New Relic agent
78%
Total Score
healthy
Active maintenance and strong project backing outweigh workflow hygiene concerns, including unpinned actions and template-injection findings.
No type declarations are published. This is a consumer-ergonomics gap for a JavaScript agent, but it does not indicate abandonment or weak project backing.
All 21 workflows were analyzed with no untrusted checkouts or script-injection findings, and 16 use read-only permissions. However, 67 of 84 action references are unpinned, and the audit reports multiple high-confidence template-injection findings plus some top-level write permissions; these warrant workflow review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ajv Version ^8.17.1 | — | — |
semver Version ^7.5.2 | — | — |
json-bigint Version ^1.0.0 | — | — |
@grpc/grpc-js Version ^1.13.2 | — | — |
concat-stream Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.