Send desktop notifications on Windows, Linux, MacOS.
93%
Total Score
healthy
Healthy: active releases and a maintained source project outweigh one archived CI action.
All three workflows were analyzed, all 13 action references are pinned, and no untrusted checkout or script-injection paths were found. One release workflow uses an archived action, which is a contained maintenance and supply-chain hygiene concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-371295 New jolicode/jolinotif is vulnerable to Code Injection in versions 3.2.0 - 3.4.0. | 3.2.0 - 3.4.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
symfony/process Version ^6.4 || ^7.3 || ^8.0 | — | — |
symfony/filesystem Version ^6.4 || ^7.3 || ^8.0 | — | — |
jolicode/php-os-helper Version ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.