Carbon.Pipeline appears to be a healthy, actively maintained dependency: it has been published for over five years, has 98 releases including 11 in the last 12 months, is not deprecated, uses a stable major version, and is backed by a non-archived organization-owned repository with recent pushes, repository tests, build tooling, Dependabot, and a clean workflow risk profile. The main concerns are maintenance concentration around one active contributor, the absence of a repository security policy, and workflow files without top-level token permissions; these are meaningful hygiene and continuity risks but do not outweigh the strong release and repository activity. The package artifact lacks tests and a changelog, but repository tests and GitHub Releases provide partial compensation.
80%
Total Score
80
100
80
Only one registry account has publish access, which is a modest publishing-continuity concern. The organization-owned repository provides some backing, so this is not severe on its own.
All five recent commits came from one contributor, creating a genuine continuity and bus-factor risk. Organization ownership partly mitigates handoff risk, but no second recent contributor is shown.
No security policy was found in the repository, reducing transparency about vulnerability reporting and response procedures.
The only workflow lacks top-level token permissions. Although no top-level write permissions were detected, explicitly restricting workflow permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.