Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2020-8165 rubygem-activesupport: potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStoreCVE-2026-54906 concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Synchronization flaw in ReadWriteLock allows unauthorized lock release and denial of serviceCVE-2022-25648 ruby-git: package vulnerable to Command Injection via git argument injectionCVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code executionCVE-2021-28834 rubygem-kramdown: allows arbitrary classes to be instantiatedCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2021-3918 nodejs-json-schema: Prototype pollution vulnerabilityCVE-2021-44906 minimist: prototype pollutionCVE-2021-23358 nodejs-underscore: Arbitrary code execution via the template functionCVE-2023-22796 rubygem-activesupport: Regular Expression Denial of ServiceCVE-2026-33176 Rails: Active Support: Active Support: Denial of Service via large scientific notation stringsCVE-2023-28120 rubygem-activesupport: Possible XSS in SafeBuffer#bytespliceCVE-2026-33169 rails: rails-activesupport: Active Support: Denial of Service via crafted long digit stringsCVE-2026-33170 Rails: Active Support: Active Support: Cross-Site Scripting (XSS) due to improper HTML safety flag propagation in SafeBuffer#%CVE-2021-32740 rubygem-addressable: ReDoS in templatesCVE-2026-35611 addressable: Addressable: Denial of Service via crafted URI templatesCVE-2022-21223 Command injection in cocoapods-downloaderCVE-2022-24440 Command injection in cocoapods-downloaderCVE-2026-54904 concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Denial of Service due to infinite loop in AtomicReference#updateCVE-2026-54905 concurrent-ruby: Concurrent-ruby: Incorrect write lock granting leading to broken mutual exclusionCVE-2026-54297 faraday: Faraday: Denial of Service via crafted nested query stringsCVE-2026-25765 Faraday: Faraday: Server-Side Request Forgery via protocol-relative URLsCVE-2022-47318 ruby-git: code injection vulnerabilityCVE-2022-46648 ruby-git: code injection vulnerabilityCVE-2022-31163 rubygem-tzinfo: arbitrary code executionYour dependencies cross-checked against the OSV vulnerability database.
GHSA-69p6-wvmq-27gg Command injection in ruby-gitGHSA-52p9-v744-mwjj Remote code execution in KramdownGHSA-mqm2-cgpr-p4m6 Unintended read access in kramdown gemGHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-qh2h-chj9-jffq Growl before 1.10.0 vulnerable to Command InjectionGHSA-2w6w-674q-4c4q Handlebars.js has JavaScript Injection via AST Type ConfusionGHSA-765h-qjxv-5f44 Prototype Pollution in handlebarsGHSA-f2jv-r9rf-7988 Remote code execution in handlebars when compiling templatesGHSA-w457-6q6x-cgp9 Prototype Pollution in handlebarsGHSA-8g7p-74h8-hg48 Denial of Service in https-proxy-agentGHSA-896r-f27r-55mw json-schema is vulnerable to Prototype PollutionGHSA-76p3-8jx3-jpfq Prototype pollution in webpack loader-utilsGHSA-76p3-8jx3-jpfq Prototype pollution in webpack loader-utilsGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-p495-jxh2-wrfg npm package rfc6902 vulnerable to Prototype PollutionGHSA-95m3-7q98-8xr5 sha.js is missing type checks leading to hash rewind and passing on crafted dataGHSA-95m3-7q98-8xr5 sha.js is missing type checks leading to hash rewind and passing on crafted dataGHSA-g4rg-993r-mgx7 Improper Neutralization of Special Elements used in a Command in Shell-quoteGHSA-w7jw-789q-3m8p shell-quote quote() does not escape newlines in object .op valuesCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
scorecard-overall OpenSSF Scorecard overall: 3.8/10scorecard-CI-Tests CI-Tests scored 0: 0 out of 24 merged PRs checked by a CI test -- score normalized to 0scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detectedscorecard-Fuzzing Fuzzing scored 0: project is not fuzzedscorecard-Maintained Maintained scored 0: 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0scorecard-Pinned-Dependencies Pinned-Dependencies scored 0: dependency not pinned by hash detected -- score normalized to 0scorecard-SAST SAST scored 0: SAST tool is not run on all commits -- score normalized to 0scorecard-Security-Policy Security-Policy scored 0: security policy file not detected