The artifact is lean and has no install-time scripts, with signed Maven provenance and a focused runtime dependency set. Its workflow audit found only template-injection hygiene findings and three unpinned actions, without untrusted checkout or script-injection paths.
92%
Total Score
100
100
100
100
100
All 10 workflows were analyzed, all use read-only permissions, and there are no untrusted checkouts or script-injection findings. Ten high-confidence template-injection findings and three of 28 unpinned actions are workflow hygiene concerns, but no trigger-and-sink combination was shown.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10660 spring-boot is vulnerable to Insecure Temporary File in versions 2.7.0 - 3.5.13 and 4.0.0 - 4.0.5. | 2.7.0 - 3.5.134.0.0 - 4.0.5 | High |
CVE-2026-40976 org.springframework.boot:spring-boot is vulnerable to Missing Authorization in versions 4.0.0 - 4.0.6. | 4.0.0 - 4.0.6 | Critical |
AIKIDO-2026-10583 spring-boot is vulnerable to Insecure Randomness in versions 2.7.0 - 3.5.13 and 4.0.0 - 4.0.5. | 2.7.0 - 3.5.134.0.0 - 4.0.5 | Medium |
AIKIDO-2026-10581 spring-boot is vulnerable to Insecure Temporary File in versions 2.7.0 - 3.5.13 and 4.0.0 - 4.0.5. | 2.7.0 - 3.5.134.0.0 - 4.0.5 | Medium |
CVE-2025-22235 org.springframework.boot:spring-boot is vulnerable to Improper Input Validation in versions 0.0.0 - 2.7.24.2, 3.1.0 - 3.1.15.2, 3.2.0 - 3.2.13.2, 3.3.0 - 3.3.10 and 3.4.0 - 3.4.4. | 0.0.0 - 2.7.24.23.1.0 - 3.1.15.23.2.0 - 3.2.13.2 +2 more | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework:spring-core Version 7.1.0-M1 | — | — |
org.springframework:spring-context Version 7.1.0-M1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.