Package Health

automate/automate

It has a clear README, tests, MIT licensing, and an organization-backed repository with recent commits and releases. Keep its GitHub Actions configuration under review because all action references are unpinned and high-confidence template-injection findings were reported.

Latest 4.2.2PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo toolingcaution

The project uses Make, Composer, and Box for builds, but no security scanning tool was detected. This is a modest transparency and maintenance gap for a deployment tool.

Security policycaution

The repository has no security policy. For a deployment tool that can affect remote servers, the missing disclosure and response process is a genuine transparency gap.

Workflow auditcaution

All 29 action references are unpinned, and the audit found three high-confidence template-injection findings in build.yaml; the low-confidence cache finding is only hygiene. No untrusted checkout or injection trigger was reported, so this is caution rather than a severe verdict.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Julien Jacottet

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^7.1
symfony/config
Version ^7.1
symfony/finder
Version ^7.1
symfony/console
Version ^7.1
symfony/process
Version ^7.1

Weekly Downloads

Info

Last Published
10 months ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform