Saves the code coverage collected during Cypress tests
68%
Total Score
caution
Usable with caveats: releases continue, but repository commit activity has stopped.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful maintenance warning even though a recent package release exists.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All seven analyzed action references are unpinned, and two high-confidence medium-severity findings expose inherited secrets; a separate workflow installs a package outside a lockfile. The pull_request_target trigger has no untrusted checkout or script-injection sink, so it is not independently severe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyc Version ^18.0.0 | — | — |
chalk Version 4.1.2 | — | — |
dayjs Version 1.11.20 | — | — |
debug Version 4.4.3 | — | — |
execa Version 4.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.