gitsafehub
github.com/lucifer1004/julia ↗

lucifer1004/julia

scanned 2026-08-11 · git 571fa80
1 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies393Known OSS vulnerabilitiesRisky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 120s

Vulnerable dependencies — Trivy 393 found · 39 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2024-45491 libexpat: Integer Overflow or Wraparound
    JuliaSyntax/docs/Manifest.toml
    A package you depend on has a known security hole (CVE-2024-45491). Fix: Update that package to its patched version.
  • Serious CVE-2024-45492 libexpat: integer overflow
    JuliaSyntax/docs/Manifest.toml
    A package you depend on has a known security hole (CVE-2024-45492). Fix: Update that package to its patched version.
  • Serious CVE-2026-10536 libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service
    JuliaSyntax/docs/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-10536). Fix: Update that package to its patched version.
  • Serious CVE-2026-11856 curl: curl: Information disclosure via incorrect Digest authentication header reuse
    JuliaSyntax/docs/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-11856). Fix: Update that package to its patched version.
  • Serious CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies
    JuliaSyntax/docs/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8924). Fix: Update that package to its patched version.
  • Serious CVE-2026-8927 curl: Information disclosure due to uncleared proxy authentication state
    JuliaSyntax/docs/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8927). Fix: Update that package to its patched version.
  • Serious CVE-2024-24577 libgit2: arbitrary code execution due to heap corruption in git_index_add
    JuliaSyntax/docs/Manifest.toml
    A package you depend on has a known security hole (CVE-2024-24577). Fix: Update that package to its patched version.
  • Serious CVE-2026-55200 libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
    JuliaSyntax/docs/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-55200). Fix: Update that package to its patched version.
  • Serious CVE-2025-47917 Mbed TLS before 3.6.4 allows a use-after-free in certain situations of ...
    JuliaSyntax/docs/Manifest.toml
    A package you depend on has a known security hole (CVE-2025-47917). Fix: Update that package to its patched version.
  • Serious CVE-2024-5535 openssl: SSL_select_next_proto buffer overread
    JuliaSyntax/docs/Manifest.toml
    A package you depend on has a known security hole (CVE-2024-5535). Fix: Update that package to its patched version.
  • Serious CVE-2026-31789 openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing
    JuliaSyntax/docs/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-31789). Fix: Update that package to its patched version.
  • Serious CVE-2026-34182 openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages
    JuliaSyntax/docs/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-34182). Fix: Update that package to its patched version.
  • Serious CVE-2023-45853 zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6
    JuliaSyntax/docs/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-45853). Fix: Update that package to its patched version.
  • Serious CVE-2026-10536 libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service
    deps/jlutilities/documenter/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-10536). Fix: Update that package to its patched version.
  • Serious CVE-2026-11564 libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse
    deps/jlutilities/documenter/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-11564). Fix: Update that package to its patched version.
  • Serious CVE-2026-11856 curl: curl: Information disclosure via incorrect Digest authentication header reuse
    deps/jlutilities/documenter/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-11856). Fix: Update that package to its patched version.
  • Serious CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies
    deps/jlutilities/documenter/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8924). Fix: Update that package to its patched version.
  • Serious CVE-2026-8925 curl: curl: Double-free vulnerability in SASL authentication
    deps/jlutilities/documenter/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8925). Fix: Update that package to its patched version.
  • Serious CVE-2026-8926 curl: curl: Information disclosure via incorrect .netrc password lookup
    deps/jlutilities/documenter/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8926). Fix: Update that package to its patched version.
  • Serious CVE-2026-8927 curl: Information disclosure due to uncleared proxy authentication state
    deps/jlutilities/documenter/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8927). Fix: Update that package to its patched version.
  • Serious CVE-2026-9079 libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
    deps/jlutilities/documenter/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-9079). Fix: Update that package to its patched version.
  • Serious CVE-2026-55200 libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
    deps/jlutilities/documenter/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-55200). Fix: Update that package to its patched version.
  • Serious CVE-2026-31789 openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing
    deps/jlutilities/documenter/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-31789). Fix: Update that package to its patched version.
  • Serious CVE-2026-34182 openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages
    deps/jlutilities/documenter/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-34182). Fix: Update that package to its patched version.
  • Serious CVE-2026-55200 libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
    deps/jlutilities/revise/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-55200). Fix: Update that package to its patched version.
… 368 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner none found ✓

Your dependencies cross-checked against the OSV vulnerability database.

Nothing found by this check. ✓

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.