Type-safe APIs with Protobuf and TypeScript.
92%
Total Score
90
100
100
80
100
One of nine workflows uses pull_request_target, which warrants review because that trigger can increase CI privilege risk. No untrusted checkouts or script-injection patterns were detected, substantially limiting the concern.
The top contributor made 80% of the 20 recent commits, creating concentration risk. However, four additional contributors were active and the repository is organization-owned, so this is a caution rather than a severe maintenance risk.
Seven workflows declare read-only permissions, but one workflow lacks top-level permissions and the publish workflow has top-level write access. This is a limited permissions-hygiene concern rather than a broad workflow failure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.