CRIT
MINED035
[MINED035] Js New Function: new Function(...) compiles strings to functions.
sample/34-using-esm-packages/src/import…:8
CRIT
DKC007
Compose service contains a literal secret environment value
integration/docker-compose.yml:26
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
readme_kr.md:5
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
readme_zh.md:5
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
packages/testing/Readme.md:5
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
readme_jp.md:5
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
packages/microservices/Readme.md:5
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
packages/core/Readme.md:5
CRIT
private-key
Identified a Private Key, which may compromise cryptographic security and sensitive data …
integration/microservices/src/tcp-tls/p…:1
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
packages/common/Readme.md:5
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
Readme.md:5
CRIT
GHSA-fjxv-7rqg-78g4
form-data: GHSA-fjxv-7rqg-78g4
package-lock.json
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
packages/platform-fastify/adapters/midd…:188
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
packages/core/router/utils/exclude-rout…:19
HIGH
SEC040
[SEC040] innerHTML XSS — template literal with server-supplied data: Setting .innerHTML w…
packages/common/pipes/parse-array.pipe.…:133
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
packages/core/router/routes-resolver.ts:150
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
packages/core/adapters/http-adapter.ts:168
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
packages/common/pipes/file/file-type.va…:145
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
packages/core/repl/repl-context.ts:132
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
packages/core/injector/topology-tree/tr…:16
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
integration/inspector/src/cats/cats.con…:15
HIGH
DKC013
Database service has no persistent data volume
sample/14-mongoose-base/docker-compose.…:3
HIGH
DKC013
Database service has no persistent data volume
sample/13-mongo-typeorm/docker-compose.…:3
HIGH
DKC013
Database service has no persistent data volume
sample/07-sequelize/docker-compose.yml:3
HIGH
DKC013
Database service has no persistent data volume
sample/06-mongoose/docker-compose.yml:3
HIGH
DKC013
Database service has no persistent data volume
sample/05-sql-typeorm/docker-compose.yml:11
HIGH
DKC013
Database service has no persistent data volume
sample/05-sql-typeorm/docker-compose.yml:3
HIGH
DKC013
Database service has no persistent data volume
integration/docker-compose.yml:35
HIGH
DKC013
Database service has no persistent data volume
integration/docker-compose.yml:26
HIGH
MINED115
Action `github/codeql-action/analyze` pinned to mutable ref `@v4`
.github/workflows/codeql-analysis.yml:61
HIGH
MINED115
Action `github/codeql-action/autobuild` pinned to mutable ref `@v4`
.github/workflows/codeql-analysis.yml:47
HIGH
MINED115
Action `github/codeql-action/init` pinned to mutable ref `@v4`
.github/workflows/codeql-analysis.yml:37
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/codeql-analysis.yml:24
HIGH
GHSA-r6q2-hw4h-h46w
tar: GHSA-r6q2-hw4h-h46w
package-lock.json
HIGH
GHSA-qffp-2rhf-9h96
tar: GHSA-qffp-2rhf-9h96
package-lock.json
HIGH
GHSA-9ppj-qmqm-q256
tar: GHSA-9ppj-qmqm-q256
package-lock.json
HIGH
GHSA-8qq5-rm4j-mr97
tar: GHSA-8qq5-rm4j-mr97
package-lock.json
HIGH
GHSA-83g3-92jg-28cx
tar: GHSA-83g3-92jg-28cx
package-lock.json
HIGH
GHSA-34x7-hfp2-rc4v
tar: GHSA-34x7-hfp2-rc4v
package-lock.json
HIGH
GHSA-5c6j-r48x-rmvq
serialize-javascript: GHSA-5c6j-r48x-rmvq
package-lock.json
HIGH
GHSA-35jh-r3h4-6jhm
lodash.template: GHSA-35jh-r3h4-6jhm
package-lock.json
HIGH
GHSA-h6ch-v84p-w6p9
diff: GHSA-h6ch-v84p-w6p9
package-lock.json
HIGH
GHSA-grv7-fg5c-xmjg
braces: GHSA-grv7-fg5c-xmjg
package-lock.json
HIGH
DKC011
Database service publishes a host port
sample/26-queues/docker-compose.yml:2
HIGH
DKC011
Database service publishes a host port
sample/14-mongoose-base/docker-compose.…:3
HIGH
DKC011
Database service publishes a host port
sample/13-mongo-typeorm/docker-compose.…:3
HIGH
DKC011
Database service publishes a host port
sample/07-sequelize/docker-compose.yml:3
HIGH
DKC011
Database service publishes a host port
sample/06-mongoose/docker-compose.yml:3
HIGH
DKC011
Database service publishes a host port
sample/05-sql-typeorm/docker-compose.yml:11
HIGH
DKC011
Database service publishes a host port
sample/05-sql-typeorm/docker-compose.yml:3
HIGH
DKC011
Database service publishes a host port
integration/docker-compose.yml:59
HIGH
DKC011
Database service publishes a host port
