gitsafehub
github.com/sarlinpe/hfnet ↗

sarlinpe/hfnet

scanned 2026-08-12 · git 83c90e6
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 3 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies402Known OSS vulnerabilities430Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 400s

Vulnerable dependencies — Trivy 402 found · 5 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2021-41208 Incomplete validation in boosted trees code
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-41208). Fix: Update that package to its patched version.
  • Serious CVE-2023-25668 CVE-2023-25668 affecting package tensorflow for versions less than 2.11.1-1
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2023-25668). Fix: Update that package to its patched version.
  • Serious GHSA-h6gw-r52c-724r NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlow
    setup/requirements.txt
    A package you depend on has a known security hole (GHSA-h6gw-r52c-724r). Fix: Update that package to its patched version.
  • Serious CVE-2022-45907 In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line c ...
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2022-45907). Fix: Update that package to its patched version.
  • Serious CVE-2025-32434 PyTorch is a Python package that provides tensor computation with stro ...
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2025-32434). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-9635 NULL Pointer Dereference in Google TensorFlow
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2019-9635). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-15202 Integer truncation in Shard API usage
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15202). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-15203 Denial of Service in Tensorflow
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15203). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-15206 Denial of Service in Tensorflow
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15206). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-15208 Data corruption in tensorflow-lite
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15208). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-15209 Null pointer dereference in tensorflow-lite
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15209). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-15210 Segmentation fault in tensorflow-lite
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15210). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-15265 Segfault in `tf.quantization.quantize_and_dequantize`
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15265). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-29591 Stack overflow due to looping TFLite subgraph
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-29591). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-37635 Heap out of bounds access in sparse reduction operations
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37635). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-37637 Null pointer dereference in `CompressElement`
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37637). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-37638 Null pointer dereference in `RaggedTensorToTensor`
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37638). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-37639 Null pointer dereference and heap OOB read in operations restoring tensors
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37639). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-37643 Null pointer dereference in `MatrixDiagPartOp`
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37643). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-37647 Null pointer dereference in `SparseTensorSliceDataset`
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37647). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-37648 Incorrect validation of `SaveV2` inputs
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37648). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-37649 Null pointer dereference in `UncompressElement`
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37649). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-37650 Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord`
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37650). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-37651 Heap buffer overflow in `FractionalAvgPoolGrad`
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37651). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-37652 Use after free in boosted trees creation
    setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37652). Fix: Update that package to its patched version.
… 377 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 430 found · 10 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2020-317 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a function taking two `int64` (i.e., `long long`) arguments. However,
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15202). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-320 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values that can cause heap ove
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15205). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-321 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buffer and altering the name of required keys results in segfaults and data corrupt
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15206). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-815 TensorFlow is an open source platform for machine learning. In affected versions the code for boosted trees in TensorFlow is still missing validation. As a result, attackers can trigger denial of serv
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-41208). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-550 TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2023-25668). Fix: Update that package to its patched version.
  • Serious GHSA-h6gw-r52c-724r NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlow
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-r6jx-9g48-2r5r Arbitrary code execution due to YAML deserialization
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37678). Fix: Update that package to its patched version.
  • Serious PYSEC-2022-43015 In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2022-45907). Fix: Update that package to its patched version.
  • Serious PYSEC-2024-259 In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2024-48063). Fix: Update that package to its patched version.
  • Serious PYSEC-2025-41 PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command E
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2025-32434). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2019-235 NULL pointer dereference in Google TensorFlow before 1.12.2 could cause a denial of service via an invalid GIF file.
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2019-9635). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-305 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `tf.raw_ops.Switch` operation takes as input a tensor and a boolean and outputs two tensors. Depending on the boolean value, on
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15190). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-309 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has incomplete validation of the shapes of its arguments. Although `reverse_index_map_
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15194). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-310 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the implementation of `SparseFillEmptyRowsGrad` uses a double indexing pattern. It is possible for `reverse_index_map(i)` to be an
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15195). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-318 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, by controlling the `fill` argument of tf.strings.as_string, a malicious attacker is able to trigger a format string vulnerability d
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15203). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-319 In eager mode, TensorFlow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1 does not set the session state. Hence, calling `tf.raw_ops.GetSessionHandle` or `tf.raw_ops.GetSessionHandleV2` results
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15204). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-322 In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, to mimic Python's indexing with negative values, TFLite uses `ResolveAxis` to convert negative values to positive indices. How
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15207). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-323 In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15208). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-324 In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a `nullptr` buffer. This can be achieved by changi
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15209). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-325 In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15210). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-326 In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15211). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-330 In Tensorflow before version 2.4.0, an attacker can pass an invalid `axis` value to `tf.quantization.quantize_and_dequantize`. This results in accessing a dimension outside the rank of the input tenso
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15265). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-331 In Tensorflow before version 2.4.0, when the `boxes` argument of `tf.image.crop_and_resize` has a very large value, the CPU kernel implementation receives it as a C++ `nan` floating point value. Attem
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15266). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-332 In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code execution. This is caused by having tensor buffers be filled with the default v
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-26266). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-333 In affected versions of TensorFlow the tf.raw_ops.DataFormatVecPermute API does not validate the src_format and dst_format attributes. The code assumes that these two arguments define a permutation of
    /workdirs/scan-8b3f32d5-792d-4cef-bc6e-e539b8cbdf27/setup/requirements.txt
    A package you depend on has a known security hole (CVE-2020-26267). Fix: Update that package to its patched version.
… 405 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: pypi:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.