gitsafehub
github.com/jamesob/zola ↗

jamesob/zola

scanned 2026-08-12 · git 7fcb9c5
3 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets3Vulnerable dependencies63Known OSS vulnerabilities90Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 3 found · 3 serious

API keys, passwords or tokens committed into the repo.

  • Serious curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
    docs/content/documentation/deployment/netlify.md:63
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
    docs/content/documentation/deployment/netlify.md:58
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
    docs/content/documentation/deployment/netlify.md:58
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 63 found · 16 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2018-25024 Out-of-bounds Write in actix-web
    Cargo.lock
    A package you depend on has a known security hole (CVE-2018-25024). Fix: Update that package to its patched version.
  • Serious CVE-2018-25025 Out-of-bounds Write in actix-web
    Cargo.lock
    A package you depend on has a known security hole (CVE-2018-25025). Fix: Update that package to its patched version.
  • Serious CVE-2018-25026 Out-of-bounds Write in actix-web
    Cargo.lock
    A package you depend on has a known security hole (CVE-2018-25026). Fix: Update that package to its patched version.
  • Serious CVE-2021-32810 rust-crossbeam-deque: race condition may lead to double free
    Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32810). Fix: Update that package to its patched version.
  • Serious CVE-2021-32810 rust-crossbeam-deque: race condition may lead to double free
    Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32810). Fix: Update that package to its patched version.
  • Serious CVE-2019-25009 An issue was discovered in the http crate before 0.1.20 for Rust. The ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2019-25009). Fix: Update that package to its patched version.
  • Serious CVE-2020-35863 An issue was discovered in the hyper crate before 0.12.34 for Rust. HT ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35863). Fix: Update that package to its patched version.
  • Serious CVE-2019-16138 Use after free in image
    Cargo.lock
    A package you depend on has a known security hole (CVE-2019-16138). Fix: Update that package to its patched version.
  • Serious CVE-2019-15552 An issue was discovered in the libflate crate before 0.1.25 for Rust. ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2019-15552). Fix: Update that package to its patched version.
  • Serious CVE-2020-25573 An issue was discovered in the linked-hash-map crate before 0.5.3 for ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-25573). Fix: Update that package to its patched version.
  • Serious CVE-2020-25573 An issue was discovered in the linked-hash-map crate before 0.5.3 for ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-25573). Fix: Update that package to its patched version.
  • Serious CVE-2020-25576 An issue was discovered in the rand_core crate before 0.4.2 for Rust. ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-25576). Fix: Update that package to its patched version.
  • Serious CVE-2020-25576 An issue was discovered in the rand_core crate before 0.4.2 for Rust. ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-25576). Fix: Update that package to its patched version.
  • Serious CVE-2019-15551 An issue was discovered in the smallvec crate before 0.6.10 for Rust. ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2019-15551). Fix: Update that package to its patched version.
  • Serious CVE-2019-15554 An issue was discovered in the smallvec crate before 0.6.10 for Rust. ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2019-15554). Fix: Update that package to its patched version.
  • Serious CVE-2021-25900 An issue was discovered in the smallvec crate before 0.6.14 and 1.x be ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2021-25900). Fix: Update that package to its patched version.
  • Worth fixing GHSA-w65j-g6c7-g3m4 Multiple memory safety issues in actix-web
    Cargo.lock
    A package you depend on has a known security hole (GHSA-w65j-g6c7-g3m4). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-15542 Uncontrolled recursion in ammonia
    Cargo.lock
    A package you depend on has a known security hole (CVE-2019-15542). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-38193 An issue was discovered in the ammonia crate before 3.1.0 for Rust. XS ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2021-38193). Fix: Update that package to its patched version.
  • Worth fixing GHSA-9g55-pg62-m8hh Channel creates zero value of any type
    Cargo.lock
    A package you depend on has a known security hole (GHSA-9g55-pg62-m8hh). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-23639 crossbeam-utils provides atomics, synchronization primitives, scoped t ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2022-23639). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-23639 crossbeam-utils provides atomics, synchronization primitives, scoped t ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2022-23639). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-36465 An issue was discovered in the generic-array crate before 0.13.3 for R ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-36465). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-26964 An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occ ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2023-26964). Fix: Update that package to its patched version.
  • Worth fixing GHSA-8r5v-vm4m-4g25 Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
    Cargo.lock
    A package you depend on has a known security hole (GHSA-8r5v-vm4m-4g25). Fix: Update that package to its patched version.
… 38 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 90 found · 16 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious RUSTSEC-2018-0019 Multiple memory safety issues
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2018-25024). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2021-0093 Data race in crossbeam-deque
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32810). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2021-0093 Data race in crossbeam-deque
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32810). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2019-0036 Type confusion if __private_get_type_id__ is overridden
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2019-25010). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2019-0034 HeaderMap::Drain API is unsound
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2019-25009). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2020-0008 Flaw in hyper allows request smuggling by sending a body in GET requests
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35863). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2021-0079 Integer overflow in `hyper`'s parsing of the `Transfer-Encoding` header leads to data loss
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32714). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2019-0014 Flaw in interface may drop uninitialized instance of arbitrary types
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2019-16138). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2019-0010 MultiDecoder::read() drops uninitialized memory of arbitrary type on panic in client code
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2019-15552). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2020-0026 linked-hash-map creates uninitialized NonNull pointer
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-25573). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2020-0026 linked-hash-map creates uninitialized NonNull pointer
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-25573). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2019-0035 Unaligned memory access
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-25576). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2019-0035 Unaligned memory access
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-25576). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2019-0009 Double-free and use-after-free in SmallVec::grow()
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2019-15551). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2019-0012 Memory corruption in SmallVec::grow()
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2019-15554). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2021-0003 Buffer overflow in SmallVec::insert_many
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-25900). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2019-0001 Uncontrolled recursion leads to abort in HTML serialization
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2019-15542). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2021-0074 Incorrect handling of embedded SVG and MathML leads to mutation XSS
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-38193). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2022-0041 Unsoundness of AtomicCell<*64> arithmetics on 32-bit targets that support Atomic*64
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2022-23639). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2022-0041 Unsoundness of AtomicCell<*64> arithmetics on 32-bit targets that support Atomic*64
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2022-23639). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2020-0146 arr! macro erases lifetimes
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-36465). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2024-0332 Degradation of service in h2 servers with CONTINUATION Flood
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2019-0033 Integer Overflow in HeaderMap::reserve() can cause Denial of Service
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2019-25008). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2021-0020 Multiple Transfer-Encoding headers misinterprets request payload
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-21299). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2021-0078 Lenient `hyper` header parsing of `Content-Length` could allow request smuggling
    /workdirs/scan-8fc20d9b-176d-4960-8711-caaba16854e7/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32715). Fix: Update that package to its patched version.
… 65 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.