gitsafehub
github.com/junrushao/mxnet ↗

junrushao/mxnet

scanned 2026-08-08 · git c2bbde7
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies154Known OSS vulnerabilities154Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 120s

Vulnerable dependencies — Trivy 154 found · 15 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2019-20477 PyYAML: command execution through python/object/apply constructor in FullLoader
    cd/utils/requirements.txt
    A package you depend on has a known security hole (CVE-2019-20477). Fix: Update that package to its patched version.
  • Serious CVE-2020-14343 PyYAML: incomplete fix for CVE-2020-1747
    cd/utils/requirements.txt
    A package you depend on has a known security hole (CVE-2020-14343). Fix: Update that package to its patched version.
  • Serious CVE-2020-1747 PyYAML: arbitrary command execution through python/object/new when FullLoader is used
    cd/utils/requirements.txt
    A package you depend on has a known security hole (CVE-2020-1747). Fix: Update that package to its patched version.
  • Serious CVE-2026-54906 concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Synchronization flaw in ReadWriteLock allows unauthorized lock release and denial of service
    docs/static_site/src/Gemfile.lock
    A package you depend on has a known security hole (CVE-2026-54906). Fix: Update that package to its patched version.
  • Serious CVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution
    docs/static_site/src/Gemfile.lock
    A package you depend on has a known security hole (CVE-2020-14001). Fix: Update that package to its patched version.
  • Serious CVE-2021-28834 rubygem-kramdown: allows arbitrary classes to be instantiated
    docs/static_site/src/Gemfile.lock
    A package you depend on has a known security hole (CVE-2021-28834). Fix: Update that package to its patched version.
  • Serious CVE-2020-11538 python-pillow: out-of-bounds reads/writes in the parsing of SGI image files in expandrow/expandrow2
    example/gluon/lipnet/requirements.txt
    A package you depend on has a known security hole (CVE-2020-11538). Fix: Update that package to its patched version.
  • Serious CVE-2020-5310 python-pillow: Integer overflow leading to buffer overflow in ImagingLibTiffDecode
    example/gluon/lipnet/requirements.txt
    A package you depend on has a known security hole (CVE-2020-5310). Fix: Update that package to its patched version.
  • Serious CVE-2020-5311 python-pillow: out-of-bounds write in expandrow in libImaging/SgiRleDecode.c
    example/gluon/lipnet/requirements.txt
    A package you depend on has a known security hole (CVE-2020-5311). Fix: Update that package to its patched version.
  • Serious CVE-2020-5312 python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.c
    example/gluon/lipnet/requirements.txt
    A package you depend on has a known security hole (CVE-2020-5312). Fix: Update that package to its patched version.
  • Serious CVE-2021-25289 python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c
    example/gluon/lipnet/requirements.txt
    A package you depend on has a known security hole (CVE-2021-25289). Fix: Update that package to its patched version.
  • Serious CVE-2021-34552 python-pillow: Buffer overflow in image convert function
    example/gluon/lipnet/requirements.txt
    A package you depend on has a known security hole (CVE-2021-34552). Fix: Update that package to its patched version.
  • Serious CVE-2022-22817 python-pillow: PIL.ImageMath.eval allows evaluation of arbitrary expressions
    example/gluon/lipnet/requirements.txt
    A package you depend on has a known security hole (CVE-2022-22817). Fix: Update that package to its patched version.
  • Serious CVE-2023-50447 pillow: Arbitrary Code Execution via the environment parameter
    example/gluon/lipnet/requirements.txt
    A package you depend on has a known security hole (CVE-2023-50447). Fix: Update that package to its patched version.
  • Serious CVE-2021-23792 The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 ar ...
    scala-package/examples/pom.xml
    A package you depend on has a known security hole (CVE-2021-23792). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-32740 rubygem-addressable: ReDoS in templates
    docs/static_site/src/Gemfile.lock
    A package you depend on has a known security hole (CVE-2021-32740). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-35611 addressable: Addressable: Denial of Service via crafted URI templates
    docs/static_site/src/Gemfile.lock
    A package you depend on has a known security hole (CVE-2026-35611). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54904 concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Denial of Service due to infinite loop in AtomicReference#update
    docs/static_site/src/Gemfile.lock
    A package you depend on has a known security hole (CVE-2026-54904). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54905 concurrent-ruby: Concurrent-ruby: Incorrect write lock granting leading to broken mutual exclusion
    docs/static_site/src/Gemfile.lock
    A package you depend on has a known security hole (CVE-2026-54905). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-26298 rubygem-redcarpet: does not escape HTML when processing quotes which could result in XSS vulnerability
    docs/static_site/src/Gemfile.lock
    A package you depend on has a known security hole (CVE-2020-26298). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-31163 rubygem-tzinfo: arbitrary code execution
    docs/static_site/src/Gemfile.lock
    A package you depend on has a known security hole (CVE-2022-31163). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-16865 python-pillow: reading specially crafted image files leads to allocation of large amounts of memory and denial of service
    example/gluon/lipnet/requirements.txt
    A package you depend on has a known security hole (CVE-2019-16865). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-19911 python-pillow: uncontrolled resource consumption in FpxImagePlugin.py
    example/gluon/lipnet/requirements.txt
    A package you depend on has a known security hole (CVE-2019-19911). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-10177 python-pillow: multiple out-of-bounds reads in libImaging/FliDecode.c
    example/gluon/lipnet/requirements.txt
    A package you depend on has a known security hole (CVE-2020-10177). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-10378 python-pillow: an out-of-bounds read in libImaging/PcxDecode.c can occur when reading PCX files
    example/gluon/lipnet/requirements.txt
    A package you depend on has a known security hole (CVE-2020-10378). Fix: Update that package to its patched version.
