{"package":"github.com/linkerd/linkerd2","ecosystem":"go","latest_version":"v18.9.1+incompatible","description":"Ultralight, security-first service mesh for Kubernetes. Main repo for Linkerd 2.x.","license":"Apache-2.0","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://pkg.go.dev/github.com/linkerd/linkerd2","repository":"https://github.com/linkerd/linkerd2","downloads_weekly":11380,"health":{"score":50,"risk":"high","breakdown":{"maintenance":0,"popularity":10,"security":23,"maturity":12,"community":5},"deprecated":false,"max_score":100},"vulnerabilities":{"count":3,"critical":0,"high":0,"medium":1,"low":2,"details":[{"vuln_id":"CVE-2025-43915","severity":"medium","summary":"Linkerd resource exhaustion vulnerability","affected_versions":"<0.0.0-20250212165942-faa3f617eef5","fixed_version":"0.0.0-20250212165942-faa3f617eef5","source":"osv","published_at":"2025-05-05T18:32:53Z","in_kev":false,"epss_prob":0.00346,"epss_percentile":0.57077,"threat_tier":"theoretical"},{"vuln_id":"CVE-2024-40632","severity":"unknown","summary":"Linkerd potential access to the shutdown endpoint in github.com/linkerd/linkerd2","affected_versions":"<0.5.1-0.20240614165515-35fb2d6d11ef","fixed_version":"0.5.1-0.20240614165515-35fb2d6d11ef","source":"osv","published_at":"2024-07-22T18:24:29Z","in_kev":false,"epss_prob":0.00086,"epss_percentile":0.24575,"threat_tier":"theoretical"},{"vuln_id":"CVE-2025-43915","severity":"unknown","summary":"Linkerd resource exhaustion vulnerability in github.com/linkerd/linkerd2","affected_versions":null,"fixed_version":null,"source":"osv","published_at":"2025-05-20T17:23:19Z","in_kev":false,"epss_prob":0.00346,"epss_percentile":0.57077,"threat_tier":"theoretical"}],"actively_exploited_count":0,"likely_exploited_count":0},"versions":{"latest":"v18.9.1+incompatible","total_count":21,"recent":["v0.1.3","v0.3.0","v0.4.3","v0.5.0","v18.7.3+incompatible","v0.1.2","v0.4.4","v0.4.0","v0.4.1","v18.8.4+incompatible","v18.7.1+incompatible","v0.3.1","v0.1.0","v18.8.2+incompatible","v0.1.1","v18.8.1+incompatible","v18.8.3+incompatible","v0.2.0","v0.4.2","v18.9.1+incompatible"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":398,"first_published":null,"last_published":"2018-09-12T22:02:40Z","dependencies_count":0,"dependencies":[]},"github_stats":null,"bundle":null,"typescript":null,"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"safe_to_use","issues":[],"use_version":"v18.9.1+incompatible","version_hint":"Update to >= 0.5.1-0.20240614165515-35fb2d6d11ef to fix known vulnerabilities","summary":"github.com/linkerd/linkerd2@v18.9.1+incompatible is safe to use (health: 50/100)"},"version_scoped":null,"requested_version":null,"_cache":"miss","_response_ms":2094,"_powered_by":"depscope.dev — free package intelligence for AI agents","typosquat":{"is_suspected":false},"maintainer_trust":{"available":false},"malicious":{"is_malicious":false},"scorecard":{"available":false},"quality":{"available":false},"version_history_summary":{"total_versions":20,"first_release_age_days":3069,"last_release_days_ago":2787,"avg_days_between_releases":162,"release_velocity":"stale"}}