Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-2700 quarkus-core: Leak of local configuration properties into Quarkus applicationsCVE-2023-2974 quarkus-core: TLS protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported TLS protocolCVE-2020-15170 Potential access control security issue in apollo-adminserviceCVE-2022-1471 SnakeYaml: Constructor Deserialization Remote Code ExecutionCVE-2022-25857 snakeyaml: Denial of Service due to missing nested depth limitation for collectionsCVE-2022-38749 snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNodeCVE-2022-38750 snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObjectCVE-2022-38751 snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.matchCVE-2022-38752 snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCodeCVE-2022-41854 dev-java/snakeyaml: DoS via stack overflowCVE-2020-15170 Potential access control security issue in apollo-adminserviceCVE-2022-1471 SnakeYaml: Constructor Deserialization Remote Code ExecutionCVE-2022-25857 snakeyaml: Denial of Service due to missing nested depth limitation for collectionsCVE-2022-38749 snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNodeCVE-2022-38750 snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObjectCVE-2022-38751 snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.matchCVE-2022-38752 snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCodeCVE-2022-41854 dev-java/snakeyaml: DoS via stack overflowYour dependencies cross-checked against the OSV vulnerability database.
GHSA-xpmx-h7xq-xffh Potential access control security issue in apollo-adminserviceGHSA-4jrv-ppp4-jm57 Deserialization of Untrusted Data in GsonGHSA-7g45-4rm6-3mm3 Guava vulnerable to insecure use of temporary directoryGHSA-3fhx-3vvg-2j84 quarkus-core vulnerable to client driven TLS cipher downgradingGHSA-f8h5-v2vg-46rr quarkus-core leaks local environment variables from Quarkus namespace during application's buildGHSA-3mc7-4q67-w48m Uncontrolled Resource Consumption in snakeyamlGHSA-98wm-3w3q-mw94 snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds WriteGHSA-9w3m-gqgf-c4p9 snakeYAML before 1.32 vulnerable to Denial of Service due to Out-of-bounds WriteGHSA-c4r9-r8fh-9vj2 snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds WriteGHSA-hhhw-99gj-p3c3 snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds WriteGHSA-mjmj-j48q-9wg2 SnakeYaml Constructor Deserialization Remote Code ExecutionGHSA-w37g-rhq8-7m4j Snakeyaml vulnerable to Stack overflow leading to denial of serviceGHSA-5mg8-w23w-74h3 Information Disclosure in GuavaCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.