decompress tar.bz2 plugin
70%
Total Score
caution
Usable with caveats: recent releases and an active repository offset single-contributor maintenance and unpinned CI actions.
All recent repository commits came from one contributor, leaving maintenance dependent on a single person; the repository is user-owned, so no organizational handoff is evidenced.
There was one commit in the last 3 months, showing recent activity but a limited maintenance pace for the observed period.
The repository has no security policy, which is a transparency gap, although CodeQL scanning provides some compensating security practice.
All 8 analyzed action references are unpinned, weakening CI supply-chain reproducibility. The audit found no untrusted checkouts, script injection, dangerous triggers, or high-severity findings, which keeps this a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
file-type Version ^21.3.4 | — | — |
is-stream Version ^4.0.1 | — | — |
seek-bzip Version ^2.0.0 | — | — |
unbzip2-stream Version ^1.4.3 | — | — |
@xhmikosr/decompress-tar Version ^9.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.