Cloud executable protocol
88%
Total Score
healthy
Frequent releases, active contributors, and strong project backing outweigh incomplete workflow analysis and unpinned actions.
No build attestation or trusted-publisher provenance is present, leaving publication origin less transparent, though the package has substantial independent maintenance evidence.
The repository name does not match the package and its README does not mention the package, creating some uncertainty about package-to-repository mapping; the monorepo context partly compensates for the name mismatch.
The audit analyzed 30 of 48 workflows, found one untrusted checkout, and reported all 72 action references unpinned. Its four cache-poisoning findings have low confidence, so they are workflow-hygiene concerns rather than severe evidence on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
semver Version ^7.8.5 | — | — |
@aws-cdk/cloud-assembly-api Version ^2.2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.