Octokit plugin adding one method for all of api.github.com REST API endpoints
68%
Total Score
67
100
100
83
100
All commits in the last 3 months came from one contributor. The organization-owned repository provides handoff capacity, but no second active contributor is shown in this period.
Only one commit was recorded in the last 3 months, indicating limited recent source activity. Recent releases and pull-request activity partly offset this, but they do not fully remove the maintenance concern.
All seven workflows were analyzed, but all 21 action references are unpinned, and three high-confidence findings report blanket GitHub App token permissions; one workflow also installs a package outside a lockfile. The pull_request_target triggers had no reported untrusted checkout or script-injection sink, so these are workflow-hygiene concerns rather than standalone critical risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@octokit/types Version ^17.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.