… 129 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 154 found · 26 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GHSA-52p9-v744-mwjj Remote code execution in Kramdown
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/docs/static_site/src/Gemfile.lock
    A package you depend on has a known security hole (CVE-2021-28834). Fix: Update that package to its patched version.
  • Serious GHSA-mqm2-cgpr-p4m6 Unintended read access in kramdown gem
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/docs/static_site/src/Gemfile.lock
    A package you depend on has a known security hole (CVE-2020-14001). Fix: Update that package to its patched version.
  • Serious GHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerability
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/assembly/pom.xml
    A package you depend on has a known security hole (CVE-2021-45046). Fix: Update that package to its patched version.
  • Serious GHSA-jfh8-c2jp-5v3q Remote code injection in Log4j
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/assembly/pom.xml
    A package you depend on has a known security hole (CVE-2021-44228). Fix: Update that package to its patched version.
  • Serious GHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerability
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/core/pom.xml
    A package you depend on has a known security hole (CVE-2021-45046). Fix: Update that package to its patched version.
  • Serious GHSA-jfh8-c2jp-5v3q Remote code injection in Log4j
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/core/pom.xml
    A package you depend on has a known security hole (CVE-2021-44228). Fix: Update that package to its patched version.
  • Serious GHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerability
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/deploy/pom.xml
    A package you depend on has a known security hole (CVE-2021-45046). Fix: Update that package to its patched version.
  • Serious GHSA-jfh8-c2jp-5v3q Remote code injection in Log4j
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/deploy/pom.xml
    A package you depend on has a known security hole (CVE-2021-44228). Fix: Update that package to its patched version.
  • Serious GHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerability
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/examples/pom.xml
    A package you depend on has a known security hole (CVE-2021-45046). Fix: Update that package to its patched version.
  • Serious GHSA-jfh8-c2jp-5v3q Remote code injection in Log4j
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/examples/pom.xml
    A package you depend on has a known security hole (CVE-2021-44228). Fix: Update that package to its patched version.
  • Serious GHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerability
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/externalPom/pom.xml
    A package you depend on has a known security hole (CVE-2021-45046). Fix: Update that package to its patched version.
  • Serious GHSA-jfh8-c2jp-5v3q Remote code injection in Log4j
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/externalPom/pom.xml
    A package you depend on has a known security hole (CVE-2021-44228). Fix: Update that package to its patched version.
  • Serious GHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerability
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/infer/pom.xml
    A package you depend on has a known security hole (CVE-2021-45046). Fix: Update that package to its patched version.
  • Serious GHSA-jfh8-c2jp-5v3q Remote code injection in Log4j
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/infer/pom.xml
    A package you depend on has a known security hole (CVE-2021-44228). Fix: Update that package to its patched version.
  • Serious GHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerability
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/init-native/pom.xml
    A package you depend on has a known security hole (CVE-2021-45046). Fix: Update that package to its patched version.
  • Serious GHSA-jfh8-c2jp-5v3q Remote code injection in Log4j
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/init-native/pom.xml
    A package you depend on has a known security hole (CVE-2021-44228). Fix: Update that package to its patched version.
  • Serious GHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerability
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/init/pom.xml
    A package you depend on has a known security hole (CVE-2021-45046). Fix: Update that package to its patched version.
  • Serious GHSA-jfh8-c2jp-5v3q Remote code injection in Log4j
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/init/pom.xml
    A package you depend on has a known security hole (CVE-2021-44228). Fix: Update that package to its patched version.
  • Serious GHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerability
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/macros/pom.xml
    A package you depend on has a known security hole (CVE-2021-45046). Fix: Update that package to its patched version.
  • Serious GHSA-jfh8-c2jp-5v3q Remote code injection in Log4j
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/macros/pom.xml
    A package you depend on has a known security hole (CVE-2021-44228). Fix: Update that package to its patched version.
  • Serious GHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerability
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/native/pom.xml
    A package you depend on has a known security hole (CVE-2021-45046). Fix: Update that package to its patched version.
  • Serious GHSA-jfh8-c2jp-5v3q Remote code injection in Log4j
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/native/pom.xml
    A package you depend on has a known security hole (CVE-2021-44228). Fix: Update that package to its patched version.
  • Serious GHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerability
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/pom.xml
    A package you depend on has a known security hole (CVE-2021-45046). Fix: Update that package to its patched version.
  • Serious GHSA-jfh8-c2jp-5v3q Remote code injection in Log4j
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/pom.xml
    A package you depend on has a known security hole (CVE-2021-44228). Fix: Update that package to its patched version.
  • Serious GHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerability
    /workdirs/scan-67b0b025-45d3-4045-ac55-8d969bf0b2e0/scala-package/spark/pom.xml
    A package you depend on has a known security hole (CVE-2021-45046). Fix: Update that package to its patched version.
… 129 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.