gitsafehub
github.com/mdboom/dependabot-core ↗

mdboom/dependabot-core

scanned 2026-08-11 · git 0f47681
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies127Known OSS vulnerabilities547Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 120s

Vulnerable dependencies — Trivy 127 found · 13 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2021-41116 Improper escaping of command arguments on Windows leading to command injection
    composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2021-41116). Fix: Update that package to its patched version.
  • Serious CVE-2024-51736 CVE-2024-51736: Command execution hijack on Windows with Process class
    composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2024-51736). Fix: Update that package to its patched version.
  • Serious CVE-2022-21235 github.com/Masterminds/vcs: Command Injection via argument injection
    dep/helpers/go.mod
    A package you depend on has a known security hole (CVE-2022-21235). Fix: Update that package to its patched version.
  • Serious CVE-2022-21235 github.com/Masterminds/vcs: Command Injection via argument injection
    go_modules/helpers/go.mod
    A package you depend on has a known security hole (CVE-2022-21235). Fix: Update that package to its patched version.
  • Serious CVE-2025-7783 form-data: Unsafe random function in form-data
    npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2025-7783). Fix: Update that package to its patched version.
  • Serious CVE-2021-3918 nodejs-json-schema: Prototype pollution vulnerability
    npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2021-3918). Fix: Update that package to its patched version.
  • Serious CVE-2022-37601 loader-utils: prototype pollution in function parseQuery in parseQuery.js
    npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2022-37601). Fix: Update that package to its patched version.
  • Serious CVE-2021-44906 minimist: prototype pollution
    npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2021-44906). Fix: Update that package to its patched version.
  • Serious CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb
    npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
  • Serious CVE-2020-7677 thenify: Arbitrary Code Execution in thenify
    npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2020-7677). Fix: Update that package to its patched version.
  • Serious CVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties
    npm_and_yarn/spec/fixtures/npm_lockfiles/package-lock.json
    A package you depend on has a known security hole (CVE-2019-10744). Fix: Update that package to its patched version.
  • Serious CVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties
    npm_and_yarn/spec/fixtures/yarn_lockfiles/yarn.lock
    A package you depend on has a known security hole (CVE-2019-10744). Fix: Update that package to its patched version.
  • Serious CVE-2022-26184 Poetry before v1.1.9 contains Untrusted Search Path
    python/helpers/requirements.txt
    A package you depend on has a known security hole (CVE-2022-26184). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-29472 Composer is a dependency manager for PHP. URLs for Mercurial repositor ...
    composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2021-29472). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-24828 Composer is a dependency manager for the PHP programming language. Int ...
    composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2022-24828). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-43655 Composer is a dependency manager for PHP. Users publishing a composer. ...
    composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2023-43655). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-40176 composer: command injection via malicious Perforce repository definition
    composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2026-40176). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-40261 composer: command injection via malicious Perforce source reference/url
    composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2026-40261). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59948 composer/composer: Composer: Arbitrary file write via crafted package name
    composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2026-59948). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-45793 Composer is a dependency Manager for the PHP language. Prior to 1.10.2 ...
    composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2026-45793). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59946 composer: Composer: Insecure file permissions leading to information disclosure and potential execution
    composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2026-59946). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59947 composer/composer: Composer: Information disclosure of credentials via debug output
    composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2026-59947). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-24739 Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows
    composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2026-24739). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-15366 nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function
    npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2020-15366). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-69873 ajv: ReDoS via $data reference
    npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2025-69873). Fix: Update that package to its patched version.
