gitsafehub
github.com/probablykasper/yt-email-notifier ↗

probablykasper/yt-email-notifier

scanned 2026-07-08 · git 85a2b11
4 of 6 checks flagged a security issue
🔴 Needs attention
6 checks ran. Start with known oss vulnerabilities below.

Informational scan, not a security audit. How this is computed.

Leaked secrets1Vulnerable dependencies30Known OSS vulnerabilities85Risky code patternsMalicious dependencies2Project health10

Security checks

Leaked secrets — Gitleaks 1 found · 1 serious

API keys, passwords or tokens committed into the repo.

  • Serious gcp-api-key Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches.
    src/web/index.html:94
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 30 found · 2 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2021-44906 minimist: prototype pollution
    package-lock.json
    A package you depend on has a known security hole (CVE-2021-44906). Fix: Update that package to its patched version.
  • Serious CVE-2021-23358 nodejs-underscore: Arbitrary code execution via the template function
    package-lock.json
    A package you depend on has a known security hole (CVE-2021-23358). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-45590 body-parser: Denial of Service Vulnerability in body-parser
    package-lock.json
    A package you depend on has a known security hole (CVE-2024-45590). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-21538 cross-spawn: regular expression denial of service
    package-lock.json
    A package you depend on has a known security hole (CVE-2024-21538). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-32141 flatted: flatted: Unbounded recursion DoS in parse() revive phase
    package-lock.json
    A package you depend on has a known security hole (CVE-2026-32141). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33228 flatted: Flatted: Prototype pollution vulnerability allows arbitrary code execution via crafted JSON.
    package-lock.json
    A package you depend on has a known security hole (CVE-2026-33228). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-21704 log4js-node is a port of log4js to node.js. In affected versions defau ...
    package-lock.json
    A package you depend on has a known security hole (CVE-2022-21704). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-0235 node-fetch: exposure of sensitive information to an unauthorized actor
    package-lock.json
    A package you depend on has a known security hole (CVE-2022-0235). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-14874 nodemailer: Nodemailer: Denial of service via crafted email address header
    package-lock.json
    A package you depend on has a known security hole (CVE-2025-14874). Fix: Update that package to its patched version.
  • Worth fixing GHSA-p6gq-j5cr-w38f Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
    package-lock.json
    A package you depend on has a known security hole (GHSA-p6gq-j5cr-w38f). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-23400 The package nodemailer before 6.6.1 are vulnerable to HTTP Header Inje ...
    package-lock.json
    A package you depend on has a known security hole (CVE-2021-23400). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-13033 nodemailer: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
    package-lock.json
    A package you depend on has a known security hole (CVE-2025-13033). Fix: Update that package to its patched version.
  • Worth fixing GHSA-268h-hp4c-crq3 Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
    package-lock.json
    A package you depend on has a known security hole (GHSA-268h-hp4c-crq3). Fix: Update that package to its patched version.
  • Worth fixing GHSA-9h6g-pr28-7cqp nodemailer ReDoS when trying to send a specially crafted email
    package-lock.json
    A package you depend on has a known security hole (GHSA-9h6g-pr28-7cqp). Fix: Update that package to its patched version.
  • Worth fixing GHSA-r7g4-qg5f-qqm2 Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
    package-lock.json
    A package you depend on has a known security hole (GHSA-r7g4-qg5f-qqm2). Fix: Update that package to its patched version.
  • Worth fixing GHSA-vvjj-xcjg-gr5g Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
    package-lock.json
    A package you depend on has a known security hole (GHSA-vvjj-xcjg-gr5g). Fix: Update that package to its patched version.
  • Worth fixing GHSA-wqvq-jvpq-h66f Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
    package-lock.json
    A package you depend on has a known security hole (GHSA-wqvq-jvpq-h66f). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-24999 express: "qs" prototype poisoning causes the hang of the node process
    package-lock.json
    A package you depend on has a known security hole (CVE-2022-24999). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-15284 qs: qs: Denial of Service via improper input validation in array parsing
    package-lock.json
    A package you depend on has a known security hole (CVE-2025-15284). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-25883 nodejs-semver: Regular expression denial of service
    package-lock.json
    A package you depend on has a known security hole (CVE-2022-25883). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-27601 Underscore.js: Underscore.js: Denial of Service via recursive data structures in flatten and isEqual functions
    package-lock.json
    A package you depend on has a known security hole (CVE-2026-27601). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-37890 nodejs-ws: denial of service when handling a request with many HTTP headers
    package-lock.json
    A package you depend on has a known security hole (CVE-2024-37890). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-48779 ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments
    package-lock.json
    A package you depend on has a known security hole (CVE-2026-48779). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-32640 nodejs-ws: Specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server
    package-lock.json
    A package you depend on has a known security hole (CVE-2021-32640). Fix: Update that package to its patched version.
  • Minor CVE-2017-16137 nodejs-debug: Regular expression Denial of Service
    package-lock.json
    A package you depend on has a known security hole (CVE-2017-16137). Fix: Update that package to its patched version.
… 5 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 85 found · 7 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundary
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2025-7783). Fix: Update that package to its patched version.
  • Serious GHSA-896r-f27r-55mw json-schema is vulnerable to Prototype Pollution
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2021-3918). Fix: Update that package to its patched version.
  • Serious GHSA-xvch-5gv4-984h Prototype Pollution in minimist
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2021-44906). Fix: Update that package to its patched version.
  • Serious GHSA-4cpg-3vgw-4877 Prototype pollution in Plist before 3.0.5 can cause denial of service
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2022-22912). Fix: Update that package to its patched version.
  • Serious GHSA-gff7-g5r8-mg8m Prototype Pollution in simple-plist
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2022-26260). Fix: Update that package to its patched version.
  • Serious GHSA-cf4h-3jhx-xvhq Arbitrary Code Execution in underscore
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2021-23358). Fix: Update that package to its patched version.
  • Serious GHSA-crh6-fp67-6883 xmldom allows multiple root nodes in a DOM
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2022-39353). Fix: Update that package to its patched version.
  • Worth fixing GHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2025-27789). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` option
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2025-69873). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` option
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2025-69873). Fix: Update that package to its patched version.
  • Worth fixing GHSA-93q8-gq69-wqmw Inefficient Regular Expression Complexity in chalk/ansi-regex
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2021-3807). Fix: Update that package to its patched version.
  • Worth fixing GHSA-93q8-gq69-wqmw Inefficient Regular Expression Complexity in chalk/ansi-regex
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2021-3807). Fix: Update that package to its patched version.
  • Worth fixing GHSA-fwr7-v2mv-hh25 Prototype Pollution in async
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2021-43138). Fix: Update that package to its patched version.
  • Worth fixing GHSA-pp7h-53gx-mx7r Remote Memory Exposure in bl
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2020-8244). Fix: Update that package to its patched version.
  • Worth fixing GHSA-qwcr-r2fm-qrc7 body-parser vulnerable to denial of service when url encoding is enabled
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2024-45590). Fix: Update that package to its patched version.
  • Worth fixing GHSA-f886-m6hf-6m8v brace-expansion: Zero-step sequence causes process hang and memory exhaustion
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2026-33750). Fix: Update that package to its patched version.
  • Worth fixing GHSA-grv7-fg5c-xmjg Uncontrolled resource consumption in braces
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2024-4068). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3xgq-45jj-v275 Regular Expression Denial of Service (ReDoS) in cross-spawn
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2024-21538). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3xgq-45jj-v275 Regular Expression Denial of Service (ReDoS) in cross-spawn
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2024-21538). Fix: Update that package to its patched version.
  • Worth fixing GHSA-25h7-pfq9-p65f flatted vulnerable to unbounded recursion DoS in parse() revive phase
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2026-32141). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rf6f-7fwh-wjgh Prototype Pollution via parse() in NodeJS flatted
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2026-33228). Fix: Update that package to its patched version.
  • Worth fixing GHSA-25h7-pfq9-p65f flatted vulnerable to unbounded recursion DoS in parse() revive phase
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2026-32141). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rf6f-7fwh-wjgh Prototype Pollution via parse() in NodeJS flatted
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2026-33228). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hmw2-7cc7-3qxx form-data: CRLF injection in form-data via unescaped multipart field names and filenames
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2026-12143). Fix: Update that package to its patched version.
  • Worth fixing GHSA-q7cg-457f-vx79 joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
    /workdirs/scan-62036dd0-aaef-479b-946f-8843399878e2/package-lock.json
    A package you depend on has a known security hole (CVE-2026-48038). Fix: Update that package to its patched version.
… 60 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog 2 found

