gitsafehub
github.com/antiagainst/babelstream ↗

antiagainst/babelstream

scanned 2026-08-10 · git 2f00dfb
3 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets8Vulnerable dependencies453Known OSS vulnerabilities10Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 8 found

API keys, passwords or tokens committed into the repo.

  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    src/julia/JuliaStream.jl/Project.toml:16
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    src/julia/JuliaStream.jl/oneAPI/Project.toml:4
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    src/julia/JuliaStream.jl/Project.toml:16
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    src/julia/JuliaStream.jl/oneAPI/Project.toml:4
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    src/julia/JuliaStream.jl/Project.toml:16
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    src/julia/JuliaStream.jl/oneAPI/Project.toml:4
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    JuliaStream.jl/Project.toml:16
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    JuliaStream.jl/oneAPI/Project.toml:4
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 453 found · 48 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2022-42920 Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing
    src/java/java-stream/pom.xml
    A package you depend on has a known security hole (CVE-2022-42920). Fix: Update that package to its patched version.
  • Serious CVE-2022-32221 curl: POST following PUT confusion
    src/julia/JuliaStream.jl/AMDGPU/Manifest.toml
    A package you depend on has a known security hole (CVE-2022-32221). Fix: Update that package to its patched version.
  • Serious CVE-2023-23914 curl: HSTS ignored on multiple requests
    src/julia/JuliaStream.jl/AMDGPU/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-23914). Fix: Update that package to its patched version.
  • Serious CVE-2023-38545 curl: heap based buffer overflow in the SOCKS5 proxy handshake
    src/julia/JuliaStream.jl/AMDGPU/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-38545). Fix: Update that package to its patched version.
  • Serious CVE-2026-11856 curl: curl: Information disclosure via incorrect Digest authentication header reuse
    src/julia/JuliaStream.jl/AMDGPU/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-11856). Fix: Update that package to its patched version.
  • Serious CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies
    src/julia/JuliaStream.jl/AMDGPU/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8924). Fix: Update that package to its patched version.
  • Serious CVE-2026-8927 curl: Information disclosure due to uncleared proxy authentication state
    src/julia/JuliaStream.jl/AMDGPU/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8927). Fix: Update that package to its patched version.
  • Serious CVE-2026-55200 libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
    src/julia/JuliaStream.jl/AMDGPU/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-55200). Fix: Update that package to its patched version.
  • Serious CVE-2025-47917 Mbed TLS before 3.6.4 allows a use-after-free in certain situations of ...
    src/julia/JuliaStream.jl/AMDGPU/Manifest.toml
    A package you depend on has a known security hole (CVE-2025-47917). Fix: Update that package to its patched version.
  • Serious CVE-2023-45853 zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6
    src/julia/JuliaStream.jl/AMDGPU/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-45853). Fix: Update that package to its patched version.
  • Serious CVE-2022-32221 curl: POST following PUT confusion
    src/julia/JuliaStream.jl/CUDA/Manifest.toml
    A package you depend on has a known security hole (CVE-2022-32221). Fix: Update that package to its patched version.
  • Serious CVE-2023-23914 curl: HSTS ignored on multiple requests
    src/julia/JuliaStream.jl/CUDA/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-23914). Fix: Update that package to its patched version.
  • Serious CVE-2023-38545 curl: heap based buffer overflow in the SOCKS5 proxy handshake
    src/julia/JuliaStream.jl/CUDA/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-38545). Fix: Update that package to its patched version.
  • Serious CVE-2026-11856 curl: curl: Information disclosure via incorrect Digest authentication header reuse
    src/julia/JuliaStream.jl/CUDA/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-11856). Fix: Update that package to its patched version.
  • Serious CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies
    src/julia/JuliaStream.jl/CUDA/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8924). Fix: Update that package to its patched version.
  • Serious CVE-2026-8927 curl: Information disclosure due to uncleared proxy authentication state
    src/julia/JuliaStream.jl/CUDA/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8927). Fix: Update that package to its patched version.
  • Serious CVE-2026-55200 libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
    src/julia/JuliaStream.jl/CUDA/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-55200). Fix: Update that package to its patched version.
  • Serious CVE-2025-47917 Mbed TLS before 3.6.4 allows a use-after-free in certain situations of ...
    src/julia/JuliaStream.jl/CUDA/Manifest.toml
    A package you depend on has a known security hole (CVE-2025-47917). Fix: Update that package to its patched version.
  • Serious CVE-2023-45853 zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6
    src/julia/JuliaStream.jl/CUDA/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-45853). Fix: Update that package to its patched version.
  • Serious CVE-2022-32221 curl: POST following PUT confusion
    src/julia/JuliaStream.jl/KernelAbstractions/Manifest.toml
    A package you depend on has a known security hole (CVE-2022-32221). Fix: Update that package to its patched version.
  • Serious CVE-2023-23914 curl: HSTS ignored on multiple requests
    src/julia/JuliaStream.jl/KernelAbstractions/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-23914). Fix: Update that package to its patched version.
  • Serious CVE-2023-38545 curl: heap based buffer overflow in the SOCKS5 proxy handshake
    src/julia/JuliaStream.jl/KernelAbstractions/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-38545). Fix: Update that package to its patched version.
  • Serious CVE-2026-11856 curl: curl: Information disclosure via incorrect Digest authentication header reuse
    src/julia/JuliaStream.jl/KernelAbstractions/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-11856). Fix: Update that package to its patched version.
  • Serious CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies
    src/julia/JuliaStream.jl/KernelAbstractions/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8924). Fix: Update that package to its patched version.
  • Serious CVE-2026-8927 curl: Information disclosure due to uncleared proxy authentication state
    src/julia/JuliaStream.jl/KernelAbstractions/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8927). Fix: Update that package to its patched version.
… 428 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 10 found

