Shared types for commitlint packages
91%
Total Score
100
100
94
67
The project uses TypeScript, Vitest, and build tooling, but no security-scanning tools were detected, leaving a modest security-process gap.
No repository security policy was found, reducing transparency about vulnerability reporting and response expectations.
All five workflows were analyzed without untrusted checkouts or script injection, but 20 of 25 action references are unpinned and a high-confidence finding reports an ad hoc package installation; one workflow also grants top-level write access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
picocolors Version ^1.1.1 | — | — |
conventional-commits-parser Version ^7.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.