88%
Total Score
88
50
94
83
50
No build attestation or trusted-publisher provenance is available, leaving the relationship between source and published artifact less transparent.
The release has 23 runtime dependencies, which is substantial but consistent with a configuration package in the Jest toolchain rather than an isolated utility.
Three contributors were active, but one made about 96% of the 73 recent commits. Organization backing partly offsets this concentration, though maintenance still depends heavily on one contributor.
The repository uses established build tools and has a build system, but no security-scanning tools were detected, leaving a modest security-hygiene gap.
All 11 workflows were analyzed with no untrusted checkout or script-injection findings, and all 48 action references are pinned. The audit identifies high-confidence trusted publishing with long-lived registry credentials, which is a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
glob Version ^13.0.6 | — | — |
chalk Version ^4.1.2 | — | — |
slash Version ^3.0.0 | — | — |
ci-info Version ^4.2.0 | — | — |
deepmerge Version ^4.3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.