🚇 Config parser for Metro.
88%
Total Score
100
100
94
67
100
The repository name does not match the package name and its README does not mention the package, creating uncertainty about the exact package-to-repository linkage; this may reflect a monorepo structure but remains a transparency gap.
No repository security policy was found, leaving vulnerability-reporting guidance unclear; the active maintenance and Dependabot coverage only partly compensate for this transparency gap.
Three workflows declare read-only permissions, but one workflow lacks top-level permissions. No workflow has top-level write access, so this is a limited hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
metro Version 0.87.1 | — | — |
connect Version ^3.6.5 | — | — |
metro-core Version 0.87.1 | — | — |
metro-cache Version 0.87.1 | — | — |
jest-validate Version ^29.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.