The package has a substantial README, documented release notes, repository tests, and active organizational ownership. Its artifact license conflicts with the declared MIT license, and the release workflow grants an app token blanket permissions; pin this version while the migration completes.
65%
Total Score
100
100
93
83
50
No build attestation or trusted-publisher provenance is present. This limits publication transparency, though the package otherwise has an established repository and release history.
The artifact includes a license file, but it was detected as BSD-3-Clause while the manifest declares MIT. The mismatch is a transparency concern that should be resolved before relying on licensing assumptions.
All 4 workflows were analyzed and all 39 action references are pinned, with no untrusted checkouts or script injection detected. However, the release workflow has a high-confidence finding that its app token inherits blanket installation permissions; the low-confidence cache findings are hygiene concerns only.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@sentry/bundler-plugins Version ^10.64.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.