gitsafehub
github.com/samuelkarp/bottlerocket ↗

samuelkarp/bottlerocket

scanned 2026-08-14 · git 182d272
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies208Known OSS vulnerabilities350Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 208 found · 7 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2020-35902 Use-after-free in actix-codec
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35902). Fix: Update that package to its patched version.
  • Serious CVE-2020-35898 Use after free in actix-utils
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35898). Fix: Update that package to its patched version.
  • Serious CVE-2020-25573 An issue was discovered in the linked-hash-map crate before 0.5.3 for ...
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-25573). Fix: Update that package to its patched version.
  • Serious GHSA-9q5j-jm53-v7vr lz4-sys vulnerable to memory corruption via issue in liblz4
    sources/Cargo.lock
    A package you depend on has a known security hole (GHSA-9q5j-jm53-v7vr). Fix: Update that package to its patched version.
  • Serious CVE-2021-25900 An issue was discovered in the smallvec crate before 0.6.14 and 1.x be ...
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-25900). Fix: Update that package to its patched version.
  • Serious CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
    sources/host-ctr/cmd/host-ctr/go.mod
    A package you depend on has a known security hole (CVE-2026-33186). Fix: Update that package to its patched version.
  • Serious CVE-2021-25900 An issue was discovered in the smallvec crate before 0.6.14 and 1.x be ...
    tools/buildsys/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-25900). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-35372 A logic error in the ln utility of uutils coreutils allows the utility ...
    packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35372). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-35380 A logic error in the cut utility of uutils coreutils causes the progra ...
    packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35380). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-35901 Use-after-free in actix-http
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35901). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-38512 rust-actix-http: potential request smuggling capabilities due to lack of input validation
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-38512). Fix: Update that package to its patched version.
  • Worth fixing GHSA-xhj4-vrgc-hr34 actix-http has HTTP/1.1 CL.TE Request Smuggling
    sources/Cargo.lock
    A package you depend on has a known security hole (GHSA-xhj4-vrgc-hr34). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-35899 Use after free in actix-service
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35899). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-35711 An issue has been discovered in the arc-swap crate before 0.4.8 (and 1 ...
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35711). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-35861 An issue was discovered in the bumpalo crate before 3.2.1 for Rust. Th ...
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35861). Fix: Update that package to its patched version.
  • Worth fixing GHSA-f85w-wvc7-crwc bumpalo has use-after-free due to a lifetime error in `Vec::into_iter()`
    sources/Cargo.lock
    A package you depend on has a known security hole (GHSA-f85w-wvc7-crwc). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-23639 crossbeam-utils provides atomics, synchronization primitives, scoped t ...
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2022-23639). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-35906 futures_task::waker may cause a use-after-free if used on a type that isn't 'static
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35906). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-35907 futures_task::noop_waker_ref can segfault due to dereferencing a NULL pointer
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35907). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-35905 MutexGuard::map can cause a data race in safe code
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35905). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-36465 An issue was discovered in the generic-array crate before 0.13.3 for R ...
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-36465). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-26964 An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occ ...
    sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2023-26964). Fix: Update that package to its patched version.
  • Worth fixing GHSA-8r5v-vm4m-4g25 Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
    sources/Cargo.lock
    A package you depend on has a known security hole (GHSA-8r5v-vm4m-4g25). Fix: Update that package to its patched version.
  • Worth fixing GHSA-q6cp-qfwq-4gcv h2 servers vulnerable to degradation of service with CONTINUATION Flood
    sources/Cargo.lock
    A package you depend on has a known security hole (GHSA-q6cp-qfwq-4gcv). Fix: Update that package to its patched version.
  • Worth fixing GHSA-f67m-9j94-qv9j Parser creates invalid uninitialized value
    sources/Cargo.lock
    A package you depend on has a known security hole (GHSA-f67m-9j94-qv9j). Fix: Update that package to its patched version.
… 183 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 350 found · 11 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious RUSTSEC-2019-0006 Buffer overflow and format vulnerabilities in functions exposed without unsafe
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2019-15547). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2020-0049 Use-after-free in Framed due to lack of pinning
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35902). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2020-0045 bespoke Cell implementation allows obtaining several mutable references to the same data
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-35898). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2019-0036 Type confusion if __private_get_type_id__ is overridden
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2019-25010). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2021-0079 Integer overflow in `hyper`'s parsing of the `Transfer-Encoding` header leads to data loss
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32714). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2020-0026 linked-hash-map creates uninitialized NonNull pointer
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2020-25573). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2022-0051 Memory corruption in liblz4
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/sources/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious RUSTSEC-2021-0003 Buffer overflow in SmallVec::insert_many
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/sources/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-25900). Fix: Update that package to its patched version.
  • Serious GO-2026-4762 Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/sources/host-ctr/cmd/host-ctr/go.sum
    A package you depend on has a known security hole (CVE-2026-33186). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2021-0079 Integer overflow in `hyper`'s parsing of the `Transfer-Encoding` header leads to data loss
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/tools/buildsys/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-32714). Fix: Update that package to its patched version.
  • Serious RUSTSEC-2021-0003 Buffer overflow in SmallVec::insert_many
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/tools/buildsys/Cargo.lock
    A package you depend on has a known security hole (CVE-2021-25900). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2m8x-mvfx-gwgj uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35357). Fix: Update that package to its patched version.
  • Worth fixing GHSA-4wrp-79m8-9m9p uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35374). Fix: Update that package to its patched version.
  • Worth fixing GHSA-6g8r-74qp-6859 uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35376). Fix: Update that package to its patched version.
  • Worth fixing GHSA-957r-r8gc-vv3h uutils coreutils doesn't preserve file ownership during moves across different filesystem boundaries
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35351). Fix: Update that package to its patched version.
  • Worth fixing GHSA-9gh9-hwpr-rvqq uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35352). Fix: Update that package to its patched version.
  • Worth fixing GHSA-f2jv-wjjc-2c94 uutils coreutils has an Uncaught Exception When Encountering Valid but Non-UTF-8 Paths
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35348). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hpfw-mqm3-33jh uutils coreutils has a Link Following issue
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35359). Fix: Update that package to its patched version.
  • Worth fixing GHSA-m2pg-c7m6-77pj uutils coreutils has an Improper Input Validation Issue in its cut Utility
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35380). Fix: Update that package to its patched version.
  • Worth fixing GHSA-m976-87wm-48fm uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35364). Fix: Update that package to its patched version.
  • Worth fixing GHSA-mh5c-xrmh-m794 uutils coreutils has an Untrusted Search Path
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35368). Fix: Update that package to its patched version.
  • Worth fixing GHSA-q6m9-xj2w-xmrc uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35360). Fix: Update that package to its patched version.
  • Worth fixing GHSA-wq63-vh5h-pr5p uutils coreutils has a UNIX Symbolic Link (Symlink) Following issue
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35372). Fix: Update that package to its patched version.
  • Worth fixing GHSA-x2wv-9p67-mh9w uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35350). Fix: Update that package to its patched version.
  • Worth fixing GHSA-x4mc-mqm7-gg39 uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition
    /workdirs/scan-ccb1a31d-8a2d-471e-89f6-067cdad18f4b/packages/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-35354). Fix: Update that package to its patched version.
… 325 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.