ESLint rules for @react-native/eslint-config
78%
Total Score
100
100
94
75
100
The repository name does not match the package and its README does not mention @react-native/eslint-plugin, which warrants caution about package-to-repository traceability. The organization-backed monorepo context partly reduces that concern but does not remove it.
The linked repository has no security policy, leaving vulnerability reporting and handling less transparent than ideal. This is a documentation gap rather than evidence of abandonment.
The audit analyzed 30 of 35 workflows and found 122 of 133 action references unpinned, plus high-confidence template-injection and floating-image findings and medium-confidence secrets-inherit findings. No untrusted checkout or script-injection paths were reported, so this lowers hygiene confidence without making the release unfit.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.