The workflow leaves all four actions unpinned, and the repository has no security policy. Recent releases, tests, and organization backing provide useful continuity.
70%
Total Score
67
100
75
All three recent commits came from one contributor, concentrating maintenance knowledge and increasing continuity risk. Organization ownership partly offsets the risk by providing potential handoff capacity.
The repository had three commits in the last three months, showing some recent activity but only modest maintenance momentum.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented.
The workflow audit completed successfully with no dangerous triggers, untrusted checkouts, or findings, but all four action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psx/api Version ^7.0 | — | — |
psx/schema Version ^7.0 | — | — |
typeapi/model Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.