Sentry Node-Core SDK
45%
Total Score
unhealthy
Risky: the package is explicitly deprecated and scheduled for removal in the next major version.
The published README explicitly labels @sentry/node-core deprecated and says it will be removed in the next major version, directing users toward functionality merged into @sentry/node. The package does include a substantial README and the repository has tests and a changelog, but those strengths do not remove the migration risk.
The linked repository name does not match the package and its README does not mention @sentry/node-core. The organization-backed monorepo makes a name mismatch ordinary, but the missing package mention leaves some uncertainty about the exact package-to-source relationship.
The audit analyzed all 26 workflows and found no untrusted checkouts or script-injection paths, but 145 of 164 action references are unpinned and several workflows expose broad app-token permissions. These are meaningful workflow hygiene concerns, though they are not by themselves evidence that the package is malicious.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@sentry/core Version 10.75.2 | — | — |
@sentry/conventions Version ^0.16.0 | — | — |
import-in-the-middle Version ^3.0.0 | — | — |
@sentry/opentelemetry Version 10.75.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.