The release is clearly licensed and includes Maven provenance, while its compiled artifact is appropriately backed by repository tests and release notes. Workflow template-injection findings and the repository’s lack of an explicit package mention warrant extra CI and source-mapping scrutiny.
86%
Total Score
100
100
81
100
100
The repository name does not match the package and its README does not mention the package, creating some uncertainty about package-to-source mapping; the monorepo structure partly explains the name mismatch but not the absent mention.
The project uses Gradle, but no security-scanning tools were detected; the missing scanning evidence is a minor transparency gap for a major framework.
This is a milestone prerelease, but the package has a stable major line and only 15% recent prereleases, so the version status is a moderate rather than severe concern.
All 14 workflows were analyzed without untrusted checkouts or script-injection findings, and most use read-only or job-level permissions. Six of 24 action references are unpinned, and high-confidence template-injection findings are present; without a dangerous trigger or sink, these are workflow hygiene concerns rather than severe dependency risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-22233 org.springframework:spring-context is vulnerable to Improper Input Validation in versions 6.2.0 - 6.2.6, 6.1.0 - 6.1.19, 6.0.0 - 6.0.23 and 0.0.0 - 5.3.39. | 0.0.0 - 5.3.396.0.0 - 6.0.236.1.0 - 6.1.19 +1 more | Low |
AIKIDO-2024-10363 spring-context is vulnerable to Improper Handling of Case Sensitivity in versions 0.0.1 - 5.3.40, 6.0.0 - 6.0.24 and 6.1.0 - 6.1.13. | 0.0.1 - 5.3.406.0.0 - 6.0.246.1.0 - 6.1.13 | Low |
CVE-2022-22968 org.springframework:spring-context is vulnerable to Improper Handling of Case Sensitivity in versions 5.3.0 - 5.3.19 and 0.0.0 - 5.2.21.RELEASE. | 0.0.0 - 5.2.21.RELEASE5.3.0 - 5.3.19 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework:spring-aop Version 7.1.0-M1 | — | — |
org.springframework:spring-beans Version 7.1.0-M1 | — | — |
org.springframework:spring-core Version 7.1.0-M1 | — | — |
org.springframework:spring-expression Version 7.1.0-M1 | — | — |
io.micrometer:micrometer-observation Version 1.18.0-M1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.