The lodash method `_.groupBy` exported as a module.
78%
Total Score
100
86
88
This release is mature, with 23 historical releases, but there have been no releases in over nine years. The active source repository provides some maintenance reassurance, but the published package itself is very stale.
The repository name does not match lodash.groupby and its README does not mention the package. A name mismatch is normal for a monorepo sub-package, but the lack of any package mention leaves some uncertainty that this repository directly backs the release.
Six of eight workflows lack top-level token permission declarations, which leaves permissions less explicit than preferred. None declares top-level write access, and two workflows use read-only permissions, limiting the concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.