Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2025-25288 octokit/plugin-paginate-rest: @octokit/plugin-paginate-rest has a Regular Expression in iterator that Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingCVE-2025-25288 octokit/plugin-paginate-rest: @octokit/plugin-paginate-rest has a Regular Expression in iterator that Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingCVE-2025-25290 octokit/request: @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingCVE-2025-25290 octokit/request: @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingCVE-2025-25289 @octokit/request-error: @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingCVE-2025-25289 @octokit/request-error: @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingCVE-2026-12151 undici: undici: Denial of Service due to unbounded memory growth via WebSocket framesCVE-2026-1526 undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompressionCVE-2026-2229 undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameterCVE-2025-22150 undici: Undici Uses Insufficiently Random ValuesCVE-2026-15157 undici: undici: HTTP header injection via unvalidated blob-like body type propertyCVE-2026-1525 undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headersCVE-2026-1527 undici: Undici: HTTP header injection and request smuggling vulnerabilityCVE-2026-16728 undici: undici: Response desynchronization via retry interceptor with mismatched Content-LengthCVE-2026-16729 undici: Undici: Cookie attribute injection allows bypassing security protectionsCVE-2026-22036 undici: Undici: Denial of Service via excessive decompression stepsCVE-2026-9679 undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decodingCVE-2026-41907 uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentialityCVE-2023-45143 node-undici: cookie leakageCVE-2024-24758 undici: sensitive information exposureCVE-2024-30260 nodejs-undici: proxy-authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipelineCVE-2024-30261 nodejs-undici: fetch() with integrity option is too lax when algorithm is specified but hash value is in incorrectCVE-2025-47279 undici: Undici Memory Leak with Invalid CertificatesCVE-2026-11525 undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie headerCVE-2026-6733 undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery.Your dependencies cross-checked against the OSV vulnerability database.
GHSA-h5c3-5r3r-rr8q @octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingGHSA-h5c3-5r3r-rr8q @octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingGHSA-rmvr-2pp2-xj38 @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingGHSA-rmvr-2pp2-xj38 @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingGHSA-xx4v-prfh-6cgc @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingGHSA-xx4v-prfh-6cgc @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingGHSA-2mjp-6q6p-2qxm Undici has an HTTP Request/Response Smuggling issueGHSA-4992-7rv2-5pvq Undici has CRLF Injection in undici via `upgrade` optionGHSA-8xcm-r25x-g524 undici vulnerable to downstream response desynchronization via retry interceptorGHSA-c76h-2ccp-4975 Use of Insufficiently Random Values in undiciGHSA-g9mf-h72j-4rw9 Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustionGHSA-m8rv-5g2x-5cg5 undici vulnerable to CRLF Injection via blob-like body 'type' propertyGHSA-p88m-4jfj-68fv undici vulnerable to HTTP header injection via Set-Cookie percent-decodingGHSA-v3r7-h72x-cjcm undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fieldsGHSA-v9p9-hfj2-hcw8 Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits ValidationGHSA-vrm6-8vpv-qv8q Undici has Unbounded Memory Consumption in WebSocket permessage-deflate DecompressionGHSA-vxpw-j846-p89q undici WebSocket client vulnerable to denial of service via fragment count bypassGHSA-w5hq-g745-h8pq uuid: Missing buffer bounds check in v3/v5/v6 when buf is providedGHSA-35p6-xmwp-9g52 undici vulnerable to HTTP response queue poisoning via keep-alive socket reuseGHSA-3787-6prv-h9w3 Undici proxy-authorization header not cleared on cross-origin redirect in fetchGHSA-9qxr-qj54-h672 Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrectGHSA-cxrh-j4jr-qwg3 undici Denial of Service attack via bad certificate dataGHSA-g8m3-5g58-fq7m undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matchingGHSA-m4v8-wqvr-p9f7 Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipelineGHSA-wqq4-5wpv-mx2g Undici's cookie header not cleared on cross-origin redirect in fetchCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.