gitsafehub
github.com/Hacker0x01/cube ↗

Hacker0x01/cube

scanned 2026-05-31 · git 4a5e766
3 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets91Vulnerable dependencies274Known OSS vulnerabilities582Risky code patternsMalicious dependenciesProject health8

Security checks

Leaked secrets — Gitleaks 91 found · 52 serious

API keys, passwords or tokens committed into the repo.

  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    docs-mintlify/admin/connect-to-data/visualization-tools/observable.mdx:117
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious grafana-api-key Identified a Grafana API key, which could compromise monitoring dashboards and sensitive data analytics.
    docs-mintlify/admin/monitoring/monitoring-integrations/grafana-cloud.mdx:93
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
    docs-mintlify/docs/data-modeling/access-control/context.mdx:166
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    docs-mintlify/docs/data-modeling/access-control/context.mdx:167
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
    docs-mintlify/embedding/authentication/security-context.mdx:166
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    docs-mintlify/embedding/authentication/security-context.mdx:167
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    docs-mintlify/reference/orchestration-api/dagster.mdx:72
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    docs-mintlify/reference/orchestration-api/dagster.mdx:92
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    docs-mintlify/reference/javascript-sdk/reference/cubejs-client-vue.mdx:118
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious grafana-api-key Identified a Grafana API key, which could compromise monitoring dashboards and sensitive data analytics.
    docs/content/product/administration/deployment/monitoring/grafana-cloud.mdx:83
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    docs/content/product/apis-integrations/orchestration-api/dagster.mdx:69
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    docs/content/product/apis-integrations/orchestration-api/dagster.mdx:89
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    docs/content/product/apis-integrations/javascript-sdk/reference/cubejs-client-vue.mdx:118
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
    docs/content/product/auth/context.mdx:163
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    docs/content/product/auth/context.mdx:164
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    docs/content/product/configuration/visualization-tools/observable.mdx:107
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    examples/recipes/active-users/queries/run.sh:8
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    examples/recipes/column-based-access/queries/run.sh:8
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    examples/recipes/column-based-access/queries/run.sh:9
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    examples/recipes/entity-attribute-value/queries/run.sh:8
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    examples/recipes/getting-unique-values-for-a-field/queries/run.sh:9
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    examples/recipes/joining-multiple-databases-data/queries/run.sh:8
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    examples/recipes/lambda-view/queries/run.sh:8
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    examples/recipes/joining-multiple-datasources-data/queries/run.sh:8
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    examples/recipes/mandatory-filters/queries/run.sh:8
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
… 66 more not shown

