Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2026-56852 golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 inputGHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 VulnerabilitiesCVE-2026-56852 golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 inputCVE-2026-56852 golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 inputGHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 VulnerabilitiesCVE-2024-25621 github.com/containerd/containerd: containerd local privilege escalationCVE-2026-46680 github.com/containerd/containerd: containerd: Privilege escalation via incorrect user ID handlingCVE-2026-53488 github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI pluginCVE-2026-53489 github.com/containerd/containerd: containerd: Arbitrary host file read via symlink following in CRI checkpoint restoreCVE-2026-53492 github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.CVE-2025-64329 github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaksCVE-2026-47262 github.com/containerd/containerd: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsingCVE-2026-50195 github.com/containerd/containerd: containerd: Arbitrary code execution via CRI checkpoint image tag poisoningCVE-2025-15558 docker/cli: Docker CLI for Windows: Privilege escalation via malicious plugin binariesCVE-2026-34040 Moby: Moby: Authorization bypass vulnerabilityCVE-2026-33997 moby: docker: github.com/moby/moby: Moby: Privilege validation bypass during plugin installationGHSA-pmwq-pjrm-6p5r in-toto-golang and in-toto-python have inconsistent negation behaviorCVE-2026-33747 BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontendCVE-2026-33748 github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir componentsCVE-2026-35469 Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming codeCVE-2026-39882 github.com/open-telemetry/opentelemetry-go: golang: OpenTelemetry-Go: Memory exhaustion via uncapped HTTP response body readingCVE-2026-39882 github.com/open-telemetry/opentelemetry-go: golang: OpenTelemetry-Go: Memory exhaustion via uncapped HTTP response body readingYour dependencies cross-checked against the OSV vulnerability database.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.