Library to help resolve module locations.
82%
Total Score
healthy
Healthy, with a high-confidence workflow permission finding as the main caveat.
One contributor made about 87% of recent commits, which concentrates operational knowledge. However, the repository is organization-owned and eight other contributors were active, partly compensating for that concentration.
The repository name differs from the package name and its README does not mention this package, creating some uncertainty about the package-to-repository linkage. The package is scoped under the same project family, so this is a caution rather than a severe concern.
The audit found a high-confidence github-app issue where an app token inherits blanket installation permissions, and only 30 of 37 workflows were analyzed. The pull_request_target triggers had no reported untrusted checkout or script-injection sinks, but the credential scope remains a real hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
global-directory Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.