gitsafehub
github.com/vchuravy/yggdrasil ↗

vchuravy/yggdrasil

scanned 2026-08-13 · git 15038bd
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets5Vulnerable dependencies49Known OSS vulnerabilitiesRisky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 5 found

API keys, passwords or tokens committed into the repo.

  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    H/hidapi/build_tarballs.jl:10
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    A/AccerionSensorAPI/build_tarballs.jl:10
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    A/AccerionSensorAPI/build_tarballs.jl:41
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    H/hidapi/build_tarballs.jl:10
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    P/Perl/build_tarballs.jl:14
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 49 found · 7 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2021-44732 Mbed TLS before 3.0.1 has a double free in certain out-of-memory condi ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2021-44732). Fix: Update that package to its patched version.
  • Serious CVE-2022-35409 An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0 ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2022-35409). Fix: Update that package to its patched version.
  • Serious CVE-2022-46393 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0 ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2022-46393). Fix: Update that package to its patched version.
  • Serious CVE-2025-47917 Mbed TLS before 3.6.4 allows a use-after-free in certain situations of ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2025-47917). Fix: Update that package to its patched version.
  • Serious CVE-2021-20236 zeromq: Stack overflow on server running PUB/XPUB socket
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2021-20236). Fix: Update that package to its patched version.
  • Serious CVE-2022-37434 zlib: heap-based buffer over-read and overflow in inflate() in inflate.c via a large gzip header extra field
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2022-37434). Fix: Update that package to its patched version.
  • Serious CVE-2023-45853 zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-45853). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-50178 Lack of validation for user-provided fields in GitForge.jl
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2025-50178). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-52569 Lack of validation for user-provided fields in GitHub.jl
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2025-52569). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-52479 CR/LF injection in URIs.jl (also affects HTTP.jl)
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2025-52479). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-61689 Header injection/Response splitting via header construction.
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2025-61689). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-36475 An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 L ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2020-36475). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-36478 An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 L ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2020-36478). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-43666 A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2021-43666). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-45450 In Mbed TLS before 2.28.0 and 3.x before 3.1.0, `psa_cipher_generate_iv` and `psa_cipher_encrypt`...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2021-45450). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-45451 In Mbed TLS before 3.1.0, `psa_aead_generate_nonce` allows policy bypass or oracle-based decryption...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2021-45451). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-43615 Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2023-43615). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-23775 Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x b ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2024-23775). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-28960 mbedtls: Insecure handling of shared memory in PSA Crypto APIs
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2024-28960). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-48965 Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_a ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2025-48965). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-52496 Mbed TLS before 3.6.4 has a race condition in AESNI detection if certa ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2025-52496). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-24119 In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in b ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2021-24119). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-36647 Use of a Broken or Risky Cryptographic Algorithm in the function mbedt ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2021-36647). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-46392 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0 ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2022-46392). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-23170 An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3 ...
    .ci/Manifest.toml
    A package you depend on has a known security hole (CVE-2024-23170). Fix: Update that package to its patched version.
… 24 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner none found ✓

Your dependencies cross-checked against the OSV vulnerability database.

Nothing found by this check. ✓

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.