Your dependencies cross-checked against the OSV vulnerability database.

  • Worth fixing RUSTSEC-2024-0019 Tokens for named pipes may be delivered after deregistration
    /workdirs/scan-82ade010-b0f9-4d9e-8dff-7d19ec4a9ca6/src/rust/rust-stream/Cargo.lock
    A package you depend on has a known security hole (CVE-2024-27308). Fix: Update that package to its patched version.
  • Worth fixing GHSA-c827-hfw6-qwvm rustix's `rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosion
    /workdirs/scan-82ade010-b0f9-4d9e-8dff-7d19ec4a9ca6/src/rust/rust-stream/Cargo.lock
    A package you depend on has a known security hole (CVE-2024-43806). Fix: Update that package to its patched version.
  • FYI RUSTSEC-2021-0139 ansi_term is Unmaintained
    /workdirs/scan-82ade010-b0f9-4d9e-8dff-7d19ec4a9ca6/src/rust/rust-stream/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI RUSTSEC-2025-0052 async-std has been discontinued
    /workdirs/scan-82ade010-b0f9-4d9e-8dff-7d19ec4a9ca6/src/rust/rust-stream/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI RUSTSEC-2021-0145 Potential unaligned read
    /workdirs/scan-82ade010-b0f9-4d9e-8dff-7d19ec4a9ca6/src/rust/rust-stream/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI RUSTSEC-2024-0375 `atty` is unmaintained
    /workdirs/scan-82ade010-b0f9-4d9e-8dff-7d19ec4a9ca6/src/rust/rust-stream/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI RUSTSEC-2026-0204 Invalid pointer dereference in `fmt::Pointer` impl for `Atomic` and `Shared` when the underlying pointer is invalid
    /workdirs/scan-82ade010-b0f9-4d9e-8dff-7d19ec4a9ca6/src/rust/rust-stream/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI RUSTSEC-2024-0384 `instant` is unmaintained
    /workdirs/scan-82ade010-b0f9-4d9e-8dff-7d19ec4a9ca6/src/rust/rust-stream/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI RUSTSEC-2024-0370 proc-macro-error is unmaintained
    /workdirs/scan-82ade010-b0f9-4d9e-8dff-7d19ec4a9ca6/src/rust/rust-stream/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • FYI RUSTSEC-2022-0104 `structopt` is in maintenance mode
    /workdirs/scan-82ade010-b0f9-4d9e-8dff-7d19ec4a9ca6/src/rust/rust-stream/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.