gitsafehub
github.com/AgriciDaniel/claude-ads ↗

AgriciDaniel/claude-ads

scanned 2026-05-24 · git 283d9d4
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets5Vulnerable dependenciesKnown OSS vulnerabilities132Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 5 found

API keys, passwords or tokens committed into the repo.

  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    tests/scripts/test_url_utils.py:101
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    tests/scripts/test_url_utils.py:102
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    tests/scripts/test_url_utils.py:103
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    tests/scripts/test_url_utils.py:136
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    tests/scripts/test_url_utils.py:90
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy none found ✓

Packages you depend on that have known security holes (CVEs).

Nothing found by this check. ✓

via Trivy v0.58.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 132 found · 15 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GHSA-8q59-q68h-6hv4 Improper Input Validation in PyYAML
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements-dev.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-rprw-h62v-c2w7 PyYAML insecurely deserializes YAML strings leading to arbitrary code execution
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements-dev.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-3f63-hfp8-52jq Arbitrary Code Execution in Pillow
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-43fq-w8qq-v88h Out-of-bounds read in Pillow
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-57h3-9rgr-c24m Out of bounds write in Pillow
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-7534-mm45-c74v Buffer Overflow in Pillow
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-8m9x-pxwq-j236 Pillow command injection
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-8vj2-vxx3-667w Arbitrary expression injection in Pillow
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-hvr8-466p-75rh Pillow Integer overflow in ImagingResampleHorizontal
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-p49h-hjvm-jg3h PCX P mode buffer overflow in Pillow
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-r7rm-8j6h-r933 Buffer Copy without Checking Size of Input in Pillow
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-vcqg-3p29-xw73 Integer overflow in Pillow
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-pj98-2xf6-cff5 ReportLab vulnerable to remote code execution via paraparser
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-qpg2-vx7j-3869 XML Injection in ReportLab
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-www2-v7xj-xrc6 Exposure of Sensitive Information to an Unauthorized Actor in urllib3
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-3c5c-7235-994j Pillow buffer overflow in ImagingPcdDecode
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-3wvg-mj6g-m9cv Pillow Uncontrolled Resource Consumption
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-3xv8-3j54-hgrp Out-of-bounds read in Pillow
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-44wm-f244-xhp3 Pillow buffer overflow vulnerability
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-5gm3-px64-rw72 Uncontrolled Resource Consumption in Pillow
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-7r7m-5h27-29hp Potential infinite loop in Pillow
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-8843-m7mw-mxqm Buffer overflow in Pillow
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-8ghj-p4vj-mr35 Pillow Denial of Service vulnerability
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-8xjq-8fcg-g5hw Out-of-bounds Write in Pillow
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-8xjv-v9xq-m5h9 Pillow Buffer overflow in ImagingFliDecode
    /workdirs/scan-92a56d34-f5ed-4b75-be8a-0d5e24b22c1c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
… 107 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard couldn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard v5.0.0 · Apache-2.0

error: Error: check runtime error: Branch-Protection: internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by personal access token 2026/05/24 23:18:49 error during command execution: check runtime error: Branch-Protection: internal error: error during

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.