Turns REST API endpoints into generic request options
68%
Total Score
75
100
100
75
100
All six workflows were analyzed and none combines an untrusted checkout or script injection with pull_request_target, but all 15 action references are unpinned and the audit found a high-confidence github-app issue where an app token inherits blanket installation permissions. Two workflows also grant top-level write access.
The repository recorded zero commits and zero active maintainers over the last three months, a meaningful maintenance concern despite the recent release and push timestamp.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10094 @octokit/endpoint is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 2.1.0 - 9.0.5 and 10.0.0 - 10.1.2. | 2.1.0 - 9.0.510.0.0 - 10.1.2 | High |
| Dependency | Last Release | Score |
|---|---|---|
@octokit/types Version ^18.0.0 | — | — |
universal-user-agent Version ^7.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.