Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.gcp-api-key Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.gcp-api-key Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.gcp-api-key Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.gcp-api-key Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.gcp-api-key Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches.Packages you depend on that have known security holes (CVEs).
CVE-2022-25648 ruby-git: package vulnerable to Command Injection via git argument injectionCVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code executionCVE-2021-28834 rubygem-kramdown: allows arbitrary classes to be instantiatedCVE-2021-32740 rubygem-addressable: ReDoS in templatesCVE-2026-35611 addressable: Addressable: Denial of Service via crafted URI templatesCVE-2026-54297 faraday: Faraday: Denial of Service via crafted nested query stringsCVE-2026-25765 Faraday: Faraday: Server-Side Request Forgery via protocol-relative URLsCVE-2022-47318 ruby-git: code injection vulnerabilityCVE-2022-46648 ruby-git: code injection vulnerabilityYour dependencies cross-checked against the OSV vulnerability database.
GHSA-69p6-wvmq-27gg Command injection in ruby-gitGHSA-52p9-v744-mwjj Remote code execution in KramdownGHSA-mqm2-cgpr-p4m6 Unintended read access in kramdown gemGHSA-h27x-rffw-24p4 Addressable has a Regular Expression Denial of Service in Addressable templatesGHSA-jxhc-q857-3j6g Regular Expression Denial of Service in Addressable templatesGHSA-pfpr-3463-c6jh ruby-git has potential remote code execution vulnerabilityGHSA-pphf-gfrm-v32r Code injection in ruby gitCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.