gitsafehub
github.com/apatrida/fork-deepseek-coder ↗

apatrida/fork-deepseek-coder

scanned 2026-08-13 · git b7ba565
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 3 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies49Known OSS vulnerabilities155Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 400s

Vulnerable dependencies — Trivy 49 found · 3 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2025-32434 PyTorch is a Python package that provides tensor computation with stro ...
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-32434). Fix: Update that package to its patched version.
  • Serious CVE-2023-6730 transformers has a Deserialization of Untrusted Data vulnerability
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2023-6730). Fix: Update that package to its patched version.
  • Serious CVE-2023-6730 transformers has a Deserialization of Untrusted Data vulnerability
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-6730). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-43497 DeepSpeed Remote Code Execution Vulnerability
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2024-43497). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-31580 PyTorch before v2.2.0 was discovered to contain a heap buffer overflow ...
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2024-31580). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-31583 Pytorch before version v2.2.0 was discovered to contain a use-after-fr ...
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2024-31583). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-2999 A vulnerability was found in PyTorch 2.6.0. It has been rated as criti ...
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-2999). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-3730 A vulnerability, which was classified as problematic, was found in PyT ...
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-3730). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-7018 transformers has a Deserialization of Untrusted Data vulnerability
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2023-7018). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-11392 transformers: Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2024-11392). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-11393 transformers: Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2024-11393). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-11394 transformers: Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2024-11394). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-4372 HuggingFace transformers vulnerable to remote code execution
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2026-4372). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-5241 python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2026-5241). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-12720 Transformers Regular Expression Denial of Service (ReDoS) vulnerability
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2024-12720). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-1194 Transformers Regular Expression Denial of Service (ReDoS) vulnerability
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-1194). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-2099 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-2099). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-3263 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-3263). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-3264 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-3264). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-3933 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-3933). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-5197 transformers: Transformers ReDoS Vulnerability
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-5197). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-6051 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-6051). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-6638 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-6638). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-6921 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-6921). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-1839 transformers: HuggingFace Transformers: Arbitrary code execution via malicious checkpoint file
    finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2026-1839). Fix: Update that package to its patched version.
… 24 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 155 found · 10 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2024-259 In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2024-48063). Fix: Update that package to its patched version.
  • Serious PYSEC-2025-41 PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command E
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-32434). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-300 Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2023-6730). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-2290 A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2026-5241). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-2102 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in resp
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2026-34520). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-238 Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parque
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2023-47248). Fix: Update that package to its patched version.
  • Serious PYSEC-2024-259 In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/requirements.txt
    A package you depend on has a known security hole (CVE-2024-48063). Fix: Update that package to its patched version.
  • Serious PYSEC-2025-41 PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command E
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/requirements.txt
    A package you depend on has a known security hole (CVE-2025-32434). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-300 Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/requirements.txt
    A package you depend on has a known security hole (CVE-2023-6730). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-2290 A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/requirements.txt
    A package you depend on has a known security hole (CVE-2026-5241). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-109 DeepSpeed Remote Code Execution Vulnerability
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2024-43497). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-251 Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp.
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2024-31583). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-252 PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (D
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2024-31580). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-191 A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-2953). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-198 In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-46148). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-203 An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-55551). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-204 pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-55552). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-205 A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-55553). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-206 pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-55554). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-207 A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-55557). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-208 A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-55558). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-209 An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-55560). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-139 A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be pe
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2026-4538). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1970 PyTorch Improper Resource Shutdown or Release vulnerability
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2025-3730). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2286 PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.
    /workdirs/scan-b6ed0563-b958-40d1-9339-0e360c65da50/finetune/requirements.txt
    A package you depend on has a known security hole (CVE-2026-24747). Fix: Update that package to its patched version.
… 130 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: pypi:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.