Package Health

snowflake-sdk

Node.js driver for Snowflake

Latest 3.4.0NPMNPM

84%

Total Score

healthy

Healthy release with active organizational maintenance; workflow pinning and one archived action are the main caveats.

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher provenance is available, leaving the relationship between the published artifact and its source less verifiable than it could be.

Dependency profilecaution

The package has 32 runtime dependencies, which adds maintenance and transitive-dependency surface for a production driver, though the profile is consistent with its broad cloud and authentication integrations.

Workflow auditcaution

The audit analyzed all 9 workflows and found no untrusted checkout or script injection, but all 34 action references are unpinned. It also found a high-confidence archived action and an ad hoc package install; the cache-poisoning findings were low confidence and are hygiene concerns rather than standalone severe risks.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-86597 New
snowflake-sdk is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.0 - 3.3.0.
0.0.0 - 3.3.0
Medium
CVE-2025-46328
snowflake-sdk is vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in versions 1.10.0 - 2.0.3.
1.10.0 - 2.0.3
Low
CVE-2025-24791
snowflake-sdk is vulnerable to Improper Preservation of Permissions in versions 1.12.0 - 2.0.1.
1.12.0 - 2.0.1
Medium
CVE-2023-34232
snowflake-sdk is vulnerable to Improper Neutralization of Special Elements used in a Command ('Command Injection') in versions 0.0.0 - 1.6.21.
0.0.0 - 1.6.21
High

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
open
Version ^7.3.1
—
—
toml
Version ^5.0.0
—
—
axios
Version ^1.15.1
—
—
moment
Version ^2.29.4
—
—
asn1.js
Version ^5.0.0
—
—

Weekly Downloads

Info

Last Published
11 days ago
Created
9 years ago
Unpacked Size
4.9 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform