Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.Packages you depend on that have known security holes (CVEs).
CVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2023-6378 logback: serialization vulnerability in logback receiverCVE-2023-6378 logback: serialization vulnerability in logback receiverCVE-2021-42550 logback: remote code execution through JNDI call from within its configuration fileCVE-2024-12798 logback-core: arbitrary code execution via JaninoEventEvaluatorCVE-2025-11226 ch.qos.logback/logback-core: Conditional abitrary code execution in logback-coreCVE-2025-22235 org.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposedCVE-2026-40973 Spring Boot: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directoryCVE-2023-20883 spring-boot: Spring Boot Welcome Page DoS VulnerabilityCVE-2022-22970 springframework: DoS via data binding to multipartFile or servlet partCVE-2022-22968 Framework: Data Binding Rules VulnerabilityCVE-2024-38820 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...CVE-2025-41249 org.springframework/spring-core: Spring Framework Annotation Detection VulnerabilityCVE-2021-22060 springframework: Additional Log Injection in Spring Framework (follow-up to CVE-2021-22096)CVE-2021-22096 springframework: malicious input leads to insertion of additional log entriesCVE-2023-20863 springframework: Spring Expression DoS VulnerabilityCVE-2026-41850 spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressionsCVE-2022-22950 spring-expression: Denial of service via specially crafted SpEL expressionCVE-2023-20861 springframework: Spring Expression DoS VulnerabilityCVE-2024-38808 spring-expression: Denial of service when processing a specially crafted Spring Expression Language expressionCVE-2026-41851 Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluationCVE-2022-1471 SnakeYaml: Constructor Deserialization Remote Code ExecutionCVE-2022-25857 snakeyaml: Denial of Service due to missing nested depth limitation for collectionsCVE-2022-38749 snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNodeCVE-2022-38750 snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObjectYour dependencies cross-checked against the OSV vulnerability database.
Nothing found by this check. ✓
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.