Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.sourcegraph-access-token Sourcegraph is a code search and navigation engine.Packages you depend on that have known security holes (CVEs).
CVE-2026-40034 gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0 ...GHSA-fr8x-3vfx-f45h gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repositoryGHSA-p3hw-mv63-rf9w gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosureGHSA-pg4w-g64p-qwhj gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repositoryCVE-2026-44471 gitoxide is an implementation of git written in Rust. Prior to 0.21.1, ...GHSA-x494-mj8g-cj27 gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack dataGHSA-9857-6mw7-fq2m gix-transport: HTTP credentials leaked to redirected host in curl backendGHSA-p3hw-mv63-rf9w gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosureGHSA-vfvv-c25p-m7mm rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code executionYour dependencies cross-checked against the OSV vulnerability database.
GHSA-f26g-jm89-4g65 gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodulesGHSA-fr8x-3vfx-f45h gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repositoryGHSA-p3hw-mv63-rf9w gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosureGHSA-pg4w-g64p-qwhj gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repositoryGHSA-f89h-2fjh-2r9q gix-fs: Symlink prefix-reuse allows worktree escape during checkoutGHSA-x494-mj8g-cj27 gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack dataGHSA-9857-6mw7-fq2m gix-transport: HTTP credentials leaked to redirected host in curl backendGHSA-p3hw-mv63-rf9w gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosureRUSTSEC-2026-0122 Potential use-after-free due to lack of panic safety in `InlineVec::clear` and `SerVec::clear`RUSTSEC-2026-0190 Unsoundness in `Error::downcast_mut()`RUSTSEC-2026-0204 Invalid pointer dereference in `fmt::Pointer` impl for `Atomic` and `Shared` when the underlying pointer is invalidRUSTSEC-2026-0186 Unchecked pointer offset in crate `memmap2`RUSTSEC-2026-0097 Rand is unsound with a custom logger using `rand::rng()`RUSTSEC-2026-0001 Potential Undefined Behaviors in `Arc<T>`/`Rc<T>` impls of `from_value` on OOMRUSTSEC-2026-0233 Crafted archives can cause a use-after-free during deserializationRUSTSEC-2026-0234 Insufficient archive validation can cause out-of-bounds reads in archives containing hash tablesRUSTSEC-2026-0235 Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/ArcRUSTSEC-2026-0249 smartstring is unmaintainedCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.