integration/docker-compose.yml:50
HIGH
DKC011
Database service publishes a host port
integration/docker-compose.yml:42
HIGH
DKC011
Database service publishes a host port
integration/docker-compose.yml:35
HIGH
DKC011
Database service publishes a host port
integration/docker-compose.yml:26
HIGH
DKC011
Database service publishes a host port
integration/docker-compose.yml:3
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
integration/inspector/src/database/data…:41
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
integration/inspector/src/cats/cats.con…:23
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
integration/hello-world/src/host-array/…:29
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
integration/hello-world/src/hello/hello…:26
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
integration/repl/src/users/users.contro…:38
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
integration/repl/src/users/users.contro…:33
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
integration/repl/src/users/users.contro…:28
MED
SEC134
[SEC134] AI scaffold leftover — Lorem ipsum / example.com / John Doe in code: Lorem ipsum…
sample/32-graphql-federation-schema-fir…:6
MED
SEC134
[SEC134] AI scaffold leftover — Lorem ipsum / example.com / John Doe in code: Lorem ipsum…
sample/31-graphql-federation-code-first…:7
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
packages/microservices/client/client-re…:129
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
packages/microservices/client/client-na…:96
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
packages/microservices/client/client-mq…:135
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
packages/core/router/utils/exclude-rout…:19
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
integration/mongoose/src/cats/cats.serv…:17
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
integration/lazy-modules/src/lazy.contr…:9
MED
DKR003
Compose service `mongodb` image uses the latest tag
sample/14-mongoose-base/docker-compose.…:3
MED
DKR003
Compose service `mongodb` image uses the latest tag
sample/06-mongoose/docker-compose.yml:3
MED
DKR003
Compose service `mongodb` image uses the latest tag
integration/docker-compose.yml:35
MED
AUC001
[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks…
—
MED
DKR002
Compose service `mqtt` image has no explicit tag
integration/docker-compose.yml:17
MED
DKR002
Compose service `nats` image has no explicit tag
integration/docker-compose.yml:9
MED
DKR002
Compose service `redis` image has no explicit tag
integration/docker-compose.yml:3
MED
DEPCUR-NPM
npm package `globals` is 3 major version(s) behind (14.0.0 -> 17.6.0)
sample/12-graphql-schema-first/package.…
MED
DEPCUR-NPM
npm package `@eslint/js` is 1 major version(s) behind (9.39.4 -> 10.0.1)
sample/12-graphql-schema-first/package.…
MED
DEPCUR-NPM
npm package `rimraf` is 3 major version(s) behind (3.0.2 -> 6.1.3)
sample/12-graphql-schema-first/package.…
MED
DEPCUR-NPM
npm package `file-type` is 1 major version(s) behind (21.3.4 -> 22.0.1)
packages/common/package.json
MED
DEPCUR-NPM
npm package `sinon-chai` is 1 major version(s) behind (3.7.0 -> 4.0.1)
package.json
MED
DEPCUR-NPM
npm package `markdown-table` is 1 major version(s) behind (2.0.0 -> 3.0.4)
package.json
MED
DEPCUR-NPM
npm package `gulp-typescript` is 1 major version(s) behind (5.0.1 -> 6.0.0-alpha.1)
package.json
MED
DEPCUR-NPM
npm package `globals` is 3 major version(s) behind (14.0.0 -> 17.6.0)
package.json
MED
DEPCUR-NPM
npm package `chai-as-promised` is 1 major version(s) behind (7.1.2 -> 8.0.2)
package.json
MED
DEPCUR-NPM
npm package `chai` is 2 major version(s) behind (4.5.0 -> 6.2.2)
package.json
MED
DEPCUR-NPM
npm package `@types/eslint__js` is 1 major version(s) behind (8.42.3 -> 9.14.0)
package.json
MED
DEPCUR-NPM
npm package `@types/chai-as-promised` is 1 major version(s) behind (7.1.8 -> 8.0.2)
package.json
MED
DEPCUR-NPM
npm package `@types/chai` is 1 major version(s) behind (4.3.20 -> 5.2.3)
package.json
MED
DEPCUR-NPM
npm package `@eslint/js` is 1 major version(s) behind (9.39.4 -> 10.0.1)
package.json
MED
DEPCUR-NPM
npm package `uuid` is 6 major version(s) behind (8.3.2 -> 14.0.0)
package.json
MED
DEPCUR-NPM
npm package `file-type` is 1 major version(s) behind (21.3.4 -> 22.0.1)
package.json
MED
GHSA-w5hq-g745-h8pq
uuid: GHSA-w5hq-g745-h8pq
tools/benchmarks/package-lock.json
MED
GHSA-58qx-3vcg-4xpx
ws: GHSA-58qx-3vcg-4xpx
package-lock.json
MED
GHSA-w5hq-g745-h8pq
uuid: GHSA-w5hq-g745-h8pq
package-lock.json
MED
GHSA-72xf-g2v4-qvf3
tough-cookie: GHSA-72xf-g2v4-qvf3
package-lock.json
MED
GHSA-qj8w-gfj5-8c6v
serialize-javascript: GHSA-qj8w-gfj5-8c6v
package-lock.json
