gitsafehub
github.com/jxs/polaris ↗

jxs/polaris

scanned 2026-08-13 · git 02ba4e3
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies42Known OSS vulnerabilities65Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 42 found · 11 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2021-28305 An issue was discovered in the diesel crate before 1.4.6 for Rust. The ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2021-28305). Fix: Update that package to its patched version.
  • Serious CVE-2020-35863 An issue was discovered in the hyper crate before 0.12.34 for Rust. HT ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35863). Fix: Update that package to its patched version.
  • Serious CVE-2019-16138 Use after free in image
    Cargo.lock
    A package you depend on has a known security hole (CVE-2019-16138). Fix: Update that package to its patched version.
  • Serious CVE-2020-25573 An issue was discovered in the linked-hash-map crate before 0.5.3 for ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-25573). Fix: Update that package to its patched version.
  • Serious CVE-2020-35866 Data races in rusqlite
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35866). Fix: Update that package to its patched version.
  • Serious CVE-2020-35867 Data races in rusqlite
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35867). Fix: Update that package to its patched version.
  • Serious CVE-2020-35868 Data races in rusqlite
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35868). Fix: Update that package to its patched version.
  • Serious CVE-2020-35869 Mishandling of format strings in rusqlite
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35869). Fix: Update that package to its patched version.
  • Serious CVE-2020-35870 Use after free in rusqlite
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35870). Fix: Update that package to its patched version.
  • Serious CVE-2020-35872 Improper type usage in rusqlite
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35872). Fix: Update that package to its patched version.
  • Serious CVE-2020-35873 Use after free in rusqlite
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35873). Fix: Update that package to its patched version.
  • Worth fixing CVE-2017-18589 Improper Input Validation in cookie
    Cargo.lock
    A package you depend on has a known security hole (CVE-2017-18589). Fix: Update that package to its patched version.
  • Worth fixing GHSA-h5x4-m2qf-r4f2 Diesel's SQLite backend has possible UTF-8 corruption
    Cargo.lock
    A package you depend on has a known security hole (GHSA-h5x4-m2qf-r4f2). Fix: Update that package to its patched version.
  • Worth fixing GHSA-wq9x-qwcq-mmgf Diesel vulnerable to Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts
    Cargo.lock
    A package you depend on has a known security hole (GHSA-wq9x-qwcq-mmgf). Fix: Update that package to its patched version.
  • Worth fixing GHSA-ggxf-9f6j-w742 Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`
    Cargo.lock
    A package you depend on has a known security hole (GHSA-ggxf-9f6j-w742). Fix: Update that package to its patched version.
  • Worth fixing GHSA-m9p2-fxp5-v3fp Diesel: Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`
    Cargo.lock
    A package you depend on has a known security hole (GHSA-m9p2-fxp5-v3fp). Fix: Update that package to its patched version.
  • Worth fixing GHSA-q8x8-jrhj-fh9p Diesel: Possible unaligned data access for implementations of `SqliteAggregate`
    Cargo.lock
    A package you depend on has a known security hole (GHSA-q8x8-jrhj-fh9p). Fix: Update that package to its patched version.
  • Worth fixing GHSA-f67m-9j94-qv9j Parser creates invalid uninitialized value
    Cargo.lock
    A package you depend on has a known security hole (GHSA-f67m-9j94-qv9j). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-32714 hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32714). Fix: Update that package to its patched version.
  • Worth fixing GHSA-f67m-9j94-qv9j Parser creates invalid uninitialized value
    Cargo.lock
    A package you depend on has a known security hole (GHSA-f67m-9j94-qv9j). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-32714 hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32714). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-12224 idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded
    Cargo.lock
    A package you depend on has a known security hole (CVE-2024-12224). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-35916 An issue was discovered in the image crate before 0.23.12 for Rust. A ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35916). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-35737 sqlite: an array-bounds overflow if billions of bytes are used in a string argument to a C API
    Cargo.lock
    A package you depend on has a known security hole (CVE-2022-35737). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-35919 An issue was discovered in the net2 crate before 0.2.36 for Rust. It h ...
    Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35919). Fix: Update that package to its patched version.
… 17 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 65 found · 9 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious RUSTSEC-2021-0037 Fix a use-after-free bug in diesels Sqlite backend
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-28305). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2019-0036 Type confusion if __private_get_type_id__ is overridden
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2019-25010). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2021-0079 Integer overflow in `hyper`'s parsing of the `Transfer-Encoding` header leads to data loss
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32714). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2020-0008 Flaw in hyper allows request smuggling by sending a body in GET requests
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35863). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2021-0079 Integer overflow in `hyper`'s parsing of the `Transfer-Encoding` header leads to data loss
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32714). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2019-0014 Flaw in interface may drop uninitialized instance of arbitrary types
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2019-16138). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2020-0026 linked-hash-map creates uninitialized NonNull pointer
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-25573). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2020-0014 Various memory safety issues
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35866). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2020-0027 traitobject assumes the layout of fat pointers
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35881). Fix: Update that package to its patched version.
  • Worth fixing GHSA-vjrq-cg9x-rfjp Improper Input Validation in cookie
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2017-18589). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2024-0365 Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2026-0111 Possible UTF-8 corruption in Diesels SQLite backend
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2026-0136 Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2026-0137 Possible unaligned data access for implementations of `SqliteAggregate`
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2026-0172 Possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2021-0078 Lenient `hyper` header parsing of `Content-Length` could allow request smuggling
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32715). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2021-0078 Lenient `hyper` header parsing of `Content-Length` could allow request smuggling
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32715). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2024-0421 `idna` accepts Punycode labels that do not produce any non-ASCII when decoded
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2024-12224). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2020-0073 Mutable reference with immutable provenance
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35916). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2022-0090 `libsqlite3-sys` via C SQLite CVE-2022-35737
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2022-35737). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2020-0080 `miow` invalidly assumes the memory layout of std::net::SocketAddr
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35921). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2020-0078 `net2` invalidly assumes the memory layout of std::net::SocketAddr
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35919). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2024-0357 `MemBio::get_buf` has undefined behavior with empty buffers
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-xp3w-r5p5-63rr rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-42327). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2022-0013 Regexes with large repetitions on empty sub-expressions take a very long time to parse
    /workdirs/scan-fcd7dcfa-f040-442a-8eb7-febafd3210c1/Cargo.lock
    A package you depend on has a known security hole (CVE-2022-24713). Fix: Update that package to its patched version.
… 40 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.