Spectral ruleset for validating IBM Cloud services
82%
Total Score
100
100
83
50
No build attestation or trusted-publisher provenance was reported. This is a transparency gap for verifying how the registry artifact was produced, though it is not evidence of a bad release by itself.
All 14 analyzed action references are unpinned, and the audit found three high-confidence template-injection findings; the low-confidence cache-poisoning finding is only a hygiene concern. No untrusted checkout or script-injection trigger was reported, limiting the severity.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-342953 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @ibm-cloud/openapi-ruleset is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 1.14.1 - 1.33.10. | 1.14.1 - 1.33.10 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
chalk Version 4.1.2 | — | — |
lodash Version 4.18.1 | — | — |
loglevel Version 1.9.2 | — | — |
inflected Version 2.1.0 | — | — |
minimatch Version 10.2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.