MED
GHSA-p8p7-x288-28g6
request: GHSA-p8p7-x288-28g6
package-lock.json
MED
GHSA-6rw7-vpxm-498p
qs: GHSA-6rw7-vpxm-498p
package-lock.json
MED
GHSA-q8mj-m7cp-5q26
qs: GHSA-q8mj-m7cp-5q26
package-lock.json
MED
GHSA-qx2v-qp2m-jg93
postcss: GHSA-qx2v-qp2m-jg93
package-lock.json
MED
GHSA-7fh5-64p2-3v2j
postcss: GHSA-7fh5-64p2-3v2j
package-lock.json
MED
GHSA-952p-6rrq-rcjv
micromatch: GHSA-952p-6rrq-rcjv
package-lock.json
MED
GHSA-mh29-5h37-fv8m
js-yaml: GHSA-mh29-5h37-fv8m
package-lock.json
MED
GHSA-jxxr-4gwj-5jf2
brace-expansion: GHSA-jxxr-4gwj-5jf2
package-lock.json
MED
GHSA-f886-m6hf-6m8v
brace-expansion: GHSA-f886-m6hf-6m8v
package-lock.json
MED
DKC015
Database service has no healthcheck
sample/14-mongoose-base/docker-compose.…:3
MED
DKC015
Database service has no healthcheck
sample/13-mongo-typeorm/docker-compose.…:3
MED
DKC015
Database service has no healthcheck
sample/07-sequelize/docker-compose.yml:3
MED
DKC015
Database service has no healthcheck
sample/06-mongoose/docker-compose.yml:3
MED
DKC015
Database service has no healthcheck
sample/05-sql-typeorm/docker-compose.yml:11
MED
DKC015
Database service has no healthcheck
sample/05-sql-typeorm/docker-compose.yml:3
MED
DKC015
Database service has no healthcheck
integration/docker-compose.yml:35
MED
DKC015
Database service has no healthcheck
integration/docker-compose.yml:26
MED
WEB003
Public web service has no security.txt
.well-known/security.txt
MED
JRN003
Frontend API reference is not matched by discovered backend routes
packages/common/interfaces/version-opti…:55
MED
AUC002
[AUC002] Low visible authorization coverage in route inventory: Only 4.0% of discovered r…
—
MED
DKC013
Database service has no persistent data volume
sample/26-queues/docker-compose.yml:2
MED
DKC013
Database service has no persistent data volume
integration/docker-compose.yml:59
MED
DKC013
Database service has no persistent data volume
integration/docker-compose.yml:50
MED
DKC013
Database service has no persistent data volume
integration/docker-compose.yml:42
MED
DKC013
Database service has no persistent data volume
integration/docker-compose.yml:3
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
integration/scopes/src/msvc/http.contro…:6
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
integration/scopes/src/inject-inquirer/…:15
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
integration/nest-application/global-pre…:10
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
integration/nest-application/global-pre…:5
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
integration/microservices/src/kafka/kaf…:55
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
integration/microservices/src/redis/red…:16
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
integration/repl/src/users/users.contro…:38
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
integration/repl/src/users/users.contro…:33
MED
DKC007
Compose service contains a literal secret environment value
sample/07-sequelize/docker-compose.yml:3
MED
DKC007
Compose service contains a literal secret environment value
sample/05-sql-typeorm/docker-compose.yml:11
MED
DKC007
Compose service contains a literal secret environment value
sample/05-sql-typeorm/docker-compose.yml:3
LOW
DEPCUR-NPM
npm package `@nestjs/microservices` is minor version(s) behind (^11.0.0 -> 11.1.24)
packages/testing/package.json
LOW
DEPCUR-NPM
npm package `@nestjs/websockets` is minor version(s) behind (^11.0.0 -> 11.1.24)
packages/microservices/package.json
LOW
DEPCUR-NPM
npm package `@nestjs/websockets` is minor version(s) behind (^11.0.0 -> 11.1.24)
packages/platform-socket.io/package.json
LOW
DEPCUR-NPM
npm package `@nestjs/platform-socket.io` is minor version(s) behind (^11.0.0 -> 11.1.24)
packages/websockets/package.json
LOW
DEPCUR-NPM
npm package `@nestjs/websockets` is minor version(s) behind (^11.0.0 -> 11.1.24)
packages/core/package.json
LOW
DEPCUR-NPM
npm package `@nestjs/microservices` is minor version(s) behind (^11.0.0 -> 11.1.24)
packages/core/package.json
LOW
DEPCUR-NPM
npm package `@nestjs/websockets` is minor version(s) behind (^11.0.0 -> 11.1.24)
packages/platform-ws/package.json
LOW
DEPCUR-NPM
npm package `ws` is minor version(s) behind (8.20.1 -> 8.21.0)
packages/platform-ws/package.json
LOW
DEPCUR-NPM
npm package `ws` is minor version(s) behind (8.20.1 -> 8.21.0)
package.json
LOW
GHSA-w7fw-mjwx-w883
qs: GHSA-w7fw-mjwx-w883
package-lock.json
LOW
GHSA-73rr-hh4g-fpgx
diff: GHSA-73rr-hh4g-fpgx
package-lock.json
LOW
GHSA-v6h2-p8h4-qcjw
brace-expansion: GHSA-v6h2-p8h4-qcjw
package-lock.json
LOW
GHSA-vpq2-c234-7xj6
@tootallnate/once: GHSA-vpq2-c234-7xj6
package-lock.json
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/transient/interc…:1
