The project has clear licensing, release notes, repository tests, and security tooling. Recent repository activity is absent, and its workflows include a high-confidence broad GitHub App permission issue plus 9 of 10 unpinned actions.
62%
Total Score
67
100
100
100
The repository had zero commits and zero active maintainers in the three months before collection, a meaningful maintenance warning for a library dependency.
There were no newly closed issues and no merged pull requests in the last month, although one pull request was opened; this supports the concern about limited recent maintenance.
All four workflows were analyzed with no untrusted checkout or script-injection findings, but 9 of 10 action references are unpinned. A high-confidence finding reports a GitHub App token inheriting blanket installation permissions, and a medium-confidence finding uses an archived action; together these are genuine workflow hygiene and permission risks.
| Title | Versions | Severity |
|---|---|---|
CVE-2023-49283 microsoft/microsoft-graph-core is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 2.0.2. | 0.0.0 - 2.0.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
microsoft/kiota-http-guzzle Version ^2.0.2 | — | — |
microsoft/kiota-serialization-form Version ^2.0.2 | — | — |
microsoft/kiota-serialization-json Version ^2.0.2 | — | — |
microsoft/kiota-serialization-text Version ^2.0.2 | — | — |
microsoft/kiota-serialization-multipart Version ^2.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.