Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2023-37920 python-certifi: Removal of e-Tugra root certificateCVE-2022-23491 python-certifi: untrusted root certificatesCVE-2024-3651 python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode()CVE-2026-45409 python-idna: idna: Denial of Service via specially crafted long inputsGHSA-6v7p-g79w-8964 MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught errorCVE-2023-32681 python-requests: Unintended leak of Proxy-Authorization headerCVE-2024-35195 requests: subsequent requests to the same host ignore cert verificationCVE-2024-47081 requests: Requests vulnerable to .netrc credentials leak via malicious URLsCVE-2026-25645 requests: Requests: Security bypass due to predictable temporary file creationCVE-2019-11324 python-urllib3: Certification mishandle when error should be thrownCVE-2023-43804 python-urllib3: Cookie request header isn't stripped during cross-origin redirectsCVE-2025-66418 urllib3: urllib3: Unbounded decompression chain leads to resource exhaustionCVE-2025-66471 urllib3: urllib3 Streaming API improperly handles highly compressed dataCVE-2026-21441 urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)CVE-2026-44431 urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headersCVE-2018-25091 urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirectCVE-2019-11236 python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal serviceCVE-2020-26137 python-urllib3: CRLF injection via HTTP request methodCVE-2023-45803 urllib3: Request body not stripped after redirect from 303 status changes request method to GETCVE-2024-37891 urllib3: proxy-authorization request header is not stripped during cross-origin redirectsCVE-2025-50181 urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiationCVE-2024-53899 virtualenv: potential command injection via virtual environment activation scriptsCVE-2026-22702 virtualenv: virtualenv: Local attacker can redirect file operations via TOCTOU race conditionYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2026-2120 Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use fromPYSEC-2018-49 In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced foPYSEC-2021-142 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or PYSEC-2024-187 virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same PYSEC-2024-48 Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file. An attacker could ePYSEC-2026-2121 Black is the uncompromising Python code formatter. Prior to 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics optiPYSEC-2022-42986 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates fromPYSEC-2023-135 Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. These are in the process of being removed from Mozilla's trust store. e-Tugra's root certificates are being removed purPYSEC-2024-230 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.05.30 and prior to 2024.PYSEC-2022-43178 An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows methodPYSEC-2026-2132 Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.PYSEC-2026-1374 filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLockPYSEC-2026-1375 filelock has a TOCTOU race condition which allows symlink attacks during lock file creationPYSEC-2024-60 A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings,PYSEC-2026-215 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions priorPYSEC-2019-217 In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.PYSEC-2021-66 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the PYSEC-2026-1471 Jinja2 vulnerable to sandbox breakout through attr filter selecting format methodPYSEC-2026-1473 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterPYSEC-2026-1474 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterPYSEC-2026-1475 Jinja has a sandbox breakout through indirect reference to format methodPYSEC-2026-89 Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-MaPYSEC-2026-3625 MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. PYSEC-2020-92 A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying mPYSEC-2021-140 An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-pypi-code-execution code-execution match in setuptools 84.0.0A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.