The prerelease label adds some version risk, and most workflow actions are unpinned. Signed Maven provenance, release notes, tests, and an organization-backed project improve confidence.
88%
Total Score
100
100
94
67
100
The repository has no published security policy, leaving reporting and response expectations less transparent. This is a moderate documentation gap rather than evidence of abandonment.
This release is a prerelease, so it may change before final stabilization. The recent prerelease share is only 25%, which limits but does not remove that concern.
All eight workflows were analyzed with no high- or medium-severity findings or untrusted sinks, but 25 of 26 action references are unpinned and two workflows grant top-level write access. These are workflow hygiene concerns, not a severe risk on their own.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-310773 sbt is vulnerable to Improper Authorization in versions 1.1.0 - 1.12.14 and 2.0.0 - 2.0.5. | 1.1.0 - 1.12.142.0.0 - 2.0.5 | Critical |
CVE-2026-32948 org.scala-sbt:sbt is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.9.5 - 1.12.7. | 0.9.5 - 1.12.7 | Medium |
CVE-2023-46122 org.scala-sbt:sbt is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.3.4 - 1.9.7. | 0.3.4 - 1.9.7 | Low |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.scala-sbt:main_3 Version 2.1.0-M3 | — | — |
org.scala-lang:scala3-library_3 Version 3.9.0 | — | — |
org.scala-sbt:io_3 Version 1.13.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.