gitsafehub
github.com/alibaba/qlexpress ↗

alibaba/qlexpress

scanned 2026-08-03 · git 9065b9a
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets2Vulnerable dependenciesKnown OSS vulnerabilities10Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 2 found · 2 serious

API keys, passwords or tokens committed into the repo.

  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    src/test/resources/perf/long_one_line.ql:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    src/test/resources/perf/long_one_line_format.ql:6
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy none found ✓

Packages you depend on that have known security holes (CVEs).

Nothing found by this check. ✓

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 10 found

Your dependencies cross-checked against the OSV vulnerability database.

  • Worth fixing GHSA-5458-7hh9-v7p4 pf4j is vulnerable to Path Traversal or Zip Slip attack through improper handling of zip entry names
    /workdirs/scan-a0881850-54b4-4a11-b7ca-e52d7f474860/pom.xml
    A package you depend on has a known security hole (CVE-2025-70952). Fix: Update that package to its patched version.
  • Worth fixing GHSA-4gc7-5j7h-4qph Spring Framework DataBinder Case Sensitive Match Exception
    /workdirs/scan-a0881850-54b4-4a11-b7ca-e52d7f474860/pom.xml
    A package you depend on has a known security hole (CVE-2024-38820). Fix: Update that package to its patched version.
  • Worth fixing GHSA-jmp9-x22r-554x Spring Framework annotation detection mechanism may result in improper authorization
    /workdirs/scan-a0881850-54b4-4a11-b7ca-e52d7f474860/pom.xml
    A package you depend on has a known security hole (CVE-2025-41249). Fix: Update that package to its patched version.
  • Worth fixing GHSA-775g-4xr8-78h8 Spring Framework Denial of Service via Integer Overflow in SpEL Expressions
    /workdirs/scan-a0881850-54b4-4a11-b7ca-e52d7f474860/pom.xml
    A package you depend on has a known security hole (CVE-2026-41849). Fix: Update that package to its patched version.
  • Worth fixing GHSA-9cmq-m9j5-mvww Spring Framework vulnerable to Denial of Service
    /workdirs/scan-a0881850-54b4-4a11-b7ca-e52d7f474860/pom.xml
    A package you depend on has a known security hole (CVE-2024-38808). Fix: Update that package to its patched version.
  • Worth fixing GHSA-r5w3-xv2f-j59q Spring Framework Algorithmic Denial of Service via SpEL Expressions
    /workdirs/scan-a0881850-54b4-4a11-b7ca-e52d7f474860/pom.xml
    A package you depend on has a known security hole (CVE-2026-41850). Fix: Update that package to its patched version.
  • Worth fixing GHSA-wxpp-56q6-5pcg Spring Framework Denial of Service via Unbounded Cache in SpEL
    /workdirs/scan-a0881850-54b4-4a11-b7ca-e52d7f474860/pom.xml
    A package you depend on has a known security hole (CVE-2026-41851). Fix: Update that package to its patched version.
  • Minor GHSA-4wp7-92pw-q264 Spring Framework DataBinder Case Sensitive Match Exception
    /workdirs/scan-a0881850-54b4-4a11-b7ca-e52d7f474860/pom.xml
    A package you depend on has a known security hole (CVE-2025-22233). Fix: Update that package to its patched version.
  • Minor GHSA-659m-px2c-25wj Spring Framework Denial of Service via AntPathMatcher
    /workdirs/scan-a0881850-54b4-4a11-b7ca-e52d7f474860/pom.xml
    A package you depend on has a known security hole (CVE-2026-41848). Fix: Update that package to its patched version.
  • Minor GHSA-9f52-rjqv-25qv Spring Framework Arbitrary Method Invocation in SpEL Expressions
    /workdirs/scan-a0881850-54b4-4a11-b7ca-e52d7f474860/pom.xml
    A package you depend on has a known security hole (CVE-2026-41852). Fix: Update that package to its patched version.

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.