Fetches and manages remotely-hosted assets and updates to your app's JS bundle.
88%
Total Score
healthy
Frequent releases, active contributors, and strong project controls outweigh workflow-audit gaps and scattered publishing accounts.
No build attestation or trusted-publisher identity is reported, leaving release provenance less transparent. This is a supply-chain transparency gap, though it is not evidence that the release is unsafe.
The organization-backed project has 13 publishing accounts, but several accounts use consumer or outside domains: brentvatne, exponent, kudochien, alanhughes, ccheever, szdziedzic, wschurman, ide, bycedric, tsapeta, and philpl. This is account hygiene caution, not evidence of a thin maintenance team.
All 136 analyzed action references are pinned, and no untrusted checkout or script-injection sinks were found. However, only 30 of 54 workflows were analyzed, with high-confidence template-injection findings and some high-confidence ad hoc package installs; the incomplete audit and workflow hygiene warrant caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
arg Version ^4.1.0 | — | — |
glob Version ^13.0.0 | — | — |
chalk Version ^4.1.2 | — | — |
debug Version ^4.3.4 | — | — |
getenv Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.