Module federation runtime package collection. You can just install it instead of installing all the packages separately.
78%
Total Score
healthy
Healthy overall, with active maintenance and provenance offset by workflow security findings and a missing security policy.
The repository name does not match this package and its README does not mention it, so the package's ownership relationship is less transparent. The organization and package namespace do align, which partly reduces concern.
The repository has no published security policy, leaving reporting and response expectations unclear despite the repository's active maintenance.
All 26 workflows were analyzed and all 113 action references are pinned, with no untrusted checkouts or script injections. However, high-confidence template-injection findings occur in a workflow with a workflow_run trigger, and high-confidence secrets-inherit findings broaden credential exposure; these are meaningful workflow risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@module-federation/runtime Version 2.9.2 | — | — |
@module-federation/webpack-bundler-runtime Version 2.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.