gitsafehub
github.com/di/pyvideo ↗

di/pyvideo

scanned 2026-08-10 · git 625ddd3
2 of 6 checks flagged a security issue
🟡 Worth a look
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies16Known OSS vulnerabilities41Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 16 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2020-28493 python-jinja2: ReDoS vulnerability in the urlize filter
    poetry.lock
    A package you depend on has a known security hole (CVE-2020-28493). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-22195 jinja2: HTML attribute injection when passing user input as keys to xmlattr filter
    poetry.lock
    A package you depend on has a known security hole (CVE-2024-22195). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-34064 jinja2: accepts keys containing non-attribute characters
    poetry.lock
    A package you depend on has a known security hole (CVE-2024-34064). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format method
    poetry.lock
    A package you depend on has a known security hole (CVE-2024-56326). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format method
    poetry.lock
    A package you depend on has a known security hole (CVE-2025-27516). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-40896 pygments: ReDoS in pygments
    poetry.lock
    A package you depend on has a known security hole (CVE-2022-40896). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-28493 python-jinja2: ReDoS vulnerability in the urlize filter
    requirements.txt
    A package you depend on has a known security hole (CVE-2020-28493). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-22195 jinja2: HTML attribute injection when passing user input as keys to xmlattr filter
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-22195). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-34064 jinja2: accepts keys containing non-attribute characters
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-34064). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format method
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-56326). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format method
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-27516). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-20270 python-pygments: Infinite loop in SML lexer may lead to DoS
    requirements.txt
    A package you depend on has a known security hole (CVE-2021-20270). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-27291 python-pygments: ReDoS in multiple lexers
    requirements.txt
    A package you depend on has a known security hole (CVE-2021-27291). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-40896 pygments: ReDoS in pygments
    requirements.txt
    A package you depend on has a known security hole (CVE-2022-40896). Fix: Update that package to its patched version.
  • Minor CVE-2026-4539 pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer
    poetry.lock
    A package you depend on has a known security hole (CVE-2026-4539). Fix: Update that package to its patched version.
  • Minor CVE-2026-4539 pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-4539). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 41 found

Your dependencies cross-checked against the OSV vulnerability database.

  • Worth fixing PYSEC-2022-42986 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2022-23491). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-135 Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. These are in the process of being removed from Mozilla's trust store. e-Tugra's root certificates are being removed pur
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2023-37920). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-230 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.05.30 and prior to 2024.
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2024-39689). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-60 A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings,
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2024-3651). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-215 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2026-45409). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-66 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2020-28493). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1471 Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2025-27516). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1473 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2024-22195). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1474 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2024-34064). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1475 Jinja has a sandbox breakout through indirect reference to format method
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2024-56326). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-62 A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A re
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2020-27783). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-19 An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attrib
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2021-28957). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-852 lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2021-43818). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-230 NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlie
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2022-2309). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-87 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML inp
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2026-41066). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-117 A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2022-40896). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-74 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `re
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2023-32681). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1872 Requests vulnerable to .netrc credentials leak via malicious URLs
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2024-47081). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1873 Requests `Session` object does not verify requests after making first request with verify=False
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2024-35195). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2275 Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system te
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2026-25645). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-3071 Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2026-49476). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-3072 Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2026-49477). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-108 An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking,
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2021-33503). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-192 urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of t
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2023-43804). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-212 urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had i
    /workdirs/scan-1ea1cc7a-4ef6-4551-a803-664a8a8c3b65/poetry.lock
    A package you depend on has a known security hole (CVE-2023-45803). Fix: Update that package to its patched version.
… 16 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.