Native bindings for Rollup
88%
Total Score
healthy
Frequent releases and active project backing make this native Rollup binary a strong dependency despite minor workflow and package-identity caveats.
The repository name does not match this platform-specific package and its README does not mention the package, creating some package-identity ambiguity. The organization-owned Rollup repository and native-binary README context partly compensate, but not completely.
All 7 workflows were analyzed, all 64 action references are pinned, and there are no untrusted checkouts or script injections. The audit reports high-severity cache-poisoning patterns only at low confidence, plus high-confidence ad hoc package installs, so this is a minor hygiene caution.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.