SCIM Patch operation (rfc7644).
82%
Total Score
70
100
95
70
50
No build attestation, trusted publisher identity, or staged publishing is present, leaving release-to-source provenance less transparent.
One workflow uses pull_request_target, which can be risky when handling untrusted pull requests, but no untrusted checkouts or script-injection patterns were detected in the analyzed workflows.
Only one registry account has publish access. This is a genuine operational concentration concern for publishing continuity, though repository activity shows the project is currently active.
The repository is owned by an individual rather than an organization, so there is no organizational maintenance buffer to offset the concentrated contributor and publishing base.
One contributor made 8 of 9 recent commits, so activity is highly concentrated; a second active contributor provides limited compensation but does not remove the maintainer-continuity concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-406665 scim-patch is vulnerable to Prototype Pollution in versions 0.9.1 - 0.9.1. | 0.9.1 - 0.9.1 | Medium |
CVE-2026-48170 scim-patch is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 0.9.0. | 0.0.0 - 0.9.0 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
@types/node Version ^26.0.0 | — | — |
fast-deep-equal Version 3.1.3 | — | — |
scim2-parse-filter Version 0.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.