Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-34040 Moby: Moby: Authorization bypass vulnerabilityCVE-2026-33997 moby: docker: github.com/moby/moby: Moby: Privilege validation bypass during plugin installationCVE-2026-56852 golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 inputCVE-2025-54410 github.com/moby/moby: Moby's Firewalld reload removes bridge network isolationCVE-2026-46600 Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...Your dependencies cross-checked against the OSV vulnerability database.
GO-2026-4883 Moby has an Off-by-one error in its plugin privilege validation in github.com/docker/dockerGO-2026-4887 Moby has AuthZ plugin bypass when provided oversized request bodies in github.com/docker/dockerGO-2026-5617 Race condition in 'docker cp' in github.com/docker/docker allows bind mount redirectionGO-2026-5668 Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap in github.com/docker/dockerGO-2026-5746 Docker: 'PUT /containers/{id}/archive' executes container binary on the host in github.com/docker/dockerGHSA-4vq8-7jfc-9cvp Moby firewalld reload removes bridge network isolationGO-2026-5064 containerd CRI checkpoint restore CDI annotation smuggling in github.com/containerd/containerdGO-2026-5338 containerd: CRI checkpoint import allows local image tag poisoning in github.com/containerd/containerdGO-2026-5622 Arbitrary host CRI log file read via symlink following in CRI checkpoint restore in github.com/containerd/containerdGO-2026-5841 OOB read in github.com/klauspost/compress/s2GO-2026-5158 Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otelGO-2026-5932 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issuesGO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessageGO-2026-5970 Infinite loop on invalid input in golang.org/x/textGO-2025-4155 Excessive resource consumption when printing error string for host certificate validation in crypto/x509GO-2025-4175 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509GO-2026-4337 Unexpected session resumption in crypto/tlsGO-2026-4340 Handshake messages may be processed at the incorrect encryption level in crypto/tlsGO-2026-4341 Memory exhaustion in query parameter parsing in net/urlGO-2026-4342 Excessive CPU consumption when building archive index in archive/zipGO-2026-4601 Incorrect parsing of IPv6 host literals in net/urlGO-2026-4602 FileInfo can escape from a Root in osGO-2026-4603 URLs in meta content attribute actions are not escaped in html/templateGO-2026-4864 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unixGO-2026-4865 JsBraceDepth Context Tracking Bugs (XSS) in html/templateCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.