Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code executionCVE-2018-1000201 ruby-ffi DDL loading issue on Windows OSCVE-2018-17567 Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 all ...CVE-2020-26298 rubygem-redcarpet: does not escape HTML when processing quotes which could result in XSS vulnerabilityCVE-2017-16516 rubygem-yajl-ruby: Yajl:: Parser.new.parse incorrect parsingCVE-2022-24795 yajl: heap-based buffer overflow when handling large inputs due to an integer overflowYour dependencies cross-checked against the OSV vulnerability database.
GHSA-mqm2-cgpr-p4m6 Unintended read access in kramdown gemGHSA-2gw2-8q9w-cw8p Ruby-ffi has a DLL loading issue GHSA-4xjh-m3qx-49wc Jekyll allows attackers to access arbitrary files by specifying a symlinkGHSA-q3wr-qw3g-3p4h Injection/XSS in RedcarpetGHSA-jj47-x69x-mxrm Buffer Overflow in yajl-rubyGHSA-wwh7-4jw9-33x6 yajl-ruby gem Denial of Service vulnerabilityCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.