Package Health

@rspack/core

Fast Rust-based bundler for the web with a modernized webpack API

Latest 2.2.8NPMNPM

68%

Total Score

caution

Usable with caveats: active maintenance is offset by high-confidence workflow risks involving untrusted checkout and template injection.

Are you affected? Scan for Free

Health Score Breakdown

Workflow auditdanger

All 24 workflows were analyzed and action references are fully pinned, but release-debug.yml combines workflow_run with an untrusted checkout, while the audit reports high-confidence template-injection findings and broad write permissions elsewhere. These are material automation supply-chain concerns.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2024-10552 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@rspack/core is vulnerable to Malicious Code in versions 1.1.7 - 1.1.7.
1.1.7 - 1.1.7
Critical

Package versions

Direct Dependencies

DependencyLast ReleaseScore
@rspack/binding
Version 2.2.8
—
—

Weekly Downloads

Info

Last Published
13 days ago
Created
4 years ago
Unpacked Size
1.7 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform