It includes an MIT license, a clear README, and release notes for this version. Build provenance is present; workflow hygiene is mostly sound, with only minor package-install findings.
92%
Total Score
100
93
67
100
The project uses TypeScript, Vitest, and npm scripts for its build and tests. No security-scanning tools were detected, which is a modest transparency gap but not enough to outweigh the active project evidence.
The repository has no security policy. This weakens vulnerability-reporting transparency, though the active organization-backed project and other release evidence partly compensate.
All 13 workflows were analyzed with no high- or medium-severity findings and no untrusted checkout or script-injection paths. Three high-confidence low-severity adhoc-package findings and two unpinned action references leave minor hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-63225 @redocly/cli is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 1.34.17 and 2.0.0 - 2.33.2. | 0.0.0 - 1.34.172.0.0 - 2.33.2 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.