Spring Boot Developer Tools
88%
Total Score
healthy
Healthy overall; active Spring Boot maintenance supports this well-audited milestone release.
The repository name does not match this Maven module and its README does not mention the package, creating a small ownership-transparency concern. The package is clearly presented as a Spring Boot module, so this is not evidence of a standalone unrelated repository.
Version 4.2.0-M1 is a prerelease, and 30% of recent releases are prereleases. The package remains on a stable major line, but this milestone may contain changing APIs.
All 10 workflows were analyzed, all use read-only permissions, and only 3 of 28 action references are unpinned. However, the audit found 10 high-confidence template-injection findings, which are a workflow hygiene concern even without an untrusted trigger or script-injection sink.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10661 spring-boot-devtools is vulnerable to Observable Timing Discrepancy in versions 2.7.0 - 3.5.13 and 4.0.0 - 4.0.5. | 2.7.0 - 3.5.134.0.0 - 4.0.5 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework.boot:spring-boot Version 4.2.0-M1 | — | — |
org.springframework.boot:spring-boot-autoconfigure Version 4.2.0-M1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.