Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
GHSA-q2qq-hmj6-3wpp hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compressionGHSA-q2qq-hmj6-3wpp hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compressionCVE-2025-4432 ring: Some AES functions may panic when overflow checking is enabled in ringGHSA-82j2-j2ch-gfr8 rustls-webpki: Denial of service via panic on malformed CRL BIT STRINGCVE-2026-32314 Yamux is a stream multiplexer over reliable, ordered connections such ...CVE-2024-12224 idna: idna accepts Punycode labels that do not produce any non-ASCII when decodedGHSA-qg5g-gv98-5ffh rustls network-reachable panic in `Acceptor::accept`GHSA-82j2-j2ch-gfr8 rustls-webpki: Denial of service via panic on malformed CRL BIT STRINGGHSA-pwjx-qhcg-rvj4 webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logicGHSA-rhfx-m35p-ff5j `IterMut` violates Stacked Borrows by invalidating internal pointerGHSA-cq8v-f236-94qc Rand is unsound with a custom logger using rand::rng()GHSA-965h-392x-2mh5 webpki: Name constraints for URI names were incorrectly acceptedGHSA-xgp8-3hg3-c2mh webpki: Name constraints were accepted for certificates asserting a wildcard nameCVE-2025-58160 tracing-subscriber: Tracing log pollutionGHSA-965h-392x-2mh5 webpki: Name constraints for URI names were incorrectly acceptedGHSA-xgp8-3hg3-c2mh webpki: Name constraints were accepted for certificates asserting a wildcard nameCVE-2025-58160 tracing-subscriber: Tracing log pollutionYour dependencies cross-checked against the OSV vulnerability database.
Nothing found by this check. ✓
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.