WFrm6jjm6g==","shasum":"71b2cfc9069c75c0675bf822c79557979c0e1fa9","tarball":"https://registry.npmjs.org/@barissozudogru/dep-health/-/dep-health-0.5.1.tgz","fileCount":9,"unpackedSize":35796,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCi0mv037rwM8yXKGth5mdnKv0z7vBl4aDtWi9VeX5JPAIhAM99y3IdjkIcaq/h7dGw0NX6KRGJQGvHa6Rh1af+nt5N"}]},"_npmUser":{"name":"barissozudogru","email":"barissozudogru@gmail.com"},"directories":{},"maintainers":[{"name":"barissozudogru","email":"barissozudogru@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dep-health_0.5.1_1787745749215_0.5369638145101572"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-19T21:49:20.512Z","modified":"2026-08-26T12:02:29.874Z","0.4.0":"2026-08-19T21:49:20.887Z","0.5.0":"2026-08-25T23:05:10.545Z","0.5.1":"2026-08-26T12:02:29.363Z"},"bugs":{"url":"https://github.com/barissozudogru/dep-health/issues"},"author":{"name":"Baris Sozudogru"},"license":"MIT","homepage":"https://petri-labs.org/tools/dep-health/","keywords":["npm","dependencies","health","maintenance","package-health","dependency-management","ci","cli"],"repository":{"type":"git","url":"git+https://github.com/barissozudogru/dep-health.git"},"description":"Score npm dependency health using freshness, recency, deprecation, and adoption signals","maintainers":[{"name":"barissozudogru","email":"barissozudogru@gmail.com"}],"readme":"<p align=\"center\">\n  <img src=\"./assets/social-preview.svg\" alt=\"dep-health\" width=\"900\" />\n</p>\n\n<p align=\"center\">\n  <a href=\"https://www.npmjs.com/package/@barissozudogru/dep-health\"><img alt=\"npm version\" src=\"https://img.shields.io/npm/v/@barissozudogru/dep-health?style=flat-square&color=8D88E8\"></a>\n  <a href=\"https://www.npmjs.com/package/@barissozudogru/dep-health\"><img alt=\"npm downloads\" src=\"https://img.shields.io/npm/dm/@barissozudogru/dep-health?style=flat-square&color=8D88E8\"></a>\n  <a href=\"https://github.com/barissozudogru/dep-health/actions/workflows/ci.yml\"><img alt=\"CI\" src=\"https://github.com/barissozudogru/dep-health/actions/workflows/ci.yml/badge.svg\"></a>\n  <a href=\"./LICENSE\"><img alt=\"MIT license\" src=\"https://img.shields.io/badge/License-MIT-8D88E8?style=flat-square\"></a>\n</p>\n\n# dep-health\n\nHealth score for every npm dependency in a project. Queries the npm registry for each dependency in `package.json` and calculates a score from 0 to 10 based on version freshness, publish recency, deprecation status, and popularity. Zero runtime dependencies.\n\nThis is a maintenance review aid, not a vulnerability or CVE scanner. A low score is a prompt to investigate, not an automatic removal decision.\n\n[Tool page](https://petri-labs.org/tools/dep-health/) · [npm](https://www.npmjs.com/package/@barissozudogru/dep-health) · [Source](https://github.com/barissozudogru/dep-health)\n\n```bash\nnpx @barissozudogru/dep-health\n```\n\n## Usage\n\n```bash\n# Analyze current directory\ndep-health\n\n# Analyze a specific project\ndep-health --path ./my-project\n\n# Filter by dependency type\ndep-health --prod-only\ndep-health --dev-only\n\n# JSON output\ndep-health --json > report.json\n\n# Fail CI if any dependency scores below threshold\ndep-health --min-score 5\n```\n\n## Options\n\n| Flag | Description | Default |\n|---|---|---|\n| `--path <dir>` | Directory containing `package.json` | Current working directory |\n| `--json` | Output results as JSON instead of formatted text | Off |\n| `--min-score <n>` | Exit with code `1` if any dependency scores below `n` | Off |\n| `--prod-only` | Analyze only `dependencies` (skip `devDependencies`) | Off |\n| `--dev-only` | Analyze only `devDependencies` (skip `dependencies`) | Off |\n| `-v, --version` | Print version and exit | - |\n| `-h, --help` | Show help message | - |\n\n`--prod-only` and `--dev-only` are mutually exclusive.\n\n## Scoring Breakdown\n\nEach dependency receives a weighted score out of 10:\n\n| Signal | Weight | Detail |\n|---|---|---|\n| Freshness | 30% | Major versions behind: -3 each. Minor: -1 each. Patch: -0.5 each. |\n| Recency | 30% | Last publish < 6 months: 10. < 1 year: 7. < 2 years: 4. Older: 1. |\n| Deprecation | 20% | Deprecated: 0. Not deprecated: 10. |\n| Popularity | 20% | TypeScript types present: +2. Weekly downloads: tiered 0 to 8. When the download count is unavailable this signal is dropped and the remaining weights are renormalised, rather than scored as zero. |\n\nDownload tiers (popularity sub-score):\n\n| Weekly downloads | Score contribution |\n|---|---|\n| >= 1,000,000 | +8 |\n| >= 100,000 | +7 |\n| >= 10,000 | +5 |\n| >= 1,000 | +3 |\n| >= 100 | +1 |\n| < 100 | 0 |\n\n## Verified output\n\nThe current release was run against this repository's real `package.json` on 2026-08-26:\n\n```text\nHEALTHY (2)\n\n  @types/node  [dev] [TS]\n  7.0/10\n  freshness:0.0  recency:10.0  deprecation:10.0  popularity:10.0\n\n  typescript  [dev]\n  7.8/10\n  freshness:4.0  recency:10.0  deprecation:10.0  popularity:n/a\n\nOverall project score: 7.4 / 10 (HEALTHY)\n2 packages analyzed\n```\n\nRegistry data changes over time, so repeated runs can legitimately differ. Unknown download data is excluded from the weighted score instead of being treated as zero.\n\nIf this saves you time, consider [starring the repository](https://github.com/barissozudogru/dep-health). It helps other developers find it.\n\n## CI Integration\n\nUse the reusable action to write the evidence to the workflow summary and enforce a threshold:\n\n```yaml\nname: Dependency health\n\non: [pull_request]\n\njobs:\n  dep-health:\n    runs-on: ubuntu-latest\n    permissions:\n      contents: read\n    steps:\n      - uses: actions/checkout@v4\n      - uses: barissozudogru/dep-health@v0.5.1\n        with:\n          path: .\n          min-score: \"4\"\n```\n\nAdd a step to your CI pipeline to enforce a minimum health score:\n\n```yaml\n- name: Check dependency health\n  run: npx @barissozudogru/dep-health --min-score 4\n```\n\nWith JSON output for artifact upload:\n\n```yaml\n- name: Dependency health report\n  run: npx @barissozudogru/dep-health --json > dep-health-report.json\n\n- name: Enforce health gate\n  run: npx @barissozudogru/dep-health --min-score 4\n```\n\n## Exit Codes\n\n| Code | Meaning |\n|---|---|\n| `0` | Analysis complete. All dependencies at or above `--min-score` (or no gate set). |\n| `1` | One or more dependencies scored below `--min-score`, or a fatal error occurred. |\n\n## Requirements\n\n- Node.js >= 18.0.0\n\n## License\n\n[MIT](LICENSE)\n","readmeFilename":"README.md"}