gitsafehub
github.com/jart/es ↗

jart/es

scanned 2026-08-01 · git 93a7383
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets1Vulnerable dependenciesKnown OSS vulnerabilities348Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 1 found

API keys, passwords or tokens committed into the repo.

  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    web/src/main/resources/resources.properties:69
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy timed out

Packages you depend on that have known security holes (CVEs).

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Trivy v0.70.0 · Apache-2.0

error: timeout after 120s

Known OSS vulnerabilities — OSV-Scanner 348 found · 68 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GHSA-fjq5-5j5f-mvxh Deserialization of Untrusted Data in Apache commons collections
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/codegen/pom.xml
    A package you depend on has a known security hole (CVE-2015-7501). Fix: Update that package to its patched version.
  • Serious GHSA-8vhq-qq4p-grq3 OS Command Injection in Plexus-utils
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/codegen/pom.xml
    A package you depend on has a known security hole (CVE-2017-1000487). Fix: Update that package to its patched version.
  • Serious GHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted Data
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2017-5929). Fix: Update that package to its patched version.
  • Serious GHSA-jm7w-5684-pvh8 FASTJSON Includes Functionality from Untrusted Control Sphere
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2025-70974). Fix: Update that package to its patched version.
  • Serious GHSA-xjrr-xv9m-4pw5 Improper Input Validation in alilibaba:fastjson
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2017-18349). Fix: Update that package to its patched version.
  • Serious GHSA-45hx-wfhj-473x Arbitrary code execution in H2 Console
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2022-23221). Fix: Update that package to its patched version.
  • Serious GHSA-h376-j262-vhq6 RCE in H2 Console
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2021-42392). Fix: Update that package to its patched version.
  • Serious GHSA-7x9j-7223-rg5m Improper Access Control in commons-fileupload
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000031). Fix: Update that package to its patched version.
  • Serious GHSA-hwj3-m3p6-hj38 dom4j allows External Entities by default which might enable XXE attacks
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2020-10683). Fix: Update that package to its patched version.
  • Serious GHSA-fjq5-5j5f-mvxh Deserialization of Untrusted Data in Apache commons collections
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2015-7501). Fix: Update that package to its patched version.
  • Serious GHSA-26gr-cvq3-qxgf Improper Authentication in Apache Shiro
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2020-1957). Fix: Update that package to its patched version.
  • Serious GHSA-45x9-q6vj-cqgq Apache Shiro Authentication Bypass vulnerability
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2022-40664). Fix: Update that package to its patched version.
  • Serious GHSA-4cf5-xmhp-3xj7 Improper Authorization in Apache Shiro
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2022-32532). Fix: Update that package to its patched version.
  • Serious GHSA-72w9-fcj5-3fcg Improper Authentication in Apache Shiro
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2020-11989). Fix: Update that package to its patched version.
  • Serious GHSA-f6jp-j6w3-w9hm Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2021-41303). Fix: Update that package to its patched version.
  • Serious GHSA-p836-389h-j692 Improper Access Control in Apache Shiro
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2016-4437). Fix: Update that package to its patched version.
  • Serious GHSA-7cj4-gj8m-m2f7 Authentication bypass in Apache Shiro
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2020-17510). Fix: Update that package to its patched version.
  • Serious GHSA-v98j-7crc-wvrj Authentication bypass in Apache Shiro
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2020-17523). Fix: Update that package to its patched version.
  • Serious GHSA-pmhc-2g4f-85cg Path Traversal in Apache Shiro
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2023-34478). Fix: Update that package to its patched version.
  • Serious GHSA-v98j-7crc-wvrj Authentication bypass in Apache Shiro
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2020-17523). Fix: Update that package to its patched version.
  • Serious GHSA-6x9x-8qw9-9pp6 Jetty vulnerable to authorization bypass due to inconsistent HTTP request handling (HTTP Request Smuggling)
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2017-7658). Fix: Update that package to its patched version.
  • Serious GHSA-vgg8-72f2-qm23 Critical severity vulnerability that affects org.eclipse.jetty:jetty-server
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2017-7657). Fix: Update that package to its patched version.
  • Serious GHSA-4wrc-f8pq-fpqp Pivotal Spring Framework contains unsafe Java deserialization methods
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000027). Fix: Update that package to its patched version.
  • Serious GHSA-36p3-wjmg-h94x Remote Code Execution in Spring Framework
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/common/pom.xml
    A package you depend on has a known security hole (CVE-2022-22965). Fix: Update that package to its patched version.
  • Serious GHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted Data
    /workdirs/scan-4dd6bdaf-930e-4816-b302-297fa0822969/parent/pom.xml
    A package you depend on has a known security hole (CVE-2017-5929). Fix: Update that package to its patched version.
… 323 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.