npmlibrary

Overview

Canonical component data stored by Polaris.

Version

3.28.0

Package Manager

npm

Type

library

Systems

1

Licenses
MIT
Direct Dependencies

3

Technology

Not linked

External Signals
deps.dev endoflife.date OSV.dev
Package URL

pkg:npm/[email protected]

Maintenance

Derived from available component and registry data

Aging
Confidence

Medium

Version Age

426 days

Update Status

Minor update available

Recent Activity

Yes

Reasons
Old versionMature versionMinor available

Lifecycle

Source: endoflife.date

Unknown
No lifecycle match available
The mapped product was not available from the third-party lifecycle source.
Open endoflife.date

Registry

Source: deps.dev

Available
Ecosystem

npm

Latest Version

3.36.0

Published

6/6/2025

Recent Releases

13

Advisories

3

Open deps.dev

Known Vulnerabilities

Source: OSV.dev

3 found

GHSA-hffm-xvc3-vprc

simple-git is vulnerable to Remote Code Execution

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Versions
all versions before 3.36.0
Open advisory

GHSA-jcxm-m3jx-f287

simple-git Affected by Command Execution via Option-Parsing Bypass

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Versions
all versions before 3.32.0
Open advisory

GHSA-r275-fr43-pm7q

simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Versions
>= 3.15.0, before 3.32.3
Open advisory
Open OSV.dev

Security

Source: OpenSSF Scorecard

Unavailable
No security scorecard available
This component does not have a repository reference for OpenSSF Scorecard lookup.

Dependencies

3 direct dependencies

Global view