Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
github-pat Uncovered a GitHub Personal Access Token, potentially leading to unauthorized repository access and sensitive content exposure.Packages you depend on that have known security holes (CVEs).
CVE-2026-71556 go-git is an extensible git implementation library written in pure Go. ...CVE-2026-71557 go-git is an extensible git implementation library written in pure Go. ...CVE-2026-46600 golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsingYour dependencies cross-checked against the OSV vulnerability database.
GHSA-hc8v-wwc9-vgxm go-git: Worktree operations may follow symlinksGHSA-qgq7-7hm3-q39j go-git: Malicious reference names may modify files outside the reference storageGO-2026-5841 OOB read in github.com/klauspost/compress/s2GO-2026-5932 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issuesGO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessageGO-2026-4970 Root escape via symlink plus trailing slash in osGO-2026-5037 Inefficient candidate hostname parsing in crypto/x509GO-2026-5038 Quadratic complexity in WordDecoder.DecodeHeader in mimeGO-2026-5039 Arbitrary inputs are included in errors without any escaping in net/textprotoGO-2026-5856 Invoking Encrypted Client Hello privacy leak in crypto/tlsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.