Clear documentation, tests, release notes, and security scanning support dependable maintenance. The organization-backed project is active, though workflow pinning needs improvement before trusting its automation.
84%
Total Score
100
100
88
All nine workflows were analyzed with no untrusted checkouts or script injection, and no workflow has top-level write permissions. However, all 49 action references are unpinned, and a high-confidence unpinned container image remains a supply-chain hygiene concern; the low-confidence cache findings are minor.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-22871 spiral/roadrunner is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 0.0.0 - 2025.1.0. | 0.0.0 - 2025.1.0 | Critical |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.