Oxc Resolver Node API
82%
Total Score
100
94
88
100
The linked repository name does not match this platform binding and its README does not mention the package, so the package-to-repository relationship is less transparent; the monorepo context partly explains the name mismatch but not the missing mention.
All eight workflows were analyzed, use read-only permissions, and have no untrusted checkouts or script injection; however, a high-confidence finding says release.yml grants an app token blanket installation permissions, creating a meaningful permissions-hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.