Utilities to help with endpoint resolution
91%
Total Score
healthy
Frequent releases and active, organization-backed maintenance make this a mature dependency with only minor transparency and workflow gaps.
No build attestation or trusted-publisher provenance was recorded, leaving publication origin less independently verifiable despite the package's active, organization-backed project.
The repository name does not match the package and its README does not mention it, which weakens direct package-to-repository traceability. The organization-backed monorepo context partly compensates for this mismatch.
The repository uses established build and test tooling, but no security-scanning tools were detected. This is a modest transparency gap rather than evidence of unsafe maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.6.2 | — | — |
@smithy/core Version ^3.35.2 | — | — |
@aws-sdk/core Version ^3.978.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.