NodeJS/browser bindings to the aws-c-* libraries
86%
Total Score
healthy
Healthy release backed by active, distributed maintenance and frequent releases.
No build attestation or trusted-publisher provenance is reported, leaving the origin of the published artifact less independently verifiable despite the project's active maintenance.
The project uses CMake, TypeScript, and webpack, but no security-scanning tools were detected. The missing scanning is a modest repository hygiene gap, not evidence of abandonment.
All seven workflows were analyzed with no untrusted checkouts, script injection, or audit findings, and four scope permissions at job level. However, all 25 action references are unpinned and one workflow has top-level write permissions, creating a workflow-supply-chain hygiene concern without an observed untrusted sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
axios Version ^1.12.2 | — | — |
buffer Version ^6.0.3 | — | — |
process Version ^0.11.10 | — | — |
crypto-js Version ^4.2.0 | — | — |
@aws-sdk/util-utf8-browser Version ^3.259.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.