A clear license, focused dependency set, readable documentation, and recent release notes support routine adoption. Pin the CI container image before relying on the project’s build automation.
82%
Total Score
100
100
100
75
The repository has no published security policy. This is a transparency gap, though it is partly offset by the active organization-backed project and recent releases.
All three workflows were analyzed without untrusted triggers or script-injection sinks, but all seven action references are unpinned and the auditor found a high-confidence unpinned container image. This is a concrete CI reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.