Simple GIT interface for node.js
72%
Total Score
caution
Usable with caveats: no commits in the last three months and all workflow actions are unpinned.
The repository is owned by an individual rather than an organization, so the small maintainer base provides less visible backing if the primary maintainer stops contributing.
No commits or active maintainers were recorded in the last three months, a meaningful maintenance concern, although the current release and recent merged pull requests partly offset it.
The repository has no security policy, leaving vulnerability reporting and response expectations less transparent for users.
All 12 analyzed action references are unpinned, creating avoidable workflow reproducibility and action-update risk; there were no untrusted checkouts, injection findings, or high-severity audit results.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-566884 New simple-git is vulnerable to Argument Injection in versions 0.0.1 - 3.36.0. | 0.0.1 - 3.36.0 | High |
AIKIDO-2026-378256 New simple-git is vulnerable to Command Injection in versions 3.15.0 - 3.36.0. | 3.15.0 - 3.36.0 | High |
AIKIDO-2026-261915 New simple-git is vulnerable to OS Command Injection in versions 0.0.1 - 3.36.0. | 0.0.1 - 3.36.0 | High |
CVE-2026-6951 simple-git is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 3.36.0. | 0.0.0 - 3.36.0 | Critical |
CVE-2026-28291 simple-git is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.0.0 - 3.32.0. | 0.0.0 - 3.32.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
debug Version ^4.4.0 | — | — |
@kwsites/file-exists Version ^1.1.1 | — | — |
@simple-git/argv-parser Version 2.0.1 | — | — |
@kwsites/promise-deferred Version ^1.1.1 | — | — |
@simple-git/args-pathspec Version 1.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.