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 274 found · 4 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2023-45133 babel: arbitrary code execution
    packages/cubejs-playground/charts-gen/yarn.lock
    A package you depend on has a known security hole (CVE-2023-45133). Fix: Update that package to its patched version.
  • Serious CVE-2025-7783 form-data: Unsafe random function in form-data
    yarn.lock
    A package you depend on has a known security hole (CVE-2025-7783). Fix: Update that package to its patched version.
  • Serious CVE-2026-33937 handlebars.js: Handlebars: Remote Code Execution via crafted Abstract Syntax Tree object in compile()
    yarn.lock
    A package you depend on has a known security hole (CVE-2026-33937). Fix: Update that package to its patched version.
  • Serious CVE-2026-41242 protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields
    yarn.lock
    A package you depend on has a known security hole (CVE-2026-41242). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34601 xmldom: xmldom: XML structure injection via CDATA terminator
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-34601). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41672 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) ...
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-41672). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41673 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) ...
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-41673). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41674 xmldom: xmldom: Arbitrary XML markup injection
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-41674). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41675 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) ...
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-41675). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-45149 brace-expansion: Large numeric range defeats documented `max` DoS protection
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-45149). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41238 DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollution
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-41238). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41239 DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressions
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-41239). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41240 DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-41240). Fix: Update that package to its patched version.
  • Worth fixing GHSA-39q2-94rc-95cp DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation
    docs/yarn.lock
    A package you depend on has a known security hole (GHSA-39q2-94rc-95cp). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-4800 lodash: lodash: Arbitrary code execution via untrusted input in template imports
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-4800). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-2950 lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-2950). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41148 Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-41148). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41149 Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-41149). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41150 Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-41150). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41159 Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-41159). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-27903 minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-27903). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-27904 minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-27904). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44573 Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-44573). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44574 Next.js has a Middleware / Proxy bypass through dynamic route parameter injection
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-44574). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44575 Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
    docs/yarn.lock
    A package you depend on has a known security hole (CVE-2026-44575). Fix: Update that package to its patched version.
… 249 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 582 found · 13 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious RUSTSEC-2021-0122 Generated code can read and write out of bounds in safe code
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/packages/cubejs-backend-native/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/packages/cubejs-playground/charts-gen/yarn.lock
    A package you depend on has a known security hole (CVE-2023-45133). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2021-0122 Generated code can read and write out of bounds in safe code
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/rust/cubesql/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious RUSTSEC-2019-0036 Type confusion if __private_get_type_id__ is overridden
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/rust/cubestore/Cargo.lock
    A package you depend on has a known security hole (CVE-2019-25010). Fix: Update that package to its patched version.
  • Serious GHSA-g93w-mfhg-p222 Angular vulnerable to XSS in i18n attribute bindings
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/yarn.lock
    A package you depend on has a known security hole (CVE-2026-32635). Fix: Update that package to its patched version.
  • Serious GHSA-g93w-mfhg-p222 Angular vulnerable to XSS in i18n attribute bindings
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/yarn.lock
    A package you depend on has a known security hole (CVE-2026-32635). Fix: Update that package to its patched version.
  • Serious GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundary
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/yarn.lock
    A package you depend on has a known security hole (CVE-2025-7783). Fix: Update that package to its patched version.
  • Serious GHSA-2w6w-674q-4c4q Handlebars.js has JavaScript Injection via AST Type Confusion
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/yarn.lock
    A package you depend on has a known security hole (CVE-2026-33937). Fix: Update that package to its patched version.
  • Serious GHSA-wf6x-7x77-mvgw Immutable is vulnerable to Prototype Pollution
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/yarn.lock
    A package you depend on has a known security hole (CVE-2026-29063). Fix: Update that package to its patched version.
  • Serious GHSA-wf6x-7x77-mvgw Immutable is vulnerable to Prototype Pollution
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/yarn.lock
    A package you depend on has a known security hole (CVE-2026-29063). Fix: Update that package to its patched version.
  • Serious GHSA-wf6x-7x77-mvgw Immutable is vulnerable to Prototype Pollution
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/yarn.lock
    A package you depend on has a known security hole (CVE-2026-29063). Fix: Update that package to its patched version.
  • Serious GHSA-wf6x-7x77-mvgw Immutable is vulnerable to Prototype Pollution
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/yarn.lock
    A package you depend on has a known security hole (CVE-2026-29063). Fix: Update that package to its patched version.
  • Serious GHSA-xq3m-2v4x-88gg Arbitrary code execution in protobufjs
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/yarn.lock
    A package you depend on has a known security hole (CVE-2026-41242). Fix: Update that package to its patched version.
  • Worth fixing GHSA-35jp-ww65-95wh axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/docs-mintlify/yarn.lock
    A package you depend on has a known security hole (CVE-2026-44494). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3g43-6gmg-66jw axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/docs-mintlify/yarn.lock
    A package you depend on has a known security hole (CVE-2026-44495). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3p68-rc4w-qgx5 Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/docs-mintlify/yarn.lock
    A package you depend on has a known security hole (CVE-2025-62718). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3w6x-2g7m-8v23 Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/docs-mintlify/yarn.lock
    A package you depend on has a known security hole (CVE-2026-42044). Fix: Update that package to its patched version.
  • Worth fixing GHSA-43fc-jf86-j433 Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/docs-mintlify/yarn.lock
    A package you depend on has a known security hole (CVE-2026-25639). Fix: Update that package to its patched version.
  • Worth fixing GHSA-445q-vr5w-6q77 Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/docs-mintlify/yarn.lock
    A package you depend on has a known security hole (CVE-2026-42037). Fix: Update that package to its patched version.
  • Worth fixing GHSA-4hjh-wcwx-xvwj Axios is vulnerable to DoS attack through lack of data size check
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/docs-mintlify/yarn.lock
    A package you depend on has a known security hole (CVE-2025-58754). Fix: Update that package to its patched version.
  • Worth fixing GHSA-5c9x-8gcm-mpgx Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/docs-mintlify/yarn.lock
    A package you depend on has a known security hole (CVE-2026-42034). Fix: Update that package to its patched version.
  • Worth fixing GHSA-62hf-57xw-28j9 Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/docs-mintlify/yarn.lock
    A package you depend on has a known security hole (CVE-2026-42039). Fix: Update that package to its patched version.
  • Worth fixing GHSA-6chq-wfr3-2hj9 Axios: Header Injection via Prototype Pollution
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/docs-mintlify/yarn.lock
    A package you depend on has a known security hole (CVE-2026-42035). Fix: Update that package to its patched version.
  • Worth fixing GHSA-898c-q2cr-xwhg axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/docs-mintlify/yarn.lock
    A package you depend on has a known security hole (CVE-2026-44490). Fix: Update that package to its patched version.
  • Worth fixing GHSA-fvcv-3m26-pcqx Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
    /workdirs/scan-f9ba5368-f17b-42c1-89b9-532eaaa32e0d/docs-mintlify/yarn.lock
    A package you depend on has a known security hole (CVE-2026-40175). Fix: Update that package to its patched version.
… 557 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog couldn’t run

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: npm:ERROR: Package/Version @cubejs-backend/server not on NPM ERROR: Error while scanning. Received [Errno 2] No such file o

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard 8 notes

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

  • Minor scorecard-overall OpenSSF Scorecard overall: 4.6/10
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Code-Review Code-Review scored 0: Found 0/30 approved changesets -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Fuzzing Fuzzing scored 0: project is not fuzzed
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Maintained Maintained scored 0: project was created within the last 90 days. Please review its contents carefully
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Pinned-Dependencies Pinned-Dependencies scored 0: dependency not pinned by hash detected -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-SAST SAST scored 0: no SAST tool detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Token-Permissions Token-Permissions scored 0: detected GitHub workflow tokens with excessive permissions
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.

via OpenSSF Scorecard v5.5.0 · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.