The repository includes tests, a clear README, and release notes for this version. Workflow credential inheritance and unpinned action references leave meaningful maintenance and build-integrity gaps.
82%
Total Score
100
100
75
The repository has no SECURITY.md policy. This is a transparency gap for reporting and handling vulnerabilities, although it does not by itself indicate abandonment.
All four workflows were analyzed without untrusted checkouts or script injection, but all seven action references are unpinned and the release workflow inherits secrets through a reusable workflow. These are meaningful supply-chain hygiene concerns, not severe risks on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
oat-sa/generis Version >=17.0.0 | — | — |
oat-sa/tao-core Version >=56.0.0 | — | — |
oat-sa/extension-tao-outcome Version >=13.0.0 | — | — |
oat-sa/oatbox-extension-installer Version ~1.1||dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.