Protocol Buffers for ECMAScript. Fully compliant with the Protobuf conformance tests.
84%
Total Score
healthy
Healthy release with active maintenance and solid publishing evidence; workflow hygiene is the main caveat.
The repository has no security policy, leaving vulnerability reporting and response expectations less transparent than they could be; active maintenance partly reduces the concern but does not remove it.
All eight workflows were analyzed, with no untrusted checkout or script-injection sinks. However, all 38 action references are unpinned and three workflows inherit secrets, creating a meaningful workflow-hygiene caution; the low-confidence cache findings are only minor hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-709877 New @bufbuild/protobuf is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 2.12.1. | 0.0.1 - 2.12.1 | Medium |
AIKIDO-2026-639460 New @bufbuild/protobuf is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 2.12.0. | 0.0.1 - 2.12.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.