gitsafehub
github.com/mattpocock/video-ideas ↗

mattpocock/video-ideas

scanned 2026-07-08 · git 8208cae
1 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependenciesKnown OSS vulnerabilities18Risky code patternsMalicious dependenciesProject health9

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy none found ✓

Packages you depend on that have known security holes (CVEs).

Nothing found by this check. ✓

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 18 found · 1 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GHSA-f82v-jwr5-mffw Authorization Bypass in Next.js Middleware
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-29927). Fix: Update that package to its patched version.
  • Worth fixing GHSA-mwcw-c2x4-8c55 Predictable results in nanoid generation when given non-integer values
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2024-55565). Fix: Update that package to its patched version.
  • Worth fixing GHSA-36qx-fr4f-26g5 Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-44573). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3x4c-7xq6-9pq8 Next.js: Unbounded next/image disk cache growth can exhaust storage
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-27980). Fix: Update that package to its patched version.
  • Worth fixing GHSA-4342-x723-ch2f Next.js Improper Middleware Redirect Handling Leads to SSRF
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-57822). Fix: Update that package to its patched version.
  • Worth fixing GHSA-7gfc-8cq8-jh5f Next.js authorization bypass vulnerability
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2024-51479). Fix: Update that package to its patched version.
  • Worth fixing GHSA-9g9p-9gw9-jx7f Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-59471). Fix: Update that package to its patched version.
  • Worth fixing GHSA-g5qg-72qw-gw5v Next.js Affected by Cache Key Confusion for Image Optimization API Routes
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-57752). Fix: Update that package to its patched version.
  • Worth fixing GHSA-g77x-44xx-532m Denial of Service condition in Next.js image optimization
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2024-47831). Fix: Update that package to its patched version.
  • Worth fixing GHSA-ggv3-7p47-pfv8 Next.js: HTTP request smuggling in rewrites
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-29057). Fix: Update that package to its patched version.
  • Worth fixing GHSA-h64f-5h5j-jqjh Next.js has a Denial of Service in the Image Optimization API
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-44577). Fix: Update that package to its patched version.
  • Worth fixing GHSA-xv57-4mr9-wg8v Next.js Content Injection Vulnerability for Image Optimization
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-55173). Fix: Update that package to its patched version.
  • Worth fixing GHSA-7fh5-64p2-3v2j PostCSS line return parsing error
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2023-44270). Fix: Update that package to its patched version.
  • Worth fixing GHSA-qx2v-qp2m-jg93 PostCSS has XSS via Unescaped </style> in its CSS Stringify Output
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-41305). Fix: Update that package to its patched version.
  • Worth fixing GHSA-m95q-7qp3-xv42 Zod denial of service vulnerability
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2023-4316). Fix: Update that package to its patched version.
  • Minor GHSA-3g8h-86w9-wvmq Next.js's Middleware / Proxy redirects can be cache-poisoned
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-44572). Fix: Update that package to its patched version.
  • Minor GHSA-c59h-r6p8-q9wc Next.js missing cache-control header may lead to CDN caching empty reply
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2023-46298). Fix: Update that package to its patched version.
  • Minor GHSA-qpjv-v59x-3qc4 Next.js Race Condition to Cache Poisoning
    /workdirs/scan-228a4d45-c81c-45bc-8c22-e485da441872/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-32421). Fix: Update that package to its patched version.

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: npm:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard 9 notes

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

  • Worth fixing scorecard-overall OpenSSF Scorecard overall: 1.6/10
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Code-Review Code-Review scored 0: Found 0/5 approved changesets -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Dependency-Update-Tool Dependency-Update-Tool scored 0: no update tool detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Fuzzing Fuzzing scored 0: project is not fuzzed
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-License License scored 0: license file not detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Maintained Maintained scored 0: 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-SAST SAST scored 0: no SAST tool detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Security-Policy Security-Policy scored 0: security policy file not detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.

via OpenSSF Scorecard v5.5.0 · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.