gitsafehub
github.com/lucifer1004/mit-18.s191-cn ↗

lucifer1004/mit-18.s191-cn

scanned 2026-08-13 · git 351f892
1 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies230Known OSS vulnerabilitiesRisky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 230 found · 17 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2024-34346 Deno permission escalation vulnerability via open of privileged files with missing `--deny` flag
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2024-34346). Fix: Update that package to its patched version.
  • Serious CVE-2026-22863 Deno node:crypto doesn't finalize cipher
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-22863). Fix: Update that package to its patched version.
  • Serious CVE-2026-22864 Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-22864). Fix: Update that package to its patched version.
  • Serious CVE-2026-27190 Deno has a Command Injection via Incomplete shell metacharacter blocklist in node:child_process
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-27190). Fix: Update that package to its patched version.
  • Serious CVE-2024-45491 libexpat: Integer Overflow or Wraparound
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2024-45491). Fix: Update that package to its patched version.
  • Serious CVE-2024-45492 libexpat: integer overflow
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2024-45492). Fix: Update that package to its patched version.
  • Serious CVE-2022-32221 curl: POST following PUT confusion
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2022-32221). Fix: Update that package to its patched version.
  • Serious CVE-2026-11856 curl: curl: Information disclosure via incorrect Digest authentication header reuse
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-11856). Fix: Update that package to its patched version.
  • Serious CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8924). Fix: Update that package to its patched version.
  • Serious CVE-2026-8927 curl: Information disclosure due to uncleared proxy authentication state
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-8927). Fix: Update that package to its patched version.
  • Serious CVE-2026-55200 libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-55200). Fix: Update that package to its patched version.
  • Serious CVE-2021-44732 Mbed TLS before 3.0.1 has a double free in certain out-of-memory condi ...
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2021-44732). Fix: Update that package to its patched version.
  • Serious CVE-2022-35409 An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0 ...
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2022-35409). Fix: Update that package to its patched version.
  • Serious CVE-2022-46393 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0 ...
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2022-46393). Fix: Update that package to its patched version.
  • Serious CVE-2025-47917 Mbed TLS before 3.6.4 allows a use-after-free in certain situations of ...
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2025-47917). Fix: Update that package to its patched version.
  • Serious CVE-2024-5535 openssl: SSL_select_next_proto buffer overread
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2024-5535). Fix: Update that package to its patched version.
  • Serious CVE-2024-56171 libxml2: Use-After-Free in libxml2
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2024-56171). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-22499 Deno is vulnerable to race condition via interactive permission prompt spoofing
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-22499). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-26103 Regular Expression Denial of Service in Deno.upgradeWebSocket API
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-26103). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-28446 Interactive `run` permission prompt spoofing via improper ANSI neutralization
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-28446). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-32477 Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. By using ANSI escape sequences and a race between `libc::tcflush(0, libc::TCIFLUSH)` and reading standard input, it's po
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2024-32477). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-61787 Deno is Vulnerable to Command Injection on Windows During Batch File Execution
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2025-61787). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-49401 Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-49401). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-49402 Deno: Command Injection via spawnSync & spawn on Windows
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-49402). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-49440 Deno: Miller-Rabin Primality Test Allows Zero Rounds
    pluto-deployment-environment/Manifest.toml
    A package you depend on has a known security hole (CVE-2026-49440). Fix: Update that package to its patched version.
… 205 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner none found ✓

Your dependencies cross-checked against the OSV vulnerability database.

Nothing found by this check. ✓

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.