Tagged template literal for Sanity.io GROQ-queries
76%
Total Score
healthy
Active organization-backed project with strong maintenance, but workflow permissions and package-to-repository identification need attention.
Eight accounts have publish access, with Sanity-owned accounts and several established external addresses. The external accounts are an account-hygiene caution, but organization backing reduces maintenance-capacity concern.
The repository name does not match the package and its README does not mention it, creating some uncertainty about package-to-repository identity even though the package appears in a large organization monorepo.
The audit found high-confidence blanket GitHub App permissions in multiple workflows, secrets inheritance, and 108 unpinned action references out of 131; 12 workflows were not analyzed, so release automation hygiene is a real caution.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.