… 102 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 547 found · 14 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GO-2022-0414 Command injection in github.com/Masterminds/vcs
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/dep/helpers/go.mod
    A package you depend on has a known security hole (CVE-2022-21235). Fix: Update that package to its patched version.
  • Serious GO-2022-0414 Command injection in github.com/Masterminds/vcs
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/go_modules/helpers/go.mod
    A package you depend on has a known security hole (CVE-2022-21235). Fix: Update that package to its patched version.
  • Serious GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2023-45133). Fix: Update that package to its patched version.
  • Serious GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundary
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2025-7783). Fix: Update that package to its patched version.
  • Serious GHSA-896r-f27r-55mw json-schema is vulnerable to Prototype Pollution
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2021-3918). Fix: Update that package to its patched version.
  • Serious GHSA-76p3-8jx3-jpfq Prototype pollution in webpack loader-utils
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2022-37601). Fix: Update that package to its patched version.
  • Serious GHSA-xvch-5gv4-984h Prototype Pollution in minimist
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2021-44906). Fix: Update that package to its patched version.
  • Serious GHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited input
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
  • Serious GHSA-29xr-v42j-r956 thenify before 3.3.1 made use of unsafe calls to `eval`.
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/npm_and_yarn/helpers/yarn.lock
    A package you depend on has a known security hole (CVE-2020-7677). Fix: Update that package to its patched version.
  • Serious GHSA-jf85-cpcp-j695 Prototype Pollution in lodash
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/npm_and_yarn/spec/fixtures/npm-shrinkwrap.json
    A package you depend on has a known security hole (CVE-2019-10744). Fix: Update that package to its patched version.
  • Serious GHSA-jf85-cpcp-j695 Prototype Pollution in lodash
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/npm_and_yarn/spec/fixtures/npm_lockfiles/package-lock.json
    A package you depend on has a known security hole (CVE-2019-10744). Fix: Update that package to its patched version.
  • Serious GHSA-jf85-cpcp-j695 Prototype Pollution in lodash
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/npm_and_yarn/spec/fixtures/shrinkwraps/npm-shrinkwrap.json
    A package you depend on has a known security hole (CVE-2019-10744). Fix: Update that package to its patched version.
  • Serious GHSA-jf85-cpcp-j695 Prototype Pollution in lodash
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/npm_and_yarn/spec/fixtures/yarn_lockfiles/yarn.lock
    A package you depend on has a known security hole (CVE-2019-10744). Fix: Update that package to its patched version.
  • Serious PYSEC-2022-234 Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malici
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/python/helpers/requirements.txt
    A package you depend on has a known security hole (CVE-2022-26184). Fix: Update that package to its patched version.
  • Worth fixing GHSA-499r-g7pc-vmp9 Composer: Arbitrary file write outside vendor via malicious transitive package name
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2026-59948). Fix: Update that package to its patched version.
  • Worth fixing GHSA-f9f8-rm49-7jv2 Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2026-45793). Fix: Update that package to its patched version.
  • Worth fixing GHSA-frqg-7g38-6gcf Improper escaping of command arguments on Windows leading to command injection
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2021-41116). Fix: Update that package to its patched version.
  • Worth fixing GHSA-g6xq-892h-64w3 Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2026-59947). Fix: Update that package to its patched version.
  • Worth fixing GHSA-gjfg-22fp-rrxx Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2026-59946). Fix: Update that package to its patched version.
  • Worth fixing GHSA-gqw4-4w2p-838q Composer has a command injection via malicious perforce reference
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2026-40261). Fix: Update that package to its patched version.
  • Worth fixing GHSA-h5h8-pc6h-jvvx Composer's missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2021-29472). Fix: Update that package to its patched version.
  • Worth fixing GHSA-jm6m-4632-36hf Composer Remote Code Execution vulnerability via web-accessible composer.phar
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2023-43655). Fix: Update that package to its patched version.
  • Worth fixing GHSA-wg36-wvj6-r67p Composer has a command injection via malicious perforce repository
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2026-40176). Fix: Update that package to its patched version.
  • Worth fixing GHSA-x7cr-6qr6-2hh6 Missing input validation can lead to command execution in composer
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2022-24828). Fix: Update that package to its patched version.
  • Worth fixing GHSA-qq5c-677p-737q Symfony vulnerable to command execution hijack on Windows with Process class
    /workdirs/scan-e4b2f81d-3790-4b6e-b0c0-f36a2f36f03f/composer/helpers/composer.lock
    A package you depend on has a known security hole (CVE-2024-51736). Fix: Update that package to its patched version.
… 522 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.