Immutable date wrapper
78%
Total Score
88
100
83
80
50
No registry build attestation or trusted-publisher provenance is present, leaving the relationship between source and published artifact less independently verifiable.
The project has 151 releases over more than nine years, but it has had no registry release in the last 12 months despite repository activity, so release maintenance appears slower than its historical cadence.
The repository has only one new issue and no closed issues in the last month, while three pull requests were opened and none merged, suggesting some current workflow sluggishness.
The repository uses established build tooling including Babel, npm scripts, and Rollup, but reports no security scanning tools, leaving a modest security-process gap.
The repository has no security policy, so consumers lack a clearly documented channel and process for reporting vulnerabilities.
| Title | Versions | Severity |
|---|---|---|
CVE-2023-22467 luxon is vulnerable to Inefficient Regular Expression Complexity in versions 2.0.0 - 2.5.2, 3.0.0 - 3.2.1 and 1.0.0 - 1.28.1. | 1.0.0 - 1.28.12.0.0 - 2.5.23.0.0 - 3.2.1 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.