Meritum module for bootstrapping georgeff/bus into the kernel ecosystem
68%
Total Score
caution
Usable with caveats: repository activity has been quiet for three months and both workflow actions are unpinned.
The package is only 105 days old and has two releases, with a median interval of about 105 days. That is limited history, but it is not yet evidence of abandonment for such a young project.
The repository records zero commits and zero active maintainers over the past three months. Although it was recently pushed and released, the lack of observed commit activity reduces confidence in ongoing maintenance.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap, not a severe risk by itself.
The repository has no security policy. That leaves vulnerability-reporting expectations unclear for consumers of this library.
The single workflow was fully analyzed with no unsafe triggers, untrusted checkouts, or audit findings, but both of its two action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
georgeff/bus Version ^1.0 | — | — |
georgeff/kernel Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.