Automated semver compliant package publishing
92%
Total Score
60
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2022-31051 semantic-release is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 17.0.4 - 19.0.3. | 17.0.4 - 19.0.3 | Medium |
CVE-2020-26226 semantic-release is vulnerable to Improper Encoding or Escaping of Output in versions 0.0.0 - 17.2.2. | 0.0.0 - 17.2.2 | High |
| Dependency | Last Release | Score |
|---|---|---|
debug Version ^4.0.0 | — | — |
execa Version ^9.0.0 | — | — |
yargs Version ^18.0.0 | — | — |
env-ci Version ^11.0.0 | — | — |
marked Version ^15.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant