Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

Ericsson/CodeCompass

https://github.com/Ericsson/CodeCompass · scanned 2026-08-13 15:01 UTC (4 weeks, 1 day ago)

120 raw signals (0 security + 120 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 4 weeks, 1 day ago · v1 · 115 actionable findings from 1 signal source. 5 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: excluding tests × Reset all
Scan summary Repository scanned at 68.7/100 with 100.0% coverage. It contains 1344 nodes across 4 cross-layer flows, written primarily in mixed languages. Engine surfaced 120 findings — concentrated in dependencies (72), security (19), frontend (10). Risk profile is high: 0 critical, 15 high, 72 medium. Recommended next step: open the dependencies layer findings first — that's where the highest-impact wins live.

Showing 108 of 115 actionable findings. 120 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

high System graph security security conf 1.00 Insecure pattern 'eval_used' in webgui/scripts/thrift.js:1096
Found a known-risky pattern (eval_used). Review and replace if possible.
webgui/scripts/thrift.js:1096 Eval used
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp
OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expansion: DoS v…
webgui-new/package-lock.json ScaOsvGhsa 3jxr 9vmj r5cp
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.12: GHSA-mh99-v99m-4gvg
OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-mh99-v99m-4gvg (aka CVE-2026-14257). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expansion: DoS v…
webgui-new/package-lock.json ScaOsvGhsa mh99 v99m 4gvg
high System graph dependencies dependencies conf 0.70 Vulnerable dependency dojox 1.11.2: GHSA-3hw5-q855-g6cw
OSV.dev reports `dojox` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-3hw5-q855-g6cw (aka CVE-2020-5259). Note: `1.11.2` is the declared floor of a range — the installed version may be newer. Prototype Pollution in Dojox Aliases: CVE-2020-5259 Advisory: https://osv.d…
webgui/package.json ScaOsvGhsa 3hw5 q855 g6cw
high System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 4.1.1: GHSA-52cp-r559-cp3m
OSV.dev reports `js-yaml` at version `4.1.1` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-52cp-r559-cp3m (aka CVE-2026-59869). Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. js-yaml: YAML merge-key chains can forc…
webgui-new/package-lock.json ScaOsvGhsa 52cp r559 cp3m
high System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 4.1.1: GHSA-5p4m-2wfm-xmqj
OSV.dev reports `js-yaml` at version `4.1.1` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-5p4m-2wfm-xmqj. Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x…
webgui-new/package-lock.json ScaOsvGhsa 5p4m 2wfm xmqj
high System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-36qx-fr4f-26g5
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-36qx-fr4f-26g5 (aka CVE-2026-44573). Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n Aliases: CVE-2026-44573 Advisory: https://osv.dev/vulnerability/GHSA-36…
webgui-new/package.json ScaOsvGhsa 36qx fr4f 26g5
high System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-89xv-2m56-2m9x
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-89xv-2m56-2m9x (aka CVE-2026-64649). Next.js: Server-Side Request Forgery in Server Actions on custom servers Aliases: CVE-2026-64649 Advisory: https://osv.dev/vulnerability/GHSA-89xv-2m56…
webgui-new/package.json ScaOsvGhsa 89xv 2m56 2m9x
high System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-8h8q-6873-q5fj
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-8h8q-6873-q5fj. Next.js Vulnerable to Denial of Service with Server Components Advisory: https://osv.dev/vulnerability/GHSA-8h8q-6873-q5fj Fix: upgrade `next` past the affected range per t…
webgui-new/package.json ScaOsvGhsa 8h8q 6873 q5fj
high System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-c4j6-fc7j-m34r
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-c4j6-fc7j-m34r (aka CVE-2026-44578). Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades Aliases: CVE-2026-44578 Advisory: https://osv.dev/vulnerabil…
webgui-new/package.json ScaOsvGhsa c4j6 fc7j m34r
high System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-m99w-x7hq-7vfj
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-m99w-x7hq-7vfj (aka CVE-2026-64641). Next.js: Denial of Service in App Router using Server Actions Aliases: CVE-2026-64641 Advisory: https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj Fix: …
webgui-new/package.json ScaOsvGhsa m99w x7hq 7vfj
high System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-p9j2-gv94-2wf4
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-p9j2-gv94-2wf4 (aka CVE-2026-64645). Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname Aliases: CVE-2026-64645 Advisory: https://osv.dev/vulnera…
webgui-new/package.json ScaOsvGhsa p9j2 gv94 2wf4
high System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-q4gf-8mx6-v5v3
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-q4gf-8mx6-v5v3. Next.js has a Denial of Service with Server Components Advisory: https://osv.dev/vulnerability/GHSA-q4gf-8mx6-v5v3 Fix: upgrade `next` past the affected range per the advis…
webgui-new/package.json ScaOsvGhsa q4gf 8mx6 v5v3
high System graph dependencies dependencies conf 1.00 Vulnerable dependency sharp 0.32.6: GHSA-f88m-g3jw-g9cj
OSV.dev reports `sharp` at version `0.32.6` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-f88m-g3jw-g9cj. sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591 Advisory: https://osv.dev/vulnerability/GHSA-f88m-g3jw-g9cj Fix: …
webgui-new/package.json ScaOsvGhsa f88m g3jw g9cj
high System graph dependencies dependencies conf 1.00 Vulnerable dependency thrift 0.16.0: GHSA-526f-jxpj-jmg2
OSV.dev reports `thrift` at version `0.16.0` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-526f-jxpj-jmg2 (aka CVE-2026-43870). Apache Thrift vulnerable to Path Traversal, HTTP Request/Response Splitting, Uncontrolled Resource Consumption Aliases: BIT-thrift-2026-43870, CVE-202…
webgui-new/package.json ScaOsvGhsa 526f jxpj jmg2
medium System graph quality Placeholder conf 1.00 Critical user flow still appears backed by mock or placeholder data
A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded.
Mock dataCritical flowGenerated repo pattern
medium System graph dependencies dependencies conf 0.90 Dependency @mui/icons-material is two or more major versions behind
`@mui/icons-material` is pinned at `5.18.0` in `webgui-new/package.json` while the latest release on the npm registry is `9.3.1` — 4 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@mui/ico…
webgui-new/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency @mui/material is two or more major versions behind
`@mui/material` is pinned at `5.18.0` in `webgui-new/package.json` while the latest release on the npm registry is `9.3.1` — 4 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@mui/material`…
webgui-new/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency @mui/x-tree-view is two or more major versions behind
`@mui/x-tree-view` is pinned at `6.17.0` in `webgui-new/package.json` while the latest release on the npm registry is `9.11.0` — 3 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@mui/x-tre…
webgui-new/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency d3 is two or more major versions behind
`d3` is pinned at `3.5.6` in `webgui/package.json` while the latest release on the npm registry is `7.9.0` — 4 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `d3` to `7.9.0`.
webgui/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency i18next is two or more major versions behind
`i18next` is pinned at `23.16.8` in `webgui-new/package.json` while the latest release on the npm registry is `26.3.6` — 3 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `i18next` to `26.3.…
webgui-new/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency marked is two or more major versions behind
`marked` is pinned at `4.0.10` in `webgui/package.json` while the latest release on the npm registry is `18.0.9` — 14 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `marked` to `18.0.9`.
webgui/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency next is two or more major versions behind
`next` is pinned at `14.2.35` in `webgui-new/package.json` while the latest release on the npm registry is `16.3.0` — 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `next` to `16.3.0`.
webgui-new/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency react-i18next is two or more major versions behind
`react-i18next` is pinned at `13.5.0` in `webgui-new/package.json` while the latest release on the npm registry is `17.0.11` — 4 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-i18nex…
webgui-new/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency react-toastify is two or more major versions behind
`react-toastify` is pinned at `9.1.3` in `webgui-new/package.json` while the latest release on the npm registry is `11.1.0` — 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-toastif…
webgui-new/package.json FreshnessOutdated
medium System graph hardware Security conf 1.00 Dockerfile runs as root: docker/dev/Dockerfile
No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image.
Container
medium System graph hardware Security conf 1.00 Dockerfile runs as root: docker/runtime/Dockerfile
No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image.
Container
medium System graph hardware Security conf 1.00 Dockerfile runs as root: docker/web/Dockerfile
No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image.
Container
medium System graph cicd CI/CD security conf 1.00 3 occurrences GitHub Action is tag-pinned rather than SHA-pinned
actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA.
3 files, 3 locations
.github/workflows/codeql.yml:26
.github/workflows/docker.yml:26
.github/workflows/scorecard.yml:36
CI/CD securitySupply chainGithub actions
medium System graph cicd CI/CD security conf 1.00 GitHub Actions workflow grants broad write permissions
CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions.
