84%
Total Score
healthy
Healthy release from an active, well-backed project, with minor workflow and package-identity caveats.
The repository name does not match this platform package and its README does not mention the package, so the package-to-source relationship is less explicit than ideal. The monorepo context partly explains the name mismatch but not the absent mention.
The repository uses a build tool, but no security-scanning tools were detected. The missing scanning tooling is a modest transparency and assurance gap, not evidence of abandonment.
No repository security policy was found, leaving vulnerability-reporting expectations unclear despite the project’s strong maintenance activity.
All 25 workflows were analyzed and no untrusted checkout or script-injection sink was found, but several workflows use unpinned tool versions and the audit reports trusted-publishing concerns. Low-confidence cache findings are hygiene only.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.