Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of serviceCVE-2023-2976 guava: insecure temporary directory creationCVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of serviceCVE-2023-2976 guava: insecure temporary directory creationCVE-2020-8908 guava: local information disclosure via temporary directory created with unsafe permissionsCVE-2020-8908 guava: local information disclosure via temporary directory created with unsafe permissionsYour dependencies cross-checked against the OSV vulnerability database.
GHSA-cqqj-4p63-rrmm HTTP Request Smuggling in NettyGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-7g45-4rm6-3mm3 Guava vulnerable to insecure use of temporary directoryGHSA-mvr2-9pj6-7w5j Denial of Service in Google GuavaGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-7g45-4rm6-3mm3 Guava vulnerable to insecure use of temporary directoryGHSA-mvr2-9pj6-7w5j Denial of Service in Google GuavaGHSA-3p8m-j85q-pgmj Netty's decoders vulnerable to DoS via zip bomb style attackGHSA-558v-64gr-wgg4 Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread HangGHSA-9vjp-v76f-g363 SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary wayGHSA-grg4-wf29-r9vv Bzip2Decoder doesn't allow setting size restrictions for decompressed dataGHSA-mj4r-2hfc-f8p6 Netty Lz4FrameDecoder is vulnerable to resource exhaustion GHSA-269q-hmxg-m83q Local Information Disclosure Vulnerability in io.netty:netty-codec-httpGHSA-38f8-5428-x5cv Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-EncodingGHSA-4mp9-239f-g9hg Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validationGHSA-57rv-r2g8-2cj3 Netty has HttpClientCodec response desynchronizationGHSA-5jpm-x58v-624v Netty's HttpPostRequestDecoder can OOMGHSA-5mcr-gq6c-3hq2 Local Information Disclosure Vulnerability in Netty on Unix-Like systemsGHSA-6cqp-g7gg-8hr5 Netty: Security Control Bypass via CORS Short-Circuit FailureGHSA-6jqx-86gh-f27w Netty SPDY SETTINGS frame count materializes unbounded settings mapGHSA-84h7-rjj3-6jx4 Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoderGHSA-f6hv-jmp6-3vwv Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoSGHSA-gcjf-9mgh-3p7g Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoderGHSA-hvcg-qmg6-jm4c Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permittedCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.