TypeScript sources, bundled typings, and a detailed README make integration straightforward. The organization-backed project has three active recent contributors and published release notes, though its repository lacks a security policy and most workflow actions are unpinned.
88%
Total Score
100
100
100
67
100
No repository security policy was found, leaving vulnerability-reporting expectations less transparent for adopters.
All three workflows were analyzed with no audit findings or untrusted checkouts, and two use read-only permissions. However, 6 of 7 action references are unpinned and one workflow has top-level write permissions, creating a moderate reproducibility and token-scope hygiene concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-397638 @tus/server is vulnerable to Path Traversal in versions 1.0.0 - 2.4.2. | 1.0.0 - 2.4.2 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
srvx Version ~0.11.15 | — | — |
debug Version ^4.3.4 | — | — |
@tus/utils Version ^0.7.1 | — | — |
lodash.throttle Version ^4.1.1 | — | — |
set-cookie-parser Version ^2.7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.