Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Your dependencies cross-checked against the OSV vulnerability database.
PYSEC-2026-2120 Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use fromRUSTSEC-2022-0013 Regexes with large repetitions on empty sub-expressions take a very long time to parseRUSTSEC-2022-0013 Regexes with large repetitions on empty sub-expressions take a very long time to parseRUSTSEC-2022-0013 Regexes with large repetitions on empty sub-expressions take a very long time to parsePYSEC-2026-2121 Black is the uncompromising Python code formatter. Prior to 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics optiPYSEC-2026-2132 Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.RUSTSEC-2022-0006 Data race in `Iter` and `IterMut`RUSTSEC-2022-0006 Data race in `Iter` and `IterMut`Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-pypi-code-execution code-execution match in packaging 24.2A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.