base abstract trigger component for react
86%
Total Score
healthy
Healthy release, supported by active maintenance and a complete, matching source repository.
No build attestation or trusted-publisher identity is provided, leaving publication provenance less transparent. This is a supply-chain transparency gap, but not evidence that the release is unsafe.
The repository has no security policy, so users have no clearly documented channel or process for reporting vulnerabilities. This is a modest transparency gap.
All five workflows were analyzed with no audit findings or untrusted checkout and script-injection paths. However, three workflows grant top-level write access and five of ten action references are unpinned, reducing workflow hardening.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@babel/runtime Version ^7.24.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.