Package Health

afragen/git-updater-gitlab

The package includes tests in its repository, a changelog, a clear MIT license, and minimal runtime dependencies. GitHub Actions need cleanup because all 10 action references are unpinned and high-confidence template-injection patterns were reported, although no untrusted trigger or checkout was found.

Latest 2.9.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo toolingcaution

Composer build tooling is present, supporting a reproducible project workflow, but no security-scanning tool was detected, leaving a minor process gap.

Security policycaution

The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a package that integrates with GitLab APIs.

Workflow auditcaution

All 10 analyzed action references are unpinned, and the audit reports high-confidence template-injection patterns plus an unsound condition. However, there are no pull_request_target or workflow_run triggers and no untrusted checkouts or script-injection findings, so this is workflow hygiene risk rather than a standalone severe dependency risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andy Fragen

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform