gitsafehub
github.com/gunthercox/robotpartsmanager ↗

gunthercox/robotpartsmanager

scanned 2026-08-08 · git e121100
1 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependenciesKnown OSS vulnerabilities34Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy none found ✓

Packages you depend on that have known security holes (CVEs).

Nothing found by this check. ✓

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 34 found · 4 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2020-35 Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data a
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2020-7471). Fix: Update that package to its patched version.
  • Serious PYSEC-2022-190 An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2022-28346). Fix: Update that package to its patched version.
  • Serious PYSEC-2022-191 A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion)
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2022-28347). Fix: Update that package to its patched version.
  • Serious GHSA-frmv-pr5f-9mcr Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2025-64459). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-31 An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collisi
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2020-13254). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-32 An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility o
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2020-13596). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-33 An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level di
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2020-24583). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-34 An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's sta
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2020-24584). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-36 Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suit
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2020-9402). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-439 In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2021-44420). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-6 In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2021-28658). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-7 In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2021-31542). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-8 In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2021-32052). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-9 In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal v
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2021-3281). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-98 Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the exist
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2021-33203). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-99 In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This ma
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2021-33571). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-1 An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityValidator incurred significant overhead in evaluating a submitted password that was
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2021-45115). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-19 The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2022-22818). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-2 An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter w
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2021-45116). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-20 An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2022-23833). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-3 Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it.
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2021-45452). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1297 Django allows enumeration of user e-mail addresses
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2024-45231). Fix: Update that package to its patched version.
  • Worth fixing GHSA-6w2r-r2m5-xq5w Django is subject to SQL injection through its column aliases
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2025-57833). Fix: Update that package to its patched version.
  • Worth fixing GHSA-7xr5-9hcq-chf9 Django Improper Output Neutralization for Logs vulnerability
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2025-48432). Fix: Update that package to its patched version.
  • Worth fixing GHSA-8qcx-xf44-272x Django: DomainNameValidator permits newline characters that may enable HTTP header injection
    /workdirs/scan-09337b3d-8d7b-41e0-8ebd-4f0a94dcbece/requirements.txt
    A package you depend on has a known security hole (CVE-2026-53878). Fix: Update that package to its patched version.
… 9 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.