The source has regular releases, three active contributors, tests, release notes, and a clear license. Pin workflow actions and inspect the high-confidence CI warning before relying on automated publishing.
67%
Total Score
100
50
100
50
The package has 8 runtime dependencies, including several related Opscale packages. This is a meaningful integration surface, though the provided signals show no dependency-specific failure.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, although it does not by itself indicate abandoned maintenance.
All 16 analyzed action references are unpinned, and two workflows grant top-level write permissions. The audit also found a high-confidence bot-conditions issue in auto-update.yml; no untrusted checkout or script-injection sink was reported, so this is caution rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
opscale-co/actions Version ^3.0 | — | — |
opscale-co/validations Version ^1.0 | — | — |
opscale-co/nova-catalogs Version ^1.3.1 | — | — |
opscale-co/nova-bpmn-field Version ^1.0 | — | — |
opscale-co/nova-dbml-field Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.