gitsafehub
github.com/llsourcell/how-to-generate-art-demo ↗

llsourcell/how-to-generate-art-demo

scanned 2026-07-16 · git b75f079
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies510Known OSS vulnerabilities560Risky code patternsMalicious dependenciesProject health10

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 510 found · 16 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2024-3660 A arbitrary code injection vulnerability in TensorFlow's Keras framewo ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-3660). Fix: Update that package to its patched version.
  • Serious CVE-2020-11538 python-pillow: out-of-bounds reads/writes in the parsing of SGI image files in expandrow/expandrow2
    requirements.txt
    A package you depend on has a known security hole (CVE-2020-11538). Fix: Update that package to its patched version.
  • Serious CVE-2020-5310 python-pillow: Integer overflow leading to buffer overflow in ImagingLibTiffDecode
    requirements.txt
    A package you depend on has a known security hole (CVE-2020-5310). Fix: Update that package to its patched version.
  • Serious CVE-2020-5311 python-pillow: out-of-bounds write in expandrow in libImaging/SgiRleDecode.c
    requirements.txt
    A package you depend on has a known security hole (CVE-2020-5311). Fix: Update that package to its patched version.
  • Serious CVE-2020-5312 python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.c
    requirements.txt
    A package you depend on has a known security hole (CVE-2020-5312). Fix: Update that package to its patched version.
  • Serious CVE-2021-25289 python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c
    requirements.txt
    A package you depend on has a known security hole (CVE-2021-25289). Fix: Update that package to its patched version.
  • Serious CVE-2021-34552 python-pillow: Buffer overflow in image convert function
    requirements.txt
    A package you depend on has a known security hole (CVE-2021-34552). Fix: Update that package to its patched version.
  • Serious CVE-2022-22817 python-pillow: PIL.ImageMath.eval allows evaluation of arbitrary expressions
    requirements.txt
    A package you depend on has a known security hole (CVE-2022-22817). Fix: Update that package to its patched version.
  • Serious CVE-2023-50447 pillow: Arbitrary Code Execution via the environment parameter
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-50447). Fix: Update that package to its patched version.
  • Serious CVE-2017-18342 PyYAML: yaml.load() API could execute arbitrary code
    requirements.txt
    A package you depend on has a known security hole (CVE-2017-18342). Fix: Update that package to its patched version.
  • Serious CVE-2020-14343 PyYAML: incomplete fix for CVE-2020-1747
    requirements.txt
    A package you depend on has a known security hole (CVE-2020-14343). Fix: Update that package to its patched version.
  • Serious CVE-2019-6446 numpy: crafted serialized object passed in numpy.load() in pickle python module allows arbitrary code execution
    requirements.txt
    A package you depend on has a known security hole (CVE-2019-6446). Fix: Update that package to its patched version.
  • Serious CVE-2018-7575 Integer Overflow or Wraparound in Google TensorFlow
    requirements.txt
    A package you depend on has a known security hole (CVE-2018-7575). Fix: Update that package to its patched version.
  • Serious CVE-2021-41208 Incomplete validation in boosted trees code
    requirements.txt
    A package you depend on has a known security hole (CVE-2021-41208). Fix: Update that package to its patched version.
  • Serious CVE-2023-25668 CVE-2023-25668 affecting package tensorflow for versions less than 2.11.1-1
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-25668). Fix: Update that package to its patched version.
  • Serious GHSA-h6gw-r52c-724r NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlow
    requirements.txt
    A package you depend on has a known security hole (GHSA-h6gw-r52c-724r). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-10906 python-jinja2: str.format_map allows sandbox escape
    requirements.txt
    A package you depend on has a known security hole (CVE-2019-10906). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-28493 python-jinja2: ReDoS vulnerability in the urlize filter
    requirements.txt
    A package you depend on has a known security hole (CVE-2020-28493). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-22195 jinja2: HTML attribute injection when passing user input as keys to xmlattr filter
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-22195). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-34064 jinja2: accepts keys containing non-attribute characters
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-34064). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format method
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-56326). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format method
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-27516). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-12060 keras: Keras Path Traversal Vulnerability
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-12060). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-9906 keras: Arbitrary Code execution in Keras Safe Mode
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-9906). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-1462 keras: Keras: Arbitrary Code Execution Vulnerability Bypassing Safe Mode
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-1462). Fix: Update that package to its patched version.
… 485 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 560 found · 25 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2026-1486 Keras Directory Traversal Vulnerability
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2025-12060). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-369 Keras code injection vulnerability
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2024-3660). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-80 In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2020-11538). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-81 libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2020-5310). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-82 libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2020-5311). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-83 libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2020-5312). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-137 An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2021-25287). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-138 An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2021-25288). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-331 Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2021-34552). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-35 An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOT
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2021-25289). Fix: Update that package to its patched version.
  • Serious PYSEC-2022-10 PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method.
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2022-22817). Fix: Update that package to its patched version.
  • Serious PYSEC-2022-168 Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2022-24303). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-457 Arbitrary Code Execution in Pillow
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2023-50447). Fix: Update that package to its patched version.
  • Serious PYSEC-2018-49 In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced fo
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2017-18342). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-142 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2020-14343). Fix: Update that package to its patched version.
  • Serious GHSA-hwvq-6gjx-j797 Special Element Injection in notebook
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2021-32798). Fix: Update that package to its patched version.
  • Serious PYSEC-2019-108 ** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2019-6446). Fix: Update that package to its patched version.
  • Serious PYSEC-2019-205 Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2018-7575). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-125 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a function taking two `int64` (i.e., `long long`) arguments. However,
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15202). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-128 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values that can cause heap ove
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15205). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-129 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buffer and altering the name of required keys results in segfaults and data corrupt
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15206). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-400 TensorFlow is an open source platform for machine learning. In affected versions the code for boosted trees in TensorFlow is still missing validation. As a result, attackers can trigger denial of serv
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2021-41208). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-548 TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2023-25668). Fix: Update that package to its patched version.
  • Serious GHSA-h6gw-r52c-724r NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlow
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-r6jx-9g48-2r5r Arbitrary code execution due to YAML deserialization
    /workdirs/scan-beceecfa-d89a-46a9-8850-c3d7a97c8a3c/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37678). Fix: Update that package to its patched version.
… 535 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: pypi:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard 10 notes

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

  • Worth fixing scorecard-overall OpenSSF Scorecard overall: 1.4/10
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Code-Review Code-Review scored 0: Found 0/8 approved changesets -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Contributors Contributors scored 0: project has 0 contributing companies or organizations -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Dependency-Update-Tool Dependency-Update-Tool scored 0: no update tool detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Fuzzing Fuzzing scored 0: project is not fuzzed
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-License License scored 0: license file not detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Maintained Maintained scored 0: 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-SAST SAST scored 0: no SAST tool detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Security-Policy Security-Policy scored 0: security policy file not detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.

via OpenSSF Scorecard v5.5.0 · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.