Node binding for rspack
62%
Total Score
caution
Usable with caveats: high-confidence workflow risks outweigh otherwise strong maintenance and release evidence.
The audit analyzed all 24 workflows and found no unpinned actions, but high-confidence template-injection findings occur alongside an untrusted checkout in the workflow_run-based release-debug workflow. High-confidence secrets-inherit and adhoc-package findings, plus top-level write permissions in 12 workflows, add supply-chain hygiene concerns.
The repository name does not match this package and its README does not mention @rspack/binding, so package ownership is less directly transparent. The monorepo relationship and organization backing partly compensate, but the package is explicitly described as an internal binding.
Version 2.2.8 is a stable major release and is not a prerelease, although the package README explicitly says it does not follow semantic versioning.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.