The package has clear licensing, documentation, tests, and security coverage. Automated commits are highly concentrated, and an archived workflow action merits routine maintenance attention.
84%
Total Score
83
94
100
One bot accounts for about 97% of recent commits, which is highly concentrated; organization ownership and a second active automation contributor partly reduce the handoff risk.
The repository name does not match the package name and its README does not mention the package, so the package-to-repository relationship is less transparent despite the matching Googleapis organizational backing.
All four workflows were analyzed with no untrusted checkouts or script injection and all 21 action references are pinned. Two workflows grant top-level write permissions, and one high-confidence medium-severity finding uses an archived action, creating a minor maintenance concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.