Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2022-1996 go-restful: Authorization Bypass Through User-Controlled KeyCVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2014-3499 docker: systemd socket activation results in privilege escalationCVE-2014-6407 docker: symbolic and hardlink issues leading to privilege escalationCVE-2014-9357 docker: Escalation of privileges during decompression of LZMA archivesCVE-2018-12608 moby: cert signing bypassCVE-2019-13509 docker: Docker Engine in debug mode may sometimes add secrets to the debug log leading to information disclosureCVE-2026-34040 Moby: Moby: Authorization bypass vulnerabilityCVE-2014-5277 docker: fallback to HTTP when HTTPS connections to the registry failCVE-2014-9356 docker: Path traversal during processing of absolute symlinksCVE-2014-9358 docker: Path traversal and spoofing opportunities presented through image identifiersCVE-2015-3627 docker: insecure opening of file-descriptor 1 leading to privilege escalationCVE-2015-3631 docker: volume mounts allow LSM profile escalationCVE-2020-27534 moby/buildkit: calls os.OpenFile with a potentially unsafe qemu-check temporary pathnameCVE-2021-41091 moby: data directory contains subdirectories with insufficiently restricted permissions, which could lead to directory traversalCVE-2022-24769 moby: Default inheritable capabilities for linux container should be emptyCVE-2022-36109 moby: supplementary groups mishandlingCVE-2024-24557 moby: classic builder cache poisoningCVE-2024-29018 moby: external DNS requests from 'internal' networks could lead to data exfiltrationCVE-2026-33997 moby: docker: github.com/moby/moby: Moby: Privilege validation bypass during plugin installationGHSA-jq35-85cj-fj4p /sys/devices/virtual/powercap accessible by default to containersGHSA-xmmx-7jpf-fx42 Moby (Docker Engine) is vulnerable to Ambiguous OCI manifest parsingCVE-2023-37788 goproxy: Denial of service (DoS) via unspecified vectors.CVE-2021-3121 gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validationCVE-2024-45339 github.com/golang/glog: Vulnerability when creating log files in github.com/golang/glogYour dependencies cross-checked against the OSV vulnerability database.
GO-2024-3321 Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/cryptoGO-2026-5005 Invoking key constraints not enforced in golang.org/x/crypto/ssh/agentGO-2026-5006 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agentGO-2026-5017 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshGO-2026-5019 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshGO-2026-5020 Invoking infinite loop on large channel writes in golang.org/x/crypto/sshGO-2026-5021 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhostsGO-2026-5023 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshGO-2022-0965 Unbounded recursion in JSON parsing in k8s.io/apimachineryGO-2024-2748 Privilege Escalation in Kubernetes in k8s.io/apimachineryGO-2021-0064 Unauthorized credential disclosure via debug logs in k8s.io/kubernetes and k8s.io/client-goGO-2021-0065 Unauthorized credential disclosure in k8s.io/kubernetes and k8s.io/client-goGO-2021-0053 Panic due to improper input validation in github.com/gogo/protobufGO-2022-0322 Uncontrolled resource consumption in github.com/prometheus/client_golangGO-2020-0012 Panic due to improper verification of cryptographic signatures in golang.org/x/crypto/sshGO-2021-0227 Panic on crafted authentication request message in golang.org/x/crypto/sshGO-2021-0356 Denial of service via crafted Signer in golang.org/x/crypto/sshGO-2022-0229 Panic in certificate parsing in crypto/x509 and golang.org/x/crypto/cryptobyteGO-2022-0968 Panic on malformed packets in golang.org/x/crypto/sshGO-2023-2402 Man-in-the-middle attacker can compromise integrity of secure channel in golang.org/x/cryptoGO-2025-3487 Potential denial of service in golang.org/x/cryptoGO-2025-4134 Unbounded memory consumption in golang.org/x/crypto/sshGO-2025-4135 Malformed constraint may cause denial of service in golang.org/x/crypto/ssh/agentGO-2026-5013 Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/sshGO-2026-5014 Invoking bypass of certificate restrictions in golang.org/x/crypto/sshCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.