gRPC utility library for loading .proto files
82%
Total Score
100
100
90
75
50
No build attestation or trusted-publisher provenance was detected, leaving release origin less independently verifiable, although the package has an established repository and release history.
A prepare script runs during installation, which adds build-time behavior and some supply-chain surface, but the available project and artifact evidence does not show it is unsafe.
The package has 61 releases over about 8 years, but only one release in the last 12 months. The linked repository's recent activity partly offsets the slower registry cadence.
The project uses TypeScript and Gulp for builds, but no security-scanning tools were detected. The missing scanning tooling is a modest transparency gap rather than evidence of abandonment.
The single workflow was fully analyzed, uses read-only permissions, and has no untrusted checkouts or injection findings. However, all 8 of 8 action references are unpinned, creating a reproducibility and action-integrity hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
long Version ^5.0.0 | — | — |
yargs Version ^17.7.2 | — | — |
protobufjs Version ^7.5.5 | — | — |
lodash.camelcase Version ^4.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.