It includes a README, release notes for this version, and a security policy. Its dependency set is small, and the package is licensed under MIT.
88%
Total Score
100
100
100
100
All six workflows were analyzed and all 28 action references are pinned, with no untrusted checkouts or script injections. The audit still found high-confidence bot-condition, template-injection, and broad GitHub App permission issues, so workflow hygiene merits caution, though no dangerous trigger-and-sink combination was shown.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-423403 Microsoft.OpenApi.YamlReader is vulnerable to Uncontrolled Resource Consumption in versions 2.0.0 - 2.11.0 and 3.0.0 - 3.9.0. | 2.0.0 - 2.11.03.0.0 - 3.9.0 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
microsoft.openapi Version [2.12.2, ) | — | — |
sharpyaml Version [2.1.5, ) | — | — |
system.text.json Version [8.0.5, ) | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.