This release appears highly suitable to depend on: it has a long and active release history, a stable current major version, a non-deprecated registry entry, a linked non-archived organization-owned repository, substantial recent commit and pull-request activity, and a healthy contributor distribution. The package is licensed, typed, tested, structured transparently, and has no install-time lifecycle scripts. Build provenance is not attested, which is a modest supply-chain transparency gap, but repository security controls and read-only workflow permissions provide meaningful compensating evidence.
96%
Total Score
100
100
100
90
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-808258 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @angular/cli is vulnerable to Path Traversal in versions 21.0.0 - 22.1.4. | 21.0.0 - 22.1.4 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
zod Version 4.4.3 | — | — |
yargs Version 18.1.0 | — | — |
listr2 Version 11.0.0 | — | — |
semver Version 7.8.5 | — | — |
jsonc-parser Version 3.3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.