Dependency health Workspace

cache-managernpm

Documented supply-chain history

This package has dated incident reports relevant to its trust history. Check the affected releases and the response before drawing conclusions about its current version.

Read the incident coverage →

Supply-chain news and reputation

Dated reporting about this package. These events are separate from its current maintenance score.

All supply-chain news →
What the project says about itself
  • Build provenance — the latest release, 7.2.9, carries a signed provenance attestation. Source: the registry.
  • Publishers on the registry — 1. Source: the registry.
  • Security policypublished. Source: the repository.

Third-party facts checked today; registry facts on every crawl.

State history 1
WhenChange
2026-09-05 first verdict: active
Supply-chain history 1
  1. account hijacked 2026-08 7.2.10

    The maintainer’s GitHub account was compromised and malicious commits to main triggered releases, with valid provenance, whose pre-install step stole npm, GitHub, cloud and Vault secrets and republished every package the stolen tokens could reach.

    Commits deleted and versions removed; the worm reached over 2,200 versions across 444 packages.

    Source: Aikido, Datadog Security Labs and Sonatype analyses, 4–5 August 2026. History, not a warning about today — the verdict above is about maintenance now.

Badge

maintenance: active

Drop this in your README. It re-renders itself as the verdict changes.

[![maintenance](https://isitdeadyet.dev/badge/npm/cache-manager.svg)](https://isitdeadyet.dev/npm/cache-manager)

Watch it

Get told when cache-manager changes state, changes licence, or is deprecated — instead of finding out during an incident.

Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.