the mighty option parser used by yargs
82%
Total Score
100
100
85
80
A prepare install lifecycle script adds some installation complexity and supply-chain exposure, but the available workflow analysis shows no dangerous workflow patterns to compound that concern.
This is a mature package with 84 releases over more than 10 years, but it has had no registry release in about 16 months despite earlier releases roughly every 10 days, so current release cadence is a modest concern.
The repository uses TypeScript, npm scripts, and Babel for builds, but no security-scanning tools were detected, leaving a modest process gap.
Neither workflow declares top-level token permissions, so the repository does not clearly document least-privilege automation access; no workflow was observed with explicit top-level write permissions.
No type declarations are published, which is a usability gap for TypeScript consumers of this library; the package otherwise includes source type definitions in its repository but does not ship declarations.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-7608 yargs-parser is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in versions 6.0.0 - 13.1.2, 14.0.0 - 15.0.1, 0.0.0 - 5.0.0 and 16.0.0 - 18.1.1. | 0.0.0 - 5.0.06.0.0 - 13.1.214.0.0 - 15.0.1 +1 more | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.