The source project is actively maintained, with six recent releases, strong repository activity, and eight active contributors. Use Microsoft.OpenApi.YamlReader instead, because this package has been deprecated and superseded.
42%
Total Score
100
100
81
100
NuGet marks the entire package as deprecated and names Microsoft.OpenApi.YamlReader as its replacement. Active releases and repository maintenance reduce abandonment concerns, but adopting a superseded package creates avoidable dependency risk.
The repository name does not match this package and its README does not mention Microsoft.OpenApi.Readers, which creates some uncertainty about package-to-repository linkage. The broader OpenAPI.NET repository structure and README do provide contextual support for the relationship.
All six workflows were analyzed with no untrusted checkouts, script injection, or unpinned action references. The audit did flag high-confidence github-app permission inheritance, plus template-injection and bot-condition hygiene issues, so workflow governance is a modest concern rather than a release-blocking risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-627503 Microsoft.OpenApi.Readers is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 1.6.29. | 0.0.1 - 1.6.29 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
microsoft.openapi Version [1.6.31, ) | — | — |
sharpyaml Version [2.1.5, ) | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.