gitsafehub
github.com/fladi/django-rest-framework-nested-resource ↗

fladi/django-rest-framework-nested-resource

scanned 2026-08-12 · git ba9dd73
2 of 6 checks flagged a security issue
🟡 Worth a look
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies1Known OSS vulnerabilities13Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 1 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2022-40898 python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli
    requirements.txt
    A package you depend on has a known security hole (CVE-2022-40898). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 13 found

Your dependencies cross-checked against the OSV vulnerability database.

  • Worth fixing PYSEC-2026-1374 filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock
    /workdirs/scan-312fed78-2477-4543-b481-72524e7a4381/requirements-test-with-inflect.txt
    A package you depend on has a known security hole (CVE-2026-22701). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1375 filelock has a TOCTOU race condition which allows symlink attacks during lock file creation
    /workdirs/scan-312fed78-2477-4543-b481-72524e7a4381/requirements-test-with-inflect.txt
    A package you depend on has a known security hole (CVE-2025-68146). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2018-28 The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to dis
    /workdirs/scan-312fed78-2477-4543-b481-72524e7a4381/requirements-test-with-inflect.txt
    A package you depend on has a known security hole (CVE-2018-18074). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-74 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `re
    /workdirs/scan-312fed78-2477-4543-b481-72524e7a4381/requirements-test-with-inflect.txt
    A package you depend on has a known security hole (CVE-2023-32681). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1872 Requests vulnerable to .netrc credentials leak via malicious URLs
    /workdirs/scan-312fed78-2477-4543-b481-72524e7a4381/requirements-test-with-inflect.txt
    A package you depend on has a known security hole (CVE-2024-47081). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1873 Requests `Session` object does not verify requests after making first request with verify=False
    /workdirs/scan-312fed78-2477-4543-b481-72524e7a4381/requirements-test-with-inflect.txt
    A package you depend on has a known security hole (CVE-2024-35195). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2275 Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system te
    /workdirs/scan-312fed78-2477-4543-b481-72524e7a4381/requirements-test-with-inflect.txt
    A package you depend on has a known security hole (CVE-2026-25645). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-263 A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come f
    /workdirs/scan-312fed78-2477-4543-b481-72524e7a4381/requirements-test.txt
    A package you depend on has a known security hole (CVE-2020-25626). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1304 Cross-site Scripting in djangorestframework
    /workdirs/scan-312fed78-2477-4543-b481-72524e7a4381/requirements-test.txt
    A package you depend on has a known security hole (CVE-2024-21520). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-43017 An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.
    /workdirs/scan-312fed78-2477-4543-b481-72524e7a4381/requirements-test.txt
    A package you depend on has a known security hole (CVE-2022-40898). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-263 A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come f
    /workdirs/scan-312fed78-2477-4543-b481-72524e7a4381/requirements.txt
    A package you depend on has a known security hole (CVE-2020-25626). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1304 Cross-site Scripting in djangorestframework
    /workdirs/scan-312fed78-2477-4543-b481-72524e7a4381/requirements.txt
    A package you depend on has a known security hole (CVE-2024-21520). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-43017 An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.
    /workdirs/scan-312fed78-2477-4543-b481-72524e7a4381/requirements.txt
    A package you depend on has a known security hole (CVE-2022-40898). Fix: Update that package to its patched version.

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.