.github/workflows/scorecard.yml CI/CD securitySupply chainGithub actions
medium System graph security Semgrep conf 0.75 insecure hash algorithm sha1 — plugins/python/parser/pyparser/parserutil.py:6
Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. Rule: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 Severity: WARNING OWASP: A03:2017 - Se…
plugins/python/parser/pyparser/parserutil.py:6 SecurityPython
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in webgui-new/src/components/codebites/codebites-node.tsx:91
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
webgui-new/src/components/codebites/codebites-node.tsx:91 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in webgui/scripts/codecompass/view/diagram.js:286
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
webgui/scripts/codecompass/view/diagram.js:286 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in webgui/scripts/codecompass/view/fileManager.js:275
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
webgui/scripts/codecompass/view/fileManager.js:275 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'domparser_html_parse' in webgui-new/src/components/editor-context-menu/editor-context-menu.tsx:79
Found a known-risky pattern (domparser_html_parse). Review and replace if possible.
webgui-new/src/components/editor-context-menu/editor-context-menu.tsx:79 Domparser html parse
medium System graph security Semgrep conf 0.55 insecure use strcat fn — logger/src/ldlogger-logger.c:145
Finding triggers whenever there is a strcat or strncat used. This is an issue because strcat or strncat can lead to buffer overflow vulns. Fix this by using strcat_s instead. Rule: c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn Severity: WARNING OWASP: — CWE: CWE-676: Use of Potenti…
logger/src/ldlogger-logger.c:145 SecurityC
medium System graph security Semgrep conf 0.55 insecure use strcat fn — logger/src/ldlogger-tool-gcc.c:90
Finding triggers whenever there is a strcat or strncat used. This is an issue because strcat or strncat can lead to buffer overflow vulns. Fix this by using strcat_s instead. Rule: c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn Severity: WARNING OWASP: — CWE: CWE-676: Use of Potenti…
logger/src/ldlogger-tool-gcc.c:90 SecurityC
medium System graph security Semgrep conf 0.55 insecure use strcat fn — logger/src/ldlogger-tool-javac.c:160
Finding triggers whenever there is a strcat or strncat used. This is an issue because strcat or strncat can lead to buffer overflow vulns. Fix this by using strcat_s instead. Rule: c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn Severity: WARNING OWASP: — CWE: CWE-676: Use of Potenti…
logger/src/ldlogger-tool-javac.c:160 SecurityC
medium System graph security Semgrep conf 0.55 insecure use strcat fn — logger/src/ldlogger-util.c:44
Finding triggers whenever there is a strcat or strncat used. This is an issue because strcat or strncat can lead to buffer overflow vulns. Fix this by using strcat_s instead. Rule: c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn Severity: WARNING OWASP: — CWE: CWE-676: Use of Potenti…
logger/src/ldlogger-util.c:44 SecurityC
medium System graph security Semgrep conf 0.55 insecure use string copy fn — logger/src/ldlogger-tool-gcc.c:67
Finding triggers whenever there is a strcpy or strncpy used. This is an issue because strcpy does not affirm the size of the destination array and strncpy will not automatically NULL-terminate strings. This can lead to buffer overflows, which can cause program crashes and potentially let an attacke…
logger/src/ldlogger-tool-gcc.c:67 SecurityC
medium System graph security Semgrep conf 0.55 insecure use string copy fn — logger/src/ldlogger-tool-javac.c:116
Finding triggers whenever there is a strcpy or strncpy used. This is an issue because strcpy does not affirm the size of the destination array and strncpy will not automatically NULL-terminate strings. This can lead to buffer overflows, which can cause program crashes and potentially let an attacke…
logger/src/ldlogger-tool-javac.c:116 SecurityC
medium System graph security Semgrep conf 0.55 insecure use string copy fn — logger/src/ldlogger-tool.c:78
Finding triggers whenever there is a strcpy or strncpy used. This is an issue because strcpy does not affirm the size of the destination array and strncpy will not automatically NULL-terminate strings. This can lead to buffer overflows, which can cause program crashes and potentially let an attacke…
logger/src/ldlogger-tool.c:78 SecurityC
medium System graph security Semgrep conf 0.55 insecure use string copy fn — logger/src/ldlogger-util.c:20
Finding triggers whenever there is a strcpy or strncpy used. This is an issue because strcpy does not affirm the size of the destination array and strncpy will not automatically NULL-terminate strings. This can lead to buffer overflows, which can cause program crashes and potentially let an attacke…
logger/src/ldlogger-util.c:20 SecurityC
medium System graph security Semgrep conf 0.55 insecure use strtok fn — logger/src/ldlogger-tool-javac.c:118
Avoid using 'strtok()'. This function directly modifies the first argument buffer, permanently erasing the delimiter character. Use 'strtok_r()' instead. Rule: c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn Severity: WARNING OWASP: — CWE: CWE-676: Use of Potentially Dangerous Functi…
logger/src/ldlogger-tool-javac.c:118 SecurityC
medium System graph security Semgrep conf 0.55 insecure use strtok fn — logger/src/ldlogger-tool.c:39
Avoid using 'strtok()'. This function directly modifies the first argument buffer, permanently erasing the delimiter character. Use 'strtok_r()' instead. Rule: c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn Severity: WARNING OWASP: — CWE: CWE-676: Use of Potentially Dangerous Functi…
logger/src/ldlogger-tool.c:39 SecurityC
medium System graph security Coverage conf 1.00 No auth library detected
The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing.
