Package Health

@trigger.dev/core

Core code used across the Trigger.dev SDK and platform

Latest 4.7.3NPMNPM

88%

Total Score

healthy

Active releases, strong repository activity, and publishing safeguards outweigh incomplete workflow coverage and weak package-to-repository naming evidence.

Are you affected? Scan for Free

Health Score Breakdown

Repo package mentioncaution

The repository name does not match @trigger.dev/core and its README does not mention the package, which creates some package-to-source ambiguity. The organization-owned monorepo context makes a sub-package name mismatch ordinary, but the lack of a README mention remains a caution.

Workflow auditcaution

All 118 analyzed action references are pinned, and most workflows use read-only or job-level permissions. The audit covered only 30 of 38 workflows and found two high-confidence low-severity adhoc package installations, so workflow hygiene is not completely clean.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-73654
@trigger.dev/core is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 3.3.8 - 4.5.5.
3.3.8 - 4.5.5
High
AIKIDO-2026-924948 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@trigger.dev/core is vulnerable to Denial of Service (DoS) in versions 3.0.0 - 4.4.4.
3.0.0 - 4.4.4
Low

Package versions

Direct Dependencies

DependencyLast ReleaseScore
zod
Version ^3.25.56 || ^4.0.0
—
—
jose
Version ^5.4.0
—
—
dequal
Version ^2.0.3
—
—
nanoid
Version 3.3.18
—
—
std-env
Version ^3.8.1
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
3 years ago
Unpacked Size
6.6 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform