Bundled typings and a clear README make integration straightforward. The repository remains active with three recent contributors, though workflow actions are unpinned and no build attestation is present.
86%
Total Score
100
100
95
83
50
No build attestation or trusted-publisher provenance was reported, reducing release transparency. This is partly offset by the active organization-owned repository and recent release notes, so it is a minor caution.
TypeScript and Gulp build tooling are present, but no security-scanning tools were detected. The repository’s security policy provides some transparency, so this is a minor hygiene gap rather than a severe concern.
The single analyzed workflow has read-only permissions, no untrusted checkout or script-injection findings, and no audit failures. All 8 action references are unpinned, which leaves a modest supply-chain hygiene gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-269867 New @grpc/grpc-js-xds is vulnerable to Incorrect Authorization in versions 0.0.1 - 1.13.0 and 1.14.0 - 1.14.0. | 0.0.1 - 1.13.01.14.0 - 1.14.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
re2-wasm Version ^1.0.1 | — | — |
vscode-uri Version ^3.0.7 | — | — |
xxhash-wasm Version ^1.0.2 | — | — |
@grpc/proto-loader Version ^0.7.13 | — | — |
google-auth-library Version ^7.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.