Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2021-44732 Mbed TLS before 3.0.1 has a double free in certain out-of-memory condi ...CVE-2022-35409 An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0 ...CVE-2022-46393 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0 ...CVE-2025-47917 Mbed TLS before 3.6.4 allows a use-after-free in certain situations of ...CVE-2021-20236 zeromq: Stack overflow on server running PUB/XPUB socketCVE-2022-37434 zlib: heap-based buffer over-read and overflow in inflate() in inflate.c via a large gzip header extra fieldCVE-2023-45853 zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6CVE-2025-50178 Lack of validation for user-provided fields in GitForge.jlCVE-2025-52569 Lack of validation for user-provided fields in GitHub.jlCVE-2025-52479 CR/LF injection in URIs.jl (also affects HTTP.jl)CVE-2025-61689 Header injection/Response splitting via header construction.CVE-2020-36475 An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 L ...CVE-2020-36478 An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 L ...CVE-2021-43666 A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier ...CVE-2021-45450 In Mbed TLS before 2.28.0 and 3.x before 3.1.0, `psa_cipher_generate_iv` and `psa_cipher_encrypt`...CVE-2021-45451 In Mbed TLS before 3.1.0, `psa_aead_generate_nonce` allows policy bypass or oracle-based decryption...CVE-2023-43615 Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.CVE-2024-23775 Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x b ...CVE-2024-28960 mbedtls: Insecure handling of shared memory in PSA Crypto APIsCVE-2025-48965 Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_a ...CVE-2025-52496 Mbed TLS before 3.6.4 has a race condition in AESNI detection if certa ...CVE-2021-24119 In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in b ...CVE-2021-36647 Use of a Broken or Risky Cryptographic Algorithm in the function mbedt ...CVE-2022-46392 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0 ...CVE-2024-23170 An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3 ...Your dependencies cross-checked against the OSV vulnerability database.
Nothing found by this check. ✓
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.