gitsafehub
github.com/honnix/renovate ↗

honnix/renovate

scanned 2026-08-15 · git a20fa18
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 3 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies284Known OSS vulnerabilities709Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 400s

Vulnerable dependencies — Trivy 284 found · 7 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2022-26945 go-getter: command injection vulnerability
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2022-26945). Fix: Update that package to its patched version.
  • Serious CVE-2026-33937 handlebars.js: Handlebars: Remote Code Execution via crafted Abstract Syntax Tree object in compile()
    yarn.lock
    A package you depend on has a known security hole (CVE-2026-33937). Fix: Update that package to its patched version.
  • Serious CVE-2021-44906 minimist: prototype pollution
    yarn.lock
    A package you depend on has a known security hole (CVE-2021-44906). Fix: Update that package to its patched version.
  • Serious CVE-2022-2216 Server-Side Request Forgery in parse-url
    yarn.lock
    A package you depend on has a known security hole (CVE-2022-2216). Fix: Update that package to its patched version.
  • Serious CVE-2022-2900 Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url
    yarn.lock
    A package you depend on has a known security hole (CVE-2022-2900). Fix: Update that package to its patched version.
  • Serious CVE-2022-25860 Remote code execution in simple-git
    yarn.lock
    A package you depend on has a known security hole (CVE-2022-25860). Fix: Update that package to its patched version.
  • Serious CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb
    yarn.lock
    A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-8911 aws/aws-sdk-go: CBC padding oracle issue in AWS S3 Crypto SDK for golang
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2020-8911). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-2582 The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext along ...
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2022-2582). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-30321 go-getter: unsafe download (issue 1 of 3)
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2022-30321). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-30322 go-getter: unsafe download (issue 2 of 3)
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2022-30322). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-30323 go-getter: unsafe download (issue 3 of 3)
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2022-30323). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-6257 hashicorp/go-getter: Arbitrary command execution through local git config file
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2024-6257). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-8959 github.com/hashicorp/go-getter: HashiCorp go-getter Arbitrary File Read
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2025-8959). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-4660 go-getter: go-getter: Arbitrary file reads via maliciously crafted URL
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2026-4660). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-29810 go-getter: writes SSH credentials into logfile, exposing sensitive credentials to local uses
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2022-29810). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-0475 go-getter: go-getter vulnerable to denial of service via malicious compressed archive
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2023-0475). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-65637 github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2025-65637). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-29482 ulikunitz/xz: Infinite loop in readUvarint allows for denial of service
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2021-29482). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-58058 github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2025-58058). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-29652 golang: crypto/ssh: crafted authentication request can lead to nil pointer dereference
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2020-29652). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-7919 golang: Integer overflow on 32bit architectures via crafted certificate allows for denial of service
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2020-7919). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-9283 golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2020-9283). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-43565 golang.org/x/crypto: empty plaintext packet causes panic
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2021-43565). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-27191 golang: crash in a golang.org/x/crypto/ssh server
    lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2022-27191). Fix: Update that package to its patched version.
… 259 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 709 found · 59 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GO-2022-0586 Resource exhaustion in github.com/hashicorp/go-getter and related modules
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2022-26945). Fix: Update that package to its patched version.
  • Serious GO-2024-3321 Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2024-45337). Fix: Update that package to its patched version.
  • Serious GO-2026-5005 Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2026-39833). Fix: Update that package to its patched version.
  • Serious GO-2026-5006 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2026-39832). Fix: Update that package to its patched version.
  • Serious GO-2026-5017 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2026-39830). Fix: Update that package to its patched version.
  • Serious GO-2026-5019 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2026-39831). Fix: Update that package to its patched version.
  • Serious GO-2026-5020 Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2026-39834). Fix: Update that package to its patched version.
  • Serious GO-2026-5021 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2026-42508). Fix: Update that package to its patched version.
  • Serious GO-2026-5023 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/2/go.mod
    A package you depend on has a known security hole (CVE-2026-46595). Fix: Update that package to its patched version.
  • Serious GO-2024-3321 Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/3/go.mod
    A package you depend on has a known security hole (CVE-2024-45337). Fix: Update that package to its patched version.
  • Serious GO-2026-5005 Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/3/go.mod
    A package you depend on has a known security hole (CVE-2026-39833). Fix: Update that package to its patched version.
  • Serious GO-2026-5006 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/3/go.mod
    A package you depend on has a known security hole (CVE-2026-39832). Fix: Update that package to its patched version.
  • Serious GO-2026-5017 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/3/go.mod
    A package you depend on has a known security hole (CVE-2026-39830). Fix: Update that package to its patched version.
  • Serious GO-2026-5019 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/3/go.mod
    A package you depend on has a known security hole (CVE-2026-39831). Fix: Update that package to its patched version.
  • Serious GO-2026-5020 Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/3/go.mod
    A package you depend on has a known security hole (CVE-2026-39834). Fix: Update that package to its patched version.
  • Serious GO-2026-5021 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/3/go.mod
    A package you depend on has a known security hole (CVE-2026-42508). Fix: Update that package to its patched version.
  • Serious GO-2026-5023 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/3/go.mod
    A package you depend on has a known security hole (CVE-2026-46595). Fix: Update that package to its patched version.
  • Serious GO-2026-4762 Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/gomod/__fixtures__/3/go.mod
    A package you depend on has a known security hole (CVE-2026-33186). Fix: Update that package to its patched version.
  • Serious MAL-2025-41763 Malicious code in some-other-package (PyPI)
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/pip_requirements/__fixtures__/requirements1.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious PYSEC-2012-2 The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/pip_requirements/__fixtures__/requirements2.txt
    A package you depend on has a known security hole (CVE-2012-3442). Fix: Update that package to its patched version.
  • Serious PYSEC-2014-1 The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Pytho
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/pip_requirements/__fixtures__/requirements2.txt
    A package you depend on has a known security hole (CVE-2014-0472). Fix: Update that package to its patched version.
  • Serious PYSEC-2014-3 The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properl
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/pip_requirements/__fixtures__/requirements2.txt
    A package you depend on has a known security hole (CVE-2014-0474). Fix: Update that package to its patched version.
  • Serious PYSEC-2019-16 Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/pip_requirements/__fixtures__/requirements2.txt
    A package you depend on has a known security hole (CVE-2019-19844). Fix: Update that package to its patched version.
  • Serious GHSA-frmv-pr5f-9mcr Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/pip_requirements/__fixtures__/requirements2.txt
    A package you depend on has a known security hole (CVE-2025-64459). Fix: Update that package to its patched version.
  • Serious GHSA-hmr4-m2h5-33qx SQL injection in Django
    /workdirs/scan-15417291-0f13-42b0-a101-989c75cc1a20/lib/manager/pip_requirements/__fixtures__/requirements2.txt
    A package you depend on has a known security hole (CVE-2020-7471). Fix: Update that package to its patched version.
… 684 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: npm:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.