TypeScript definitions for passport-oauth2
88%
Total Score
100
100
95
90
50
No registry build attestation or trusted publisher identity is present, leaving publication provenance less transparent even though repository activity and organization backing provide compensating project evidence.
The package has existed for about 9 years with 19 releases, but its latest release was about 15 months ago and there were no releases in the last 12 months. The active source repository partly compensates for this because type packages may only change when definitions need updates.
Five workflows declare read-only permissions and none declare top-level write permissions; two omit top-level permissions, which is a minor workflow-hygiene gap but not a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@types/oauth Version * | — | — |
@types/express Version * | — | — |
@types/passport Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.