Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
aws-access-token Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.aws-access-token Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.aws-access-token Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.aws-access-token Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.aws-access-token Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.aws-access-token Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.Packages you depend on that have known security holes (CVEs).
GHSA-8gj8-hv75-gp94 `SegQueue` creates zero value of any typeGHSA-rwf4-gx62-rqfw `MsQueue` `push`/`pop` use the wrong orderingsGHSA-m4ch-rfv5-x5g3 git2-rs fails to verify SSH keys by defaultCVE-2024-12224 idna: idna accepts Punycode labels that do not produce any non-ASCII when decodedGHSA-22q8-ghmq-63vf libgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2GHSA-m4ch-rfv5-x5g3 git2-rs fails to verify SSH keys by defaultCVE-2020-35919 An issue was discovered in the net2 crate before 0.2.36 for Rust. It h ...CVE-2020-35920 An issue was discovered in the socket2 crate before 0.3.16 for Rust. I ...GHSA-q445-7m23-qrmw openssl's `MemBio::get_buf` has undefined behavior with empty buffersCVE-2022-24713 Mozilla: Denial of Service via complex regular expressionsCVE-2018-20990 Arbitrary file overwrite in tar-rsCVE-2021-38511 tar-crate: links in archive can create arbitrary directoriesCVE-2026-33055 tar-rs is a tar archive reading/writing library for Rust. Versions 0.4 ...CVE-2026-33056 tar-rs: tar-rs: Arbitrary directory permission modification via crafted tar archiveGHSA-3pv8-6f4r-ffg2 tar has a PAX header desynchronization issueGHSA-9hpw-r23r-xgm5 Data race in `Iter` and `IterMut`GHSA-j39j-6gw9-jw6h git2 has potential undefined behavior when dereferencing Buf struct CVE-2026-41677 rust-openssl provides OpenSSL bindings for the Rust programming langua ...Your dependencies cross-checked against the OSV vulnerability database.
GHSA-m4ch-rfv5-x5g3 git2-rs fails to verify SSH keys by defaultRUSTSEC-2024-0421 `idna` accepts Punycode labels that do not produce any non-ASCII when decodedRUSTSEC-2023-0003 git2 does not verify SSH keys by defaultRUSTSEC-2024-0013 Memory corruption, denial of service, and arbitrary code execution in libgit2RUSTSEC-2020-0080 `miow` invalidly assumes the memory layout of std::net::SocketAddrRUSTSEC-2020-0078 `net2` invalidly assumes the memory layout of std::net::SocketAddrRUSTSEC-2024-0357 `MemBio::get_buf` has undefined behavior with empty buffersRUSTSEC-2022-0013 Regexes with large repetitions on empty sub-expressions take a very long time to parseRUSTSEC-2018-0002 Links in archives can overwrite any existing fileRUSTSEC-2021-0080 Links in archive can create arbitrary directoriesRUSTSEC-2026-0067 `unpack_in` can chmod arbitrary directories by following symlinksRUSTSEC-2026-0068 tar-rs incorrectly ignores PAX size headers if header size is nonzeroRUSTSEC-2026-0008 Potential undefined behavior when dereferencing Buf structGHSA-xmgf-hq76-4vx2 rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized lengthRUSTSEC-2022-0020 `SegQueue` creates zero value of any typeRUSTSEC-2022-0029 `MsQueue` `push`/`pop` use the wrong orderingsRUSTSEC-2025-0121 gcc crate is unmaintainedRUSTSEC-2026-0183 Potential undefined behavior when calling Remote::list()RUSTSEC-2026-0184 Potential undefined behavior with Signature from a buffer-created BlameHunkRUSTSEC-2020-0016 `net2` crate has been deprecated; use `socket2` insteadRUSTSEC-2023-0022 `openssl` `X509NameBuilder::build` returned object is not thread safeRUSTSEC-2023-0023 `openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file readRUSTSEC-2023-0024 `openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereferenceRUSTSEC-2023-0044 `openssl` `X509VerifyParamRef::set_host` buffer over-readRUSTSEC-2023-0072 `openssl` `X509StoreRef::objects` is unsoundCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.