The release has signed provenance, a licensed source tree, tests, release notes, and broad recent contributor activity. Most workflow references are unpinned, and the repository does not clearly identify this artifact in its README, so verify the publication mapping before standardizing on it.
88%
Total Score
100
100
88
50
100
The repository name does not match this artifact and its README does not mention the package, so the exact publication mapping is not explicit even though the organization-backed monorepo context is plausible.
The repository has no security policy, leaving vulnerability-reporting and response expectations less transparent.
This is a prerelease milestone, and half of recent releases are prereleases, which adds some compatibility risk despite the stable major line.
All eight workflows were analyzed without high-confidence findings or untrusted checkouts, but 25 of 26 action references are unpinned and two workflows grant top-level write permissions, creating avoidable workflow hygiene and update risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-824110 main_3 is vulnerable to Remote Code Execution in versions 2.0.0 - 2.0.5. | 2.0.0 - 2.0.5 | Critical |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.scala-sbt:actions_3 Version 2.1.0-M3 | — | — |
org.scala-sbt:build-file_3 Version 2.1.0-M3 | — | — |
org.scala-sbt:main-settings_3 Version 2.1.0-M3 | — | — |
org.scala-sbt:run_3 Version 2.1.0-M3 | — | — |
org.scala-sbt:command_3 Version 2.1.0-M3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.