The linked Kestra project shows exceptionally strong ongoing maintenance and organizational backing: 197 releases in the last 12 months, 1,451 commits from 100 active maintainers in three months, substantial issue and pull-request throughput, a non-archived repository, broad contributor distribution, security tooling, and build provenance. However, the published artifact's README identifies itself as MySQL Connector/J and refers to Oracle, despite the package being io.kestra:kestra and the linked repository matching Kestra; this is a serious release-transparency and artifact-integrity concern that materially reduces confidence in depending on this specific release. Workflow permission hygiene also has notable gaps, although the repository has a security policy and active project governance.
58%
Total Score
100
50
89
70
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-789992 New kestra is vulnerable to Remote Code Execution in versions 0.2.0 - 1.0.44 and 1.1.0 - 1.3.20. | 0.2.0 - 1.0.441.1.0 - 1.3.20 | Critical |
CVE-2026-55839 io.kestra:kestra is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.3.24. | 0.0.0 - 1.3.24 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
com.google.guava:guava Version * | — | — |
commons-io:commons-io Version * | — | — |
org.apache.commons:commons-lang3 Version * | — | — |
io.swagger.core.v3:swagger-annotations Version * | — | — |
com.google.code.findbugs:jsr305 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.