GitHub API token authentication for browsers and Node.js
82%
Total Score
67
100
100
83
100
One contributor made all 3 commits in the last 3 months, creating a concentrated short-term contributor base. Organization ownership provides some handoff capacity, but no second recent contributor is shown.
The repository recorded 3 commits in the last 3 months, showing recent work, but the volume is limited. This is a mild maintenance concern rather than evidence of abandonment.
All 6 workflows were analyzed with no reported audit findings or untrusted checkouts, but all 14 action references are unpinned and 2 workflows grant top-level write access. These are workflow-hygiene cautions, not severe risks without an untrusted sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@octokit/types Version ^18.0.0 | — | — |
@octokit/request-error Version ^7.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.