Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
slack-webhook-url Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.slack-webhook-url Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.slack-webhook-url Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.slack-webhook-url Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.slack-webhook-url Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.slack-webhook-url Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2026-54906 concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Synchronization flaw in ReadWriteLock allows unauthorized lock release and denial of serviceCVE-2026-33210 ruby/json: Ruby JSON: Denial of Service or Information Disclosure via format string injectionCVE-2026-42257 net-imap: Net::IMAP: Arbitrary IMAP command injection via CRLF sequences in unvalidated inputCVE-2026-39324 Rack::Session is a session management implementation for Rack. From 2. ...GHSA-53g2-mvcc-q9x3 Stored XSS via HTMLParser attribute injection on pasteGHSA-g9jg-w8vm-g96v Trix has a stored XSS vulnerability through its attachment attributeGHSA-qmpg-8xg6-ph5q Trix has a Stored XSS vulnerability through serialized attributesCVE-2026-35611 addressable: Addressable: Denial of Service via crafted URI templatesCVE-2025-14762 aws-sdk-ruby: AWS SDK for Ruby: Data integrity compromise via missing cryptographic key commitmentCVE-2026-33306 github.com/bcrypt-ruby/bcrypt-ruby: bcrypt-ruby (JRuby): Weakened password hashing due to integer overflowCVE-2026-54904 concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Denial of Service due to infinite loop in AtomicReference#updateCVE-2026-54905 concurrent-ruby: Concurrent-ruby: Incorrect write lock granting leading to broken mutual exclusionCVE-2026-41316 erb: ERB: Arbitrary code execution via deserialization bypassCVE-2026-45363 ruby-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verificationGHSA-9wjq-cp2p-hrgf SVG `href` attribute bypasses local-reference restriction in LoofahCVE-2026-54522 MessagePack for Ruby is an implementation of the MessagePack binary se ...CVE-2026-42245 ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responsesCVE-2026-42246 net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLSCVE-2026-42258 ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol ArgumentsCVE-2026-42256 ruby/net-imap: ruby: Net::IMAP: Denial of Service via large iteration count in SCRAM authenticationCVE-2026-47240 net-imap: Net::IMAP: Command injection via non-synchronizing literalsCVE-2026-47242 Net::IMAP implements Internet Message Access Protocol (IMAP) client fu ...GHSA-c4rq-3m3g-8wgx Nokogiri CSS selector tokenizer has regular expression backtrackingGHSA-5prr-v3j2-97mh Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`GHSA-v2fc-qm4h-8hqv Nokogiri XSLT transform has a memory leakYour dependencies cross-checked against the OSV vulnerability database.
GHSA-33qg-7wpp-89cq Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserializationGHSA-53g2-mvcc-q9x3 Trix: Stored XSS via HTMLParser attribute injection on pasteGHSA-g9jg-w8vm-g96v Trix has a stored XSS vulnerability through its attachment attributeGHSA-qmpg-8xg6-ph5q Trix has a Stored XSS vulnerability through serialized attributesGHSA-h27x-rffw-24p4 Addressable has a Regular Expression Denial of Service in Addressable templatesGHSA-2xgq-q749-89fq AWS SDK for Ruby's S3 Encryption Client has a Key Commitment IssueGHSA-f27w-vcwj-c954 bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRubyGHSA-h8w8-99g7-qmvj Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`GHSA-wv3x-4vxv-whpp Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivityGHSA-q339-8rmv-2mhv ERB has an @_init deserialization guard bypass via def_module / def_method / def_classGHSA-3m6g-2423-7cp3 Ruby JSON has a format string injection vulnerabilityGHSA-c32j-vqhx-rx3x ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351GHSA-9wjq-cp2p-hrgf Loofah: SVG `href` attribute bypasses local-reference restrictionGHSA-46q3-7gv7-qmgg Net::IMAP: Command Injection via ID command argumentGHSA-75xq-5h9v-w6px net-imap vulnerable to command Injection via unvalidated Symbol inputsGHSA-87pf-fpwv-p7m7 net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authenticationGHSA-8p34-64r3-mwg8 Net::IMAP: Command Injection via non-synchronizing literal in "raw" argumentGHSA-hm49-wcqc-g2xg net-imap vulnerable to command Injection via "raw" arguments to multiple commandsGHSA-vcgp-9326-pqcp net-imap vulnerable to STARTTLS stripping via invalid response timingGHSA-5prr-v3j2-97mh Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`GHSA-c4rq-3m3g-8wgx Nokogiri CSS selector tokenizer has regular expression backtrackingGHSA-v2fc-qm4h-8hqv Nokogiri XSLT transform has a memory leakGHSA-wx95-c6cv-8532 Nokogiri does not check the return value from xmlC14NExecuteGHSA-2vqw-3mp8-cgmx Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent ConnectionsGHSA-qpgp-93vx-g8v8 Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.