86%
Total Score
healthy
Frequent releases and broad, active maintenance outweigh workflow hygiene issues.
No build attestation or staged publishing is reported, although the trusted publisher identity is GitHub; the missing verifiable provenance is a supply-chain transparency gap.
The package declares 21 runtime dependencies, including substantial runtime and build-related components; this adds maintenance surface but is consistent with a server runtime package.
All 24 workflows were analyzed, with no untrusted checkout or script-injection findings. However, the audit reports high-confidence template-injection findings, repeated ad hoc package installs, 75 of 156 unpinned action uses, and one failed file; these are workflow hygiene and reproducibility concerns, not evidence of an immediate dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tsx Version 4.21.0 | — | — |
etag Version 1.8.1 | — | — |
undici Version 5.28.4 | — | — |
esbuild Version 0.27.0 | — | — |
ts-morph Version 12.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.