80%
Total Score
healthy
Healthy: active organization-backed maintenance outweighs workflow pinning and credential-hygiene concerns.
No build attestation or trusted-publisher provenance was recorded. This weakens release transparency, although the active organization-owned repository provides some compensating context.
The repository name does not match the package and its README does not mention the package, so the linkage is less explicit. Because the repository is organization-backed and appears to be a broader project repository, this is a limited caution rather than a severe concern.
The project uses TypeScript, npm scripts, and SWC for builds, showing established build tooling. No security scanning tools were detected, leaving a modest transparency gap.
The repository has no security policy, so vulnerability reporting and response expectations are less transparent. Active maintenance and organizational backing partly reduce the concern but do not remove it.
All six workflows were analyzed without dangerous trigger-and-sink combinations, but 18 of 20 action references are unpinned. High-confidence secrets inheritance and ad hoc package installation add workflow hygiene concerns, though no high-severity findings were reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.8.1 | — | — |
lodash Version ^4.18.1 | — | — |
node-fetch Version ^2.7.0 | — | — |
@stoplight/json Version ^3.20.1 | — | — |
@stoplight/path Version ^1.3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.