Packages that look intentionally malicious: typosquats, sneaky install scripts.

  • Worth fixing guarddog-npm-bundled_binary bundled_binary match in systray 1.0.5
    systray
    A dependency shows signs of being intentionally malicious (typosquat, hidden install script, etc.). Fix: Don’t install it until you’ve verified the package. Consider removing it.
  • Worth fixing guarddog-npm-shady-links shady-links match in nodemailer 6.10.1
    nodemailer
    A dependency shows signs of being intentionally malicious (typosquat, hidden install script, etc.). Fix: Don’t install it until you’ve verified the package. Consider removing it.

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard 10 notes

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

  • Worth fixing scorecard-overall OpenSSF Scorecard overall: 1.4/10
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Code-Review Code-Review scored 0: Found 0/30 approved changesets -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Dependency-Update-Tool Dependency-Update-Tool scored 0: no update tool detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Fuzzing Fuzzing scored 0: project is not fuzzed
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-License License scored 0: license file not detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Maintained Maintained scored 0: project is archived
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-SAST SAST scored 0: no SAST tool detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Security-Policy Security-Policy scored 0: security policy file not detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Signed-Releases Signed-Releases scored 0: Project has not signed or included provenance with any releases.
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.

via OpenSSF Scorecard v5.5.0 · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.