Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2026-71556 github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolutionCVE-2026-71557 go-git is an extensible git implementation library written in pure Go. ...CVE-2026-71556 github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolutionCVE-2026-71557 go-git is an extensible git implementation library written in pure Go. ...CVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary module content no ...CVE-2026-56865 A malicious GOPROXY was previously capable of forging up to two sumdb ...CVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary module content no ...CVE-2026-56865 A malicious GOPROXY was previously capable of forging up to two sumdb ...CVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary module content no ...CVE-2026-56865 A malicious GOPROXY was previously capable of forging up to two sumdb ...Your dependencies cross-checked against the OSV vulnerability database.
GHSA-hc8v-wwc9-vgxm go-git: Worktree operations may follow symlinksGHSA-qgq7-7hm3-q39j go-git: Malicious reference names may modify files outside the reference storageGHSA-hc8v-wwc9-vgxm go-git: Worktree operations may follow symlinksGHSA-qgq7-7hm3-q39j go-git: Malicious reference names may modify files outside the reference storageGO-2026-5932 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issuesGO-2026-6179 Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlogGO-2026-6180 Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdbGO-2026-4970 Root escape via symlink plus trailing slash in osGO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnaGO-2026-5856 Invoking Encrypted Client Hello privacy leak in crypto/tlsGO-2026-5972 Enforce maximum recursion depth in encoding/asn1GO-2026-6088 Add recursion depth guard during decode in encoding/xmlGO-2026-6089 Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/httpGO-2026-6090 Limit handshake messages we are willing to accept post-handshake in crypto/tlsGO-2026-6091 Fix Javascript regexp context tracking in html/templateGO-2026-6218 Avoid quadratic complexity in resolvePath in net/urlGO-2026-5046 CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2GO-2026-5047 Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2GO-2026-5048 Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2GO-2026-5932 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issuesGO-2026-6179 Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlogGO-2026-6180 Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdbGO-2022-0969 Denial of service in net/http and golang.org/x/net/http2GO-2022-1037 Unbounded memory consumption when reading headers in archive/tarGO-2022-1038 Incorrect sanitization of forwarded query parameters in net/http/httputilCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.