Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.Packages you depend on that have known security holes (CVEs).
CVE-2023-4759 jgit: arbitrary file overwriteCVE-2025-4949 org.eclipse.jgit: XXE vulnerability in Eclipse JGitYour dependencies cross-checked against the OSV vulnerability database.
GHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-2f88-5hg8-9x2x Origin Validation Error in Apache MavenGHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-fhw8-8j55-vwgq Unsafe deserialization in Apache MINA SSHDGHSA-fhw8-8j55-vwgq Unsafe deserialization in Apache MINA SSHDGHSA-vmq6-5m68-f53m logback serialization vulnerabilityGHSA-rqfh-9r24-8c9r AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertionGHSA-26vr-8j45-3r4w Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resourcesGHSA-7p3p-8qv8-m2vh Eclipse Jetty: HTTP Authority/Host mismatchGHSA-86wm-rrjm-8wh8 Buffer not correctly recycled in Gzip Request inflationGHSA-g8m5-722r-8whq Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacksGHSA-m394-8rww-3jr7 DOS vulnerability for Quoted Quality CSV headersGHSA-q4rv-gq96-w7c5 **UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate requestGHSA-qw69-rqj8-6qw8 OutOfMemoryError for large multipart without filename in Eclipse JettyGHSA-3p86-9955-h393 Arbitrary File Overwrite in Eclipse JGit GHSA-vrpq-qp53-qv56 Eclipse JGit XML External Entity (XXE) VulnerabilityGHSA-25qh-j22f-pwp8 QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processingGHSA-668q-qrv7-99fm Deserialization of Untrusted Data in logbackGHSA-pr98-23f8-jwxv QOS.CH logback-core Expression Language Injection vulnerabilityGHSA-vmq6-5m68-f53m logback serialization vulnerabilityGHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsGHSA-2326-hx7g-3m9r Apache MINA SSHD: integrity check bypassGHSA-mjmq-gwgm-5qhm Apache MINA SSHD information disclosure vulnerabilityGHSA-9279-7hph-r3xw Buffer Overflow in Apache Mina SSHDGHSA-mjmq-gwgm-5qhm Apache MINA SSHD information disclosure vulnerabilityCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.