Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.kubernetes-secret-yaml Possible Kubernetes Secret detected, posing a risk of leaking credentials/tokens from your deploymentsprivate-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.kubernetes-secret-yaml Possible Kubernetes Secret detected, posing a risk of leaking credentials/tokens from your deploymentsgeneric-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2022-1996 go-restful: Authorization Bypass Through User-Controlled KeyGHSA-r277-6w6q-xmqw kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc DefaultCVE-2022-40083 Labstack Echo v4.8.0 was discovered to contain an open redirect vulner ...CVE-2020-26892 The JWT library in NATS nats-server before 2.1.9 has Incorrect Access ...CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2022-1996 go-restful: Authorization Bypass Through User-Controlled KeyCVE-2022-1996 go-restful: Authorization Bypass Through User-Controlled KeyGHSA-r277-6w6q-xmqw kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc DefaultCVE-2022-40083 Labstack Echo v4.8.0 was discovered to contain an open redirect vulner ...CVE-2020-26892 The JWT library in NATS nats-server before 2.1.9 has Incorrect Access ...CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2022-1996 go-restful: Authorization Bypass Through User-Controlled KeyGHSA-r277-6w6q-xmqw kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc DefaultCVE-2022-40083 Labstack Echo v4.8.0 was discovered to contain an open redirect vulner ...CVE-2020-26892 The JWT library in NATS nats-server before 2.1.9 has Incorrect Access ...CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2022-1996 go-restful: Authorization Bypass Through User-Controlled KeyGHSA-r277-6w6q-xmqw kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc DefaultCVE-2022-40083 Labstack Echo v4.8.0 was discovered to contain an open redirect vulner ...CVE-2020-26892 The JWT library in NATS nats-server before 2.1.9 has Incorrect Access ...CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2026-41602 github.com/apache/thrift: Apache Thrift: Integer Overflow in TFramedTransport Go implementationYour dependencies cross-checked against the OSV vulnerability database.
GO-2022-0588 Cross-site scripting via leaked style elements in github.com/microcosm-cc/bluemondayGO-2026-4762 Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpcGO-2022-0619 Authorization bypass in github.com/emicklei/go-restful, go-restful/v2 and go-restful/v3GHSA-7jwh-3vrq-q3m8 pgproto3 SQL Injection via Protocol Message Size OverflowGO-2024-2606 SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgxGO-2024-2606 SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgxGO-2024-2606 SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgxGO-2022-1031 Open redirect in github.com/labstack/echo/v4GO-2022-0380 Incorrect handling of credential expiry in github.com/nats-io/jwtGO-2024-3321 Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/cryptoGO-2026-5005 Invoking key constraints not enforced in golang.org/x/crypto/ssh/agentGO-2026-5006 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agentGO-2026-5017 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshGO-2026-5019 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshGO-2026-5020 Invoking infinite loop on large channel writes in golang.org/x/crypto/sshGO-2026-5021 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhostsGO-2026-5023 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshGO-2024-3321 Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/cryptoGO-2026-5005 Invoking key constraints not enforced in golang.org/x/crypto/ssh/agentGO-2026-5006 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agentGO-2026-5017 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshGO-2026-5019 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshGO-2026-5020 Invoking infinite loop on large channel writes in golang.org/x/crypto/sshGO-2026-5021 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhostsGO-2026-5023 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.