Microsoft Application Insights module for Node.js
86%
Total Score
healthy
Active Microsoft-backed maintenance and strong package documentation outweigh limited provenance and workflow-publishing concerns.
No build attestation or trusted publisher identity is recorded for this release. The repository and CI evidence provide context, but the release cannot be independently verified through registry provenance.
All 10 workflows were analyzed with no untrusted checkout or script-injection findings, and all 24 action references are pinned. The high-confidence use-trusted-publishing finding indicates registry publication uses a long-lived token rather than short-lived credentials, which is a supply-chain hygiene concern; the low-confidence cache findings and low-severity ad hoc package findings are lesser concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@azure/identity Version ^4.13.1 | — | — |
@azure/core-auth Version ^1.9.0 | — | — |
@azure/functions Version ^4.11.2 | — | — |
@opentelemetry/api Version ^1.9.1 | — | — |
@opentelemetry/core Version ^2.10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.