Utilities for building ESLint plugins.
91%
Total Score
100
100
90
90
100
The repository uses TypeScript and Vite build tooling, but no security-scanning tools were detected. The absence is a modest transparency and process gap, partially offset by the repository's security policy and controlled workflows.
All workflows declare top-level permissions, and four are read-only; three publishing or automation workflows have top-level write permissions, which is justified operationally but increases the impact of workflow compromise.
Version 0.7.3 is not a stable-major release, so API compatibility may still evolve; it is nevertheless a normal release rather than a prerelease, with no recent prerelease usage.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-21539 @eslint/plugin-kit is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.0.0 - 0.2.3. | 0.0.0 - 0.2.3 | Low |
| Dependency | Last Release | Score |
|---|---|---|
levn Version ^0.4.1 | — | — |
@eslint/core Version ^1.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.