Set of stateless request methods to create, check, reset, refresh, and delete user access tokens for OAuth and GitHub Apps
80%
Total Score
100
100
100
67
100
No security policy was found in the repository, leaving vulnerability-reporting expectations unclear; the presence of CodeQL provides partial compensating security hygiene.
All six workflows were analyzed, but all 14 action references are unpinned, two workflows grant top-level write permissions, and a high-confidence finding reports blanket GitHub App token permissions. No untrusted checkout or script-injection sink was found, limiting the risk to workflow hygiene rather than a severe dependency concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@octokit/types Version ^18.0.0 | — | — |
@octokit/request Version ^10.0.16 | — | — |
@octokit/request-error Version ^7.1.2 | — | — |
@octokit/oauth-authorization-url Version ^8.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.