Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.Packages you depend on that have known security holes (CVEs).
CVE-2022-1996 go-restful: Authorization Bypass Through User-Controlled KeyCVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2025-65637 github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payloadCVE-2022-29526 golang: syscall: faccessat checks wrong groupCVE-2022-24778 imgcrypt: Unauthorized access to encryted container image on a shared system due to missing check in CheckAuthorization() code pathCVE-2021-30465 runc: vulnerable to symlink exchange attackCVE-2024-21626 runc: file descriptor leakCVE-2025-31133 runc: container escape via 'masked path' abuse due to mount race conditionsCVE-2025-52565 runc: container escape with malicious config due to /dev/console mount and related racesCVE-2025-52881 runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirectsCVE-2021-43784 runc: integer overflow in netlink bytemsg length field allows attacker to override netlink-based container configurationCVE-2022-29162 runc: incorrect handling of inheritable capabilitiesCVE-2023-28642 runc: AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configurationCVE-2024-45310 runc: runc can be tricked into creating empty files/directories on hostCVE-2026-41579 runc: runc: Host filesystem integrity compromised by malicious container imagesCVE-2025-52881 runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirectsCVE-2022-21698 prometheus/client_golang: Denial of service using InstrumentHandlerCounterCVE-2025-65637 github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payloadCVE-2021-33194 golang: x/net/html: infinite loop in ParseFragmentCVE-2021-44716 golang: net/http: limit growth of header canonicalization cacheCVE-2022-27664 golang: net/http: handle server errors after sending GOAWAYCVE-2022-41723 golang.org/x/net/http2: avoid quadratic complexity in HPACK decodingCVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)Your dependencies cross-checked against the OSV vulnerability database.
GO-2022-0619 Authorization bypass in github.com/emicklei/go-restful, go-restful/v2 and go-restful/v3GO-2026-4762 Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpcGO-2026-4762 Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpcGO-2026-4762 Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpcGO-2025-4188 Logrus is vulnerable to DoS when using Entry.writerScanner in github.com/sirupsen/logrusGO-2022-0493 Incorrect privilege reporting in syscall and golang.org/x/sys/unixGO-2021-0412 Incorrect authorization in github.com/containerd/imgcryptGO-2022-0452 Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runcGO-2022-0914 Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runcGO-2023-1683 AppArmor bypass with symlinked /proc in github.com/opencontainers/runcGO-2024-2491 Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runcGO-2024-3110 Can be confused to create empty files/directories on the host in github.com/opencontainers/runcGO-2025-4096 Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runcGO-2025-4097 Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runcGO-2025-4098 Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runcGO-2026-5761 Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runcGHSA-v95c-p5hm-xq8f Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunCGO-2025-4098 Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runcGO-2022-0322 Uncontrolled resource consumption in github.com/prometheus/client_golangGO-2025-4188 Logrus is vulnerable to DoS when using Entry.writerScanner in github.com/sirupsen/logrusGO-2021-0238 Infinite loop when parsing inputs in golang.org/x/net/htmlGO-2022-0236 Panic due to large headers in net/http and golang.org/x/net/http/httpgutsGO-2022-0969 Denial of service in net/http and golang.org/x/net/http2GO-2022-1144 Excessive memory growth in net/http and golang.org/x/net/http2GO-2023-1571 Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/netCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.