Parse and format xcodebuild logs
86%
Total Score
healthy
Healthy—frequent releases and a very active, well-backed repository outweigh limited workflow-audit concerns.
The package is backed by an organization, but publish access includes outside-domain accounts such as ide (jameside.com), bycedric (bycedric.com), tsapeta (tsapeta.com), and philpl (kitten.sh), creating account-hygiene risk despite the clear expo.io domain.
The linked repository name does not match the package and its README does not mention @expo/xcpretty. This is a caution because the package-to-repository connection is not explicit, although the organization-backed monorepo context partly explains the mismatch.
The audit covered only 30 of 54 workflows and found 18 high-confidence template-injection findings, plus high-confidence ad hoc package installs; low-confidence cache findings are hygiene only. No untrusted checkout or script-injection sink was found, but incomplete coverage warrants caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
chalk Version ^4.1.0 | — | — |
js-yaml Version ^4.1.0 | — | — |
@babel/code-frame Version ^7.20.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.