Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
GHSA-353f-x4gh-cqq8 Nokogiri patches vendored libxml2 to resolve multiple CVEsGHSA-353f-x4gh-cqq8 Nokogiri patches vendored libxml2 to resolve multiple CVEsGHSA-c4rq-3m3g-8wgx Nokogiri CSS selector tokenizer has regular expression backtrackingGHSA-mrxw-mxhj-p664 Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEsGHSA-5prr-v3j2-97mh Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`GHSA-pxvg-2qj5-37jq Update packaged libxml2 to v2.10.4 to resolve multiple CVEsGHSA-v2fc-qm4h-8hqv Nokogiri XSLT transform has a memory leakGHSA-wx95-c6cv-8532 Nokogiri does not check the return value from xmlC14NExecuteGHSA-xc9x-jj77-9p9j Use-after-free in libxml2 via Nokogiri::XML::ReaderCVE-2024-49761 rexml: REXML ReDoS vulnerabilityCVE-2024-35176 REXML: DoS parsing an XML with many `<`s in an attribute valueCVE-2024-39908 rexml: DoS vulnerability in REXMLCVE-2024-41123 rexml: rubygem-rexml: DoS when parsing an XML having many specific characters such as whitespace character, >] and ]>CVE-2024-41946 rexml: DoS vulnerability in REXMLCVE-2024-43398 rexml: DoS vulnerability in REXMLGHSA-c4rq-3m3g-8wgx Nokogiri CSS selector tokenizer has regular expression backtrackingGHSA-mrxw-mxhj-p664 Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEsGHSA-5prr-v3j2-97mh Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`GHSA-pxvg-2qj5-37jq Update packaged libxml2 to v2.10.4 to resolve multiple CVEsGHSA-v2fc-qm4h-8hqv Nokogiri XSLT transform has a memory leakGHSA-wx95-c6cv-8532 Nokogiri does not check the return value from xmlC14NExecuteGHSA-xc9x-jj77-9p9j Use-after-free in libxml2 via Nokogiri::XML::ReaderCVE-2024-49761 rexml: REXML ReDoS vulnerabilityCVE-2024-35176 REXML: DoS parsing an XML with many `<`s in an attribute valueCVE-2024-39908 rexml: DoS vulnerability in REXMLYour dependencies cross-checked against the OSV vulnerability database.
GHSA-353f-x4gh-cqq8 Nokogiri patches vendored libxml2 to resolve multiple CVEsGHSA-353f-x4gh-cqq8 Nokogiri patches vendored libxml2 to resolve multiple CVEsGHSA-5prr-v3j2-97mh Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`GHSA-c4rq-3m3g-8wgx Nokogiri CSS selector tokenizer has regular expression backtrackingGHSA-mrxw-mxhj-p664 Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEsGHSA-v2fc-qm4h-8hqv Nokogiri XSLT transform has a memory leakGHSA-wx95-c6cv-8532 Nokogiri does not check the return value from xmlC14NExecuteGHSA-2rxp-v6pw-ch6m REXML ReDoS vulnerabilityGHSA-4xqq-m2hx-25v8 REXML denial of service vulnerabilityGHSA-5866-49gr-22v4 REXML DoS vulnerabilityGHSA-r55c-59qm-vjw6 REXML DoS vulnerabilityGHSA-vg3r-rm7w-2xgh REXML contains a denial of service vulnerabilityGHSA-vmwr-mc7x-5vc3 REXML denial of service vulnerabilityGHSA-5prr-v3j2-97mh Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`GHSA-c4rq-3m3g-8wgx Nokogiri CSS selector tokenizer has regular expression backtrackingGHSA-mrxw-mxhj-p664 Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEsGHSA-v2fc-qm4h-8hqv Nokogiri XSLT transform has a memory leakGHSA-wx95-c6cv-8532 Nokogiri does not check the return value from xmlC14NExecuteGHSA-2rxp-v6pw-ch6m REXML ReDoS vulnerabilityGHSA-4xqq-m2hx-25v8 REXML denial of service vulnerabilityGHSA-5866-49gr-22v4 REXML DoS vulnerabilityGHSA-r55c-59qm-vjw6 REXML DoS vulnerabilityGHSA-vg3r-rm7w-2xgh REXML contains a denial of service vulnerabilityGHSA-vmwr-mc7x-5vc3 REXML denial of service vulnerabilityGHSA-5v8h-3h3q-446p Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exceptionCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.