Xeol scanner #244
Xeol scanner #244
15 new security issues (0 max.).
Annotations
Check warning on line 28 in Dockerfile
codacy-production / Codacy Static Code Analysis
Dockerfile#L28
Only the exit code from the final command in this RUN instruction will be evaluated unless 'pipefail' is set.
Check warning on line 69 in Dockerfile
codacy-production / Codacy Static Code Analysis
Dockerfile#L69
Detected docker image with no explicit version attached.
Check warning on line 305 in go.mod
codacy-production / Codacy Static Code Analysis
go.mod#L305
Insecure dependency golang/github.com/mholt/archiver/v3@v3.5.1 (CVE-2024-0406: mholt/archiver: path traversal vulnerability) (no fix available)
Check warning on line 305 in go.mod
codacy-production / Codacy Static Code Analysis
go.mod#L305
Insecure dependency golang/github.com/mholt/archiver/v3@v3.5.1 (CVE-2025-3445: mholt/archiver: A Path Traversal "Zip Slip" vulnerability in mholt/archiver) (no fix available)
Check warning on line 336 in go.mod
codacy-production / Codacy Static Code Analysis
go.mod#L336
Insecure dependency golang/github.com/nwaples/rardecode@v1.1.2 (CVE-2025-11579: github.com/nwaples/rardecode: RarDecode Out Of Memory Crash) (no fix available)
Check warning on line 12 in internal/openssfdb/writer.go
codacy-production / Codacy Static Code Analysis
internal/openssfdb/writer.go#L12
Detected file permissions that are set to more than `0600` (user/owner can read and write). Setting file permissions to higher than `0600` is most likely unnecessary and violates the principle of least privilege.
Check warning on line 12 in internal/openssfdb/writer.go
codacy-production / Codacy Static Code Analysis
internal/openssfdb/writer.go#L12
The application was found setting directory permissions to overly permissive values.
Check failure on line 54 in test-cve-2025-55182/src/javascript/package-lock.json
codacy-production / Codacy Static Code Analysis
test-cve-2025-55182/src/javascript/package-lock.json#L54
Insecure dependency npm/react-server-dom-webpack@19.0.0 (CVE-2025-55182: next: React Server Components: Pre-authentication remote code execution via unsafe deserialization) (update to 19.0.1)
Check warning on line 54 in test-cve-2025-55182/src/javascript/package-lock.json
codacy-production / Codacy Static Code Analysis
test-cve-2025-55182/src/javascript/package-lock.json#L54
Insecure dependency npm/react-server-dom-webpack@19.0.0 (CVE-2025-55183: next: React Server Components: Source code exposure through crafted HTTP request) (update to 19.0.2)
Check warning on line 54 in test-cve-2025-55182/src/javascript/package-lock.json
codacy-production / Codacy Static Code Analysis
test-cve-2025-55182/src/javascript/package-lock.json#L54
Insecure dependency npm/react-server-dom-webpack@19.0.0 (CVE-2025-55184: next: React Server Components: Denial of Service via unsafe HTTP deserialization) (update to 19.0.2)
Check warning on line 54 in test-cve-2025-55182/src/javascript/package-lock.json
codacy-production / Codacy Static Code Analysis
test-cve-2025-55182/src/javascript/package-lock.json#L54
Insecure dependency npm/react-server-dom-webpack@19.0.0 (CVE-2026-23864: React Server Components have multiple Denial of Service Vulnerabilities) (update to 19.0.4)
Check failure on line 1 in test-eol-project/package-lock.json
codacy-production / Codacy Static Code Analysis
test-eol-project/package-lock.json#L1
File test-eol-project/package-lock.json has 1554 non-comment lines of code
Check failure on line 458 in test-eol-project/package-lock.json
codacy-production / Codacy Static Code Analysis
test-eol-project/package-lock.json#L458
Insecure dependency npm/form-data@2.3.3 (CVE-2025-7783: form-data: Unsafe random function in form-data) (update to 2.5.4)
Check warning on line 1042 in test-eol-project/package-lock.json
codacy-production / Codacy Static Code Analysis
test-eol-project/package-lock.json#L1042
Insecure dependency npm/qs@6.5.5 (CVE-2025-15284: qs: qs: Denial of Service via improper input validation in array parsing) (update to 6.14.1)
Check warning on line 1066 in test-eol-project/package-lock.json
codacy-production / Codacy Static Code Analysis
test-eol-project/package-lock.json#L1066
Insecure dependency npm/request@2.88.2 (CVE-2023-28155: request: bypass of SSRF mitigations when following a cross-protocol redirect) (no fix available)
Check notice on line 1302 in test-eol-project/package-lock.json
codacy-production / Codacy Static Code Analysis
test-eol-project/package-lock.json#L1302
Insecure dependency npm/tmp@0.0.30 (CVE-2025-54798: tmp: tmp Symbolic Link Write Vulnerability) (update to 0.2.4)
Check warning on line 1314 in test-eol-project/package-lock.json
codacy-production / Codacy Static Code Analysis
test-eol-project/package-lock.json#L1314
Insecure dependency npm/tough-cookie@2.5.0 (CVE-2023-26136: tough-cookie: prototype pollution in cookie memstore) (update to 4.1.3)
Check warning on line 1490 in test-eol-project/package-lock.json
codacy-production / Codacy Static Code Analysis
test-eol-project/package-lock.json#L1490
Insecure dependency npm/xml2js@0.4.23 (CVE-2023-0842: node-xml2js: xml2js is vulnerable to prototype pollution) (update to 0.5.0)