Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2023-44981 zookeeper: Authorization Bypass in Apache ZooKeeperCVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of serviceCVE-2023-2976 guava: insecure temporary directory creationCVE-2017-5637 zookeeper: Incorrect input validation with wchp/wchc four letter wordsCVE-2018-8012 zookeeper: No authentication or authorization is enforced when a server joins a quorumCVE-2019-0201 zookeeper: Information disclosure in Apache ZooKeeperCVE-2020-8908 guava: local information disclosure via temporary directory created with unsafe permissionsYour dependencies cross-checked against the OSV vulnerability database.
GHSA-cqqj-4p63-rrmm HTTP Request Smuggling in NettyGHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4jGHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.xGHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4jGHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeperGHSA-c27h-mcmw-48hv Deserialization of Untrusted Data in org.codehaus.jackson:jackson-mapper-aslGHSA-7g45-4rm6-3mm3 Guava vulnerable to insecure use of temporary directoryGHSA-mvr2-9pj6-7w5j Denial of Service in Google GuavaGHSA-5mcr-gq6c-3hq2 Local Information Disclosure Vulnerability in Netty on Unix-Like systemsGHSA-9vjp-v76f-g363 SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary wayGHSA-f256-j965-7f32 Possible request smuggling in HTTP/2 due missing validation of content-lengthGHSA-grg4-wf29-r9vv Bzip2Decoder doesn't allow setting size restrictions for decompressed dataGHSA-p979-4mfw-53vg HTTP Request Smuggling in NettyGHSA-wm47-8v5p-wjpj Possible request smuggling in HTTP/2 due missing validationGHSA-wx5j-54mm-rqqq HTTP request smuggling in nettyGHSA-xfv3-rrfm-f2rv Information Exposure in NettyGHSA-fp5r-v3w9-4333 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted dataGHSA-vp98-w2p3-mv35 Apache Log4j 1.x (EOL) allows Denial of Service (DoS)GHSA-w9p3-5cr8-m3jj Deserialization of Untrusted Data in Log4j 1.xGHSA-2hw2-62cp-p9p7 Access control bypass in Apache ZooKeeperGHSA-7cwj-j333-x7f7 Uncontrolled Resource Consumption in Apache ZooKeeperGHSA-ccqf-c5hq-77mp Missing Authorization in Apache ZooKeeperGHSA-r6j9-8759-g62w Improper Restriction of XML External Entity Reference in jackson-mapper-aslGHSA-5mg8-w23w-74h3 Information Disclosure in GuavaGHSA-7vpq-g998-qpv7 Netty denial of service vulnerabilityCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.