{"package":"vega-interpreter","ecosystem":"npm","latest_version":"2.2.1","description":"CSP-compliant interpreter for Vega expressions.","license":"BSD-3-Clause","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://github.com/vega/vega#readme","repository":"https://github.com/vega/vega","downloads_weekly":365787,"health":{"score":61,"risk":"moderate","breakdown":{"maintenance":10,"popularity":14,"security":20,"maturity":12,"community":5},"deprecated":false,"max_score":100},"vulnerabilities":{"count":1,"critical":0,"high":1,"medium":0,"low":0,"details":[{"vuln_id":"CVE-2025-59840","severity":"high","summary":"Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global variable","affected_versions":"<6.2.0|>=6.0.0,<6.1.0|>=2.0.0,<2.2.1|<1.2.1|<5.2.1","fixed_version":"5.2.1","source":"osv","published_at":"2025-11-13T22:32:35Z","in_kev":false,"epss_prob":0.00034,"epss_percentile":0.09728,"threat_tier":"theoretical"}],"actively_exploited_count":0,"likely_exploited_count":0},"versions":{"latest":"2.2.1","total_count":13,"recent":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.1.0","1.2.0","2.0.0","2.1.0","2.2.0","2.2.1","1.2.1"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":5,"first_published":"2020-06-02T09:52:17.309Z","last_published":"2025-09-24T19:59:28.259Z","dependencies_count":1,"dependencies":["vega-util"]},"github_stats":null,"bundle":{"size_kb":6.0,"gzip_kb":2.5,"dependency_count":1,"has_js_module":false,"has_side_effects":true,"scoped":false,"source":"bundlephobia"},"typescript":{"score":10,"has_types":true,"types_source":"bundled","types_package":null},"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"update_required","issues":["1 high severity vulnerabilities"],"use_version":"2.2.1","version_hint":"Update to >= 5.2.1 to fix known vulnerabilities","summary":"vega-interpreter@2.2.1 has vulnerabilities — update to latest"},"version_scoped":null,"requested_version":null,"_cache":"miss","_response_ms":981,"_powered_by":"depscope.dev — free package intelligence for AI agents","typosquat":{"is_suspected":false},"maintainer_trust":{"available":false},"malicious":{"is_malicious":false},"scorecard":{"available":false},"quality":{"available":false},"version_history_summary":{"total_versions":13,"first_release_age_days":2157,"last_release_days_ago":217,"avg_days_between_releases":180,"release_velocity":"moderate"}}