Package Health

sequelize

Sequelize is a promise-based Node.js ORM tool for Postgres, MySQL, MariaDB, SQLite, Microsoft SQL Server, Amazon Redshift and Snowflake’s Data Cloud. It features solid transaction support, relations, eager and lazy loading, read replication and more.

Latest 6.37.8NPMNPM

82%

Total Score

healthy

Healthy: active maintenance and a stable, licensed release outweigh workflow hygiene findings.

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation or staged publishing is provided, leaving publication provenance less transparent. This is a modest supply-chain transparency gap, not evidence that the release is unsafe on its own.

Lifecycle scriptscaution

A prepare script runs during installation, which adds execution-time supply-chain exposure compared with a package that has no install lifecycle behavior. No other provided signal shows that this script is unsafe.

Release historycaution

The package has a long history and 632 releases, but only one release in the last 12 months despite a roughly two-day median interval historically. Recent repository activity and exact-version release notes partly offset the slower registry cadence.

Workflow auditcaution

All nine workflows were analyzed successfully, with no untrusted checkout or script-injection sink. However, high-confidence findings include blanket GitHub App permissions, an unpinned container image, and template-injection hygiene concerns, while three of 49 action references are unpinned.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-69240
sequelize is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 6.37.4.
0.0.0 - 6.37.4
Critical
CVE-2026-30951
sequelize is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 6.0.0-beta.1 - 6.37.7.
6.0.0-beta.1 - 6.37.7
High
CVE-2023-22579
sequelize is vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') in versions 0.0.0 - 6.28.1.
0.0.0 - 6.28.1
Critical
CVE-2023-25813
sequelize is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 6.19.1.
0.0.0 - 6.19.1
Critical
CVE-2023-22580
sequelize is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 6.28.1.
0.0.0 - 6.28.1
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
wkx
Version ^0.5.0
—
—
uuid
Version ^8.3.2
—
—
debug
Version ^4.3.4
—
—
dottie
Version ^2.0.6
—
—
lodash
Version ^4.17.21
—
—

Weekly Downloads

Info

Last Published
7 months ago
Created
15 years ago
Unpacked Size
2.8 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform