Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
GHSA-mrrw-grhq-86gf Ascii (crate) allows out-of-bounds array indexing in safe codeGHSA-f85w-wvc7-crwc bumpalo has use-after-free due to a lifetime error in `Vec::into_iter()`CVE-2022-31104 Miscompilation of `i8x16.swizzle` and `select` with v128 inputsCVE-2022-31169 Cranelift vulnerable to miscompilation of constant values in division on AArch64CVE-2025-27612 libcontainer: Libcontainer is affected by capabilities elevationCVE-2024-27308 CVE-2024-27308 affecting package rpm-ostree for versions less than 2024.4-1CVE-2025-53605 protobuf: Protobuf: Uncontrolled Recursion VulnerabilityCVE-2024-43806 Rustix is a set of safe Rust bindings to POSIX-ish APIs. When using `r ...CVE-2026-33055 tar-rs is a tar archive reading/writing library for Rust. Versions 0.4 ...CVE-2026-33056 tar-rs: tar-rs: Arbitrary directory permission modification via crafted tar archiveGHSA-3pv8-6f4r-ffg2 tar has a PAX header desynchronization issueCVE-2020-26235 Segmentation fault in timeCVE-2025-54867 Youki: If /proc and /sys in the rootfs are symbolic links, they can potentially be exploited to gain access to the host root filesystem.CVE-2025-62161 youki container escape via "masked path" abuse due to mount race conditionsCVE-2025-62596 youki container escape and denial of service due to arbitrary write gadgets and procfs write redirectsGHSA-cq8v-f236-94qc Rand is unsound with a custom logger using rand::rng()GHSA-mc8h-8q98-g5hr Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_allYour dependencies cross-checked against the OSV vulnerability database.
GHSA-4g74-7cff-xcv8 youki container escape via "masked path" abuse due to mount race conditionsGHSA-vf95-55w6-qmrf youki container escape and denial of service due to arbitrary write gadgets and procfs write redirectsGHSA-7f6x-jwh5-m9r4 Cranelift vulnerable to miscompilation of constant values in division on AArch64GHSA-jqwc-c49r-4w2x Miscompilation of `i8x16.swizzle` and `select` with v128 inputsGHSA-m4ch-rfv5-x5g3 git2-rs fails to verify SSH keys by defaultRUSTSEC-2024-0421 `idna` accepts Punycode labels that do not produce any non-ASCII when decodedGHSA-5w4j-f78p-4wh9 Libcontainer is affected by capabilities elevation similar to GHSA-f3fp-gc8g-vw66RUSTSEC-2023-0003 git2 does not verify SSH keys by defaultRUSTSEC-2024-0013 Memory corruption, denial of service, and arbitrary code execution in libgit2RUSTSEC-2024-0019 Tokens for named pipes may be delivered after deregistrationRUSTSEC-2024-0437 Crash due to uncontrolled recursion in protobuf crateGHSA-c827-hfw6-qwvm rustix's `rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosionRUSTSEC-2026-0067 `unpack_in` can chmod arbitrary directories by following symlinksRUSTSEC-2026-0068 tar-rs incorrectly ignores PAX size headers if header size is nonzeroRUSTSEC-2020-0071 Potential segfault in the time crateRUSTSEC-2026-0009 Denial of Service via Stack ExhaustionGHSA-j26p-6wx7-f3pw Youki: If /proc and /sys in the rootfs are symbolic links, they can potentially be exploited to gain access to the host root filesystem.RUSTSEC-2026-0008 Potential undefined behavior when dereferencing Buf structGHSA-55f3-3qvg-8pv5 Symlink bypasses filesystem sandboxRUSTSEC-2025-0056 adler crate is unmaintained, use adler2 insteadRUSTSEC-2026-0190 Unsoundness in `Error::downcast_mut()`RUSTSEC-2023-0015 Ascii allows out-of-bounds array indexing in safe codeRUSTSEC-2021-0145 Potential unaligned readRUSTSEC-2024-0375 `atty` is unmaintainedRUSTSEC-2022-0078 Use-after-free due to a lifetime error in `Vec::into_iter()`Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.