Package Health

protobufjs-cli

Translates between file formats and generates static code as well as TypeScript definitions.

Latest 2.7.1NPMNPM

84%

Total Score

healthy

Frequent releases and an active organization-backed repository outweigh workflow pinning and installation-hygiene gaps.

Are you affected? Scan for Free

Health Score Breakdown

Repo toolingcaution

The repository uses TypeScript, npm scripts, and Gulp, but no security scanning tools were detected; this is a modest transparency gap rather than evidence of abandonment.

Workflow auditcaution

Both workflows were analyzed with no untrusted checkouts or script injection, but all 12 action references are unpinned and two workflows install packages outside a lockfile. The low-confidence cache-poisoning finding is hygiene-level only.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-54271
protobufjs-cli is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 1.3.1 and 2.0.0 - 2.4.2.
0.0.0 - 1.3.12.0.0 - 2.4.2
High
CVE-2026-44295
protobufjs-cli is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 1.2.0 and 2.0.0 - 2.0.1.
0.0.0 - 1.2.02.0.0 - 2.0.1
High
CVE-2026-42290
protobufjs-cli is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.0.0 - 1.2.0 and 2.0.0 - 2.0.1.
0.0.0 - 1.2.02.0.0 - 2.0.1
High

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tmp
Version ^0.2.7
—
—
glob
Version ^8.1.0
—
—
jsdoc
Version ^4.0.5
—
—
espree
Version ^9.6.1
—
—
minimist
Version ^1.2.8
—
—

Weekly Downloads

Info

Last Published
5 hours ago
Created
4 years ago
Unpacked Size
0.5 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform