The modern build of lodash’s internal `getNative` as a module.
61%
Total Score
100
79
75
The package has had only two releases, with the latest in June 2015 and none in about 11 years. The linked repository remains active, but that does not demonstrate maintenance of this specific release line.
The linked lodash repository neither matches the package name nor mentions lodash._getnative in its README, so the package-to-source relationship is not clearly established. Its monorepo context provides some explanation but does not remove the provenance gap.
All 8 workflows were analyzed, all 20 action references are pinned, and no high- or medium-severity findings were reported. Three high-confidence low-severity adhoc-package findings are a minor workflow hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.