Its long release history, clear documentation, and active seven-person contributor base support dependable maintenance. Pinning all workflow dependencies would improve build reproducibility.
88%
Total Score
100
100
100
83
All three workflows were analyzed with no untrusted checkout or script-injection findings, but all 14 action references are unpinned and a high-confidence audit finding identifies an unpinned container image; this is a reproducibility and workflow-hygiene caution.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-550503 league/commonmark is vulnerable to Denial of Service (DoS) in versions 1.5.0 - 2.9.2. | 1.5.0 - 2.9.2 | High |
AIKIDO-2026-280543 league/commonmark is vulnerable to Cross-Site Scripting (XSS) in versions 2.7.0 - 2.9.0. | 2.7.0 - 2.9.0 | High |
AIKIDO-2026-319775 league/commonmark is vulnerable to Denial of Service (DoS) in versions 0.6.0 - 2.9.0. | 0.6.0 - 2.9.0 | High |
AIKIDO-2026-676279 league/commonmark is vulnerable to Denial of Service (DoS) in versions 1.5.0 - 2.9.0. | 1.5.0 - 2.9.0 | High |
AIKIDO-2026-849032 league/commonmark is vulnerable to Denial of Service (DoS) in versions 2.0.0 - 2.8.3. | 2.0.0 - 2.8.3 | High |
| Dependency | Last Release | Score |
|---|---|---|
league/config Version ^1.1.1 | — | — |
psr/event-dispatcher Version ^1.0 | — | — |
symfony/polyfill-php80 Version ^1.16 | — | — |
symfony/deprecation-contracts Version ^2.1 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.