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/transient/hello.…:1
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/transient/hello.…:2
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/transient/guards…:1
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/request-chain/re…:1
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/request-chain/re…:1
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/request-chain/in…:1
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/msvc/interceptor…:1
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/msvc/hello.modul…:8
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/msvc/guards/requ…:1
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/hello/hello.cont…:2
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/circular-transie…:2
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/circular-hello/u…:1
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/circular-hello/i…:1
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/circular-hello/h…:1
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/circular-hello/h…:2
LOW
AIC003
Duplicated implementation block across source files
integration/scopes/src/circular-hello/g…:1
LOW
AIC003
Duplicated implementation block across source files
integration/repl/src/users/users.servic…:11
LOW
AIC003
Duplicated implementation block across source files
integration/repl/src/users/users.contro…:1
LOW
AIC003
Duplicated implementation block across source files
integration/mongoose/src/async-existing…:1
LOW
AIC003
Duplicated implementation block across source files
integration/microservices/src/tcp-tls/a…:31
LOW
AIC003
Duplicated implementation block across source files
integration/microservices/src/tcp-tls/a…:1
LOW
AIC003
Duplicated implementation block across source files
integration/microservices/src/rmq/rmq.c…:34
LOW
AIC003
Duplicated implementation block across source files
integration/microservices/src/rmq/rmq.c…:33
LOW
AIC003
Duplicated implementation block across source files
integration/microservices/src/rmq/rmq-b…:24
LOW
AIC003
Duplicated implementation block across source files
integration/microservices/src/redis/red…:20
LOW
AIC003
Duplicated implementation block across source files
integration/microservices/src/redis/red…:13
LOW
AIC003
Duplicated implementation block across source files
integration/microservices/src/mqtt/mqtt…:144
LOW
AIC003
Duplicated implementation block across source files
integration/inspector/src/properties/pr…:1
LOW
AIC003
Duplicated implementation block across source files
integration/hello-world/src/host/host.c…:11
LOW
DKC015
Database service has no healthcheck
sample/26-queues/docker-compose.yml:2
LOW
DKC015
Database service has no healthcheck
integration/docker-compose.yml:59
LOW
DKC015
Database service has no healthcheck
integration/docker-compose.yml:50
LOW
DKC015
Database service has no healthcheck
integration/docker-compose.yml:42
LOW
DKC015
Database service has no healthcheck
integration/docker-compose.yml:3
LOW
DKC010
Compose service lacks no-new-privileges hardening
integration/docker-compose.yml:17
LOW
DKC010
Compose service lacks no-new-privileges hardening
integration/docker-compose.yml:9
LOW
DKC006
Compose service does not declare a runtime user
integration/docker-compose.yml:17
LOW
DKC006
Compose service does not declare a runtime user
integration/docker-compose.yml:9
INFO
MINED053
[MINED053] Placeholder Default Username: [email protected] / [email protected] / admin/admin…
sample/19-auth-jwt/src/users/users.serv…:12
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
integration/microservices/src/mqtt/mqtt…:142
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
integration/injector/src/circular-struc…:9
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
integration/graphql-code-first/src/reci…:17
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
integration/hello-world/src/hello/hello…:29
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
integration/graphql-code-first/src/comm…:8
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
integration/graphql-code-first/src/comm…:6
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
integration/nest-application/raw-body/s…:10
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
integration/microservices/src/kafka-con…:20
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
integration/discovery/src/webhooks.expl…:24
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
integration/discovery/src/my-webhook/fl…:7
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
integration/discovery/src/my-webhook/cl…:7
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
integration/auto-mock/src/foo.service.ts:6