Standard Subresource Integrity library -- parses, serializes, generates, and verifies integrity metadata according to the SRI spec.
68%
Total Score
67
100
100
83
100
All recent commits came from one contributor. The npm organization provides backing, but no second active contributor is shown in this period.
Only one commit was recorded in the last 3 months, so current development activity is thin despite the recent release history.
All 38 action references are unpinned, and four workflows grant top-level write permissions; high-confidence template-injection findings and a medium-confidence bot-condition finding add workflow hygiene concerns, though no untrusted checkout or script-injection trigger was found.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-27290 ssri is vulnerable to Uncontrolled Resource Consumption in versions 5.2.2 - 6.0.2, 7.0.0 - 7.1.1 and 8.0.0 - 8.0.0. | 5.2.2 - 6.0.27.0.0 - 7.1.18.0.0 - 8.0.0 | High |
CVE-2018-7651 ssri is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 5.2.2. | 0.0.0 - 5.2.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
minipass Version ^7.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.