Node Rest and Http Clients for use with TypeScript
91%
Total Score
100
100
100
90
50
The release has no attestation or trusted-publisher provenance, which leaves publication origin less transparent even though other repository and release signals are strong.
Both workflows lack top-level permissions declarations and instead rely on job-level permissions, which is a permissions-hygiene gap; however, neither workflow declares top-level write access.
| Title | Versions | Severity |
|---|---|---|
CVE-2023-30846 typed-rest-client is vulnerable to Insufficiently Protected Credentials in versions 0.0.0 - 1.8.0. | 0.0.0 - 1.8.0 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
qs Version ^6.16.0 | — | — |
des.js Version ^1.1.0 | — | — |
js-md4 Version ^0.3.2 | — | — |
tunnel Version 0.0.6 | — | — |
underscore Version ^1.13.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.