gitsafehub
github.com/Asabeneh/30-Days-Of-Python ↗

Asabeneh/30-Days-Of-Python

scanned 2026-05-26 · git 80e4ac4
2 of 6 checks flagged a security issue
🟡 Worth a look
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies14Known OSS vulnerabilities40Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 600s

Vulnerable dependencies — Trivy 14 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2023-30861 flask: Possible disclosure of permanent session cookie due to missing Vary: Cookie header
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2023-30861). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-28493 python-jinja2: ReDoS vulnerability in the urlize filter
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2020-28493). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-22195 Jinja is an extensible templating engine. Special placeholders in the ...
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2024-22195). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-34064 Jinja is an extensible templating engine. The `xmlattr` filter in affe ...
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2024-34064). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-56326 Jinja is an extensible templating engine. Prior to 3.1.5, An oversight ...
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2024-56326). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-27516 Jinja is an extensible templating engine. Prior to 3.1.6, an oversight ...
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2025-27516). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-25577 python-werkzeug: high resource usage when parsing multipart form data with many fields
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2023-25577). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-34069 Werkzeug is a comprehensive WSGI web application library. The debugger ...
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2024-34069). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-49766 Werkzeug safe_join not safe on Windows
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2024-49766). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-66221 Werkzeug safe_join() allows Windows special device names
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2025-66221). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-21860 Werkzeug safe_join() allows Windows special device names with compound extensions
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2026-21860). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-27199 Werkzeug safe_join() allows Windows special device names
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2026-27199). Fix: Update that package to its patched version.
  • Minor CVE-2026-27205 flask: Flask: Information disclosure via improper caching of session data
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2026-27205). Fix: Update that package to its patched version.
  • Minor CVE-2023-23934 python-werkzeug: cookie prefixed with = can shadow unprefixed cookie
    python_for_web/requirements.txt
    A package you depend on has a known security hole (CVE-2023-23934). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 40 found

Your dependencies cross-checked against the OSV vulnerability database.

  • Worth fixing GHSA-m2qf-hxjv-5gpq Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-2g68-c3qc-8985 Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-xg9f-g7g7-2323 High resource usage when parsing multipart form data with many fields
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-m2qf-hxjv-5gpq Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-2g68-c3qc-8985 Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-xg9f-g7g7-2323 High resource usage when parsing multipart form data with many fields
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Minor GHSA-68rp-wp8r-4726 Flask session does not add `Vary: Cookie` header when accessed in some ways
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Minor GHSA-px8h-6qxv-m22q Incorrect parsing of nameless cookies leads to __Host- cookies bypass
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Minor GHSA-68rp-wp8r-4726 Flask session does not add `Vary: Cookie` header when accessed in some ways
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Minor GHSA-px8h-6qxv-m22q Incorrect parsing of nameless cookies leads to __Host- cookies bypass
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI PYSEC-2023-62 Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxy
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI PYSEC-2021-66 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI GHSA-cpwx-vrp4-4pq7 Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI GHSA-g3rq-g295-4j3m Regular Expression Denial of Service (ReDoS) in Jinja2
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI GHSA-h5c8-rqwp-cp95 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI GHSA-h75v-3vvj-5mfj Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI GHSA-q2x7-8rv6-6q7h Jinja has a sandbox breakout through indirect reference to format method
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI PYSEC-2022-203 ** DISPUTED ** Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included in
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI PYSEC-2023-221 Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are ap
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI PYSEC-2023-57 Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised application
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI PYSEC-2023-58 Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file parts. Parts can be a sm
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI GHSA-29vq-49wr-vm6x Werkzeug safe_join() allows Windows special device names
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI GHSA-87hc-h4r5-73f7 Werkzeug safe_join() allows Windows special device names with compound extensions
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI GHSA-f9vj-2wh5-fj8j Werkzeug safe_join not safe on Windows
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI GHSA-hgf8-39gv-g3f2 Werkzeug safe_join() allows Windows special device names
    /workdirs/scan-cecea858-81fe-461f-aa3f-65511a1c4185/python_for_web/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
… 15 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard couldn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard v5.0.0 · Apache-2.0

error: Check Branch-Protection failed for github.com/Asabeneh/30-Days-Of-Python: internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.