Sentry hub which handles global state managment.
42%
Total Score
unhealthy
Risky: this release is from a discontinued package, despite strong ongoing maintenance of the Sentry monorepo.
The package includes a README, but it explicitly identifies the package as discontinued and directs consumers to exports from @sentry/core. That makes this release a poor choice for a new dependency despite repository tests and changelog evidence.
The package has 440 releases since 2018, but no releases in the last 12 months; the repository remains active, so this points to package-specific withdrawal rather than abandonment of the wider project.
The linked repository name does not match @sentry/hub and its README does not mention the package, creating some uncertainty about package-specific ownership. The organization-backed monorepo context partly explains the mismatch but does not remove the concern.
All 26 workflows were analyzed, with no untrusted checkouts or script-injection findings. However, high-confidence blanket GitHub App permissions and 145 unpinned action references are workflow hygiene concerns; low-confidence cache findings do not materially change the assessment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@sentry/core Version 7.120.4 | — | — |
@sentry/types Version 7.120.4 | — | — |
@sentry/utils Version 7.120.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.