auth
medium System graph security Semgrep conf 0.55 object deserialization — plugins/search/common/src/cc/search/analysis/tags/Tags.java:171
Found object deserialization using ObjectInputStream. Deserializing entire Java objects is dangerous because malicious actors can create Java object streams with unintended consequences. Ensure that the objects being deserialized are not user-controlled. If this must be done, consider using HMACs t…
plugins/search/common/src/cc/search/analysis/tags/Tags.java:171 SecurityJava
medium System graph quality Placeholder conf 1.00 Placeholder or mock-heavy implementation detected
Found 36 placeholder/mock markers across 15 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data.
Mock dataIncompleteGenerated repo pattern
medium System graph security Secrets conf 0.65 Runtime dotenv file present in repo: webgui-new/.env
`webgui-new/.env` looks like a runtime dotenv file. No high-confidence secret value was matched, but runtime dotenv files often drift into live credentials. Move real values to a secret manager and keep only `.env.example` style templates in source control.
webgui-new/.env ConfigEnv fileRuntime env
medium System graph quality Tests conf 1.00 Very low test-to-source ratio
3 test file(s) for 124 source file(s) (ratio 0.02). Consider adding integration or unit tests for critical paths.
Coverage
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency ajv 6.12.6: GHSA-2g4f-4pwh-qvx6
OSV.dev reports `ajv` at version `6.12.6` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-2g4f-4pwh-qvx6 (aka CVE-2025-69873). Note: `ajv` is a transitive dependency — pulled in by another package, not declared directly in a manifest. ajv has ReDoS when using `$data` option Alias…
webgui-new/package-lock.json ScaOsvGhsa 2g4f 4pwh qvx6
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v
OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-f886-m6hf-6m8v (aka CVE-2026-33750). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expansion: Zero-…
webgui-new/package-lock.json ScaOsvGhsa f886 m6hf 6m8v
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.12: GHSA-rgw5-rvv9-x895
OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-rgw5-rvv9-x895. Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https:…
webgui-new/package-lock.json ScaOsvGhsa rgw5 rvv9 x895
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency codemirror 5.19.0: GHSA-4gw3-8f77-f72c
OSV.dev reports `codemirror` at version `5.19.0` (declared in `webgui/package.json`) is affected by GHSA-4gw3-8f77-f72c (aka CVE-2020-7760). Note: `5.19.0` is the declared floor of a range — the installed version may be newer. Regular expression denial of service in codemirror Aliases: CVE-2020-7…
webgui/package.json ScaOsvGhsa 4gw3 8f77 f72c
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency dijit 1.11.2: GHSA-cxjc-r2fp-7mq6
OSV.dev reports `dijit` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-cxjc-r2fp-7mq6. Note: `1.11.2` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-cxjc-r2fp-7mq6 Fix: upgr…
webgui/package.json ScaOsvGhsa cxjc r2fp 7mq6
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency dijit 1.11.2: GHSA-wp32-wq34-2rqh
OSV.dev reports `dijit` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-wp32-wq34-2rqh. Note: `1.11.2` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-wp32-wq34-2rqh Fix: upgr…
webgui/package.json ScaOsvGhsa wp32 wq34 2rqh
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency dojo 1.11.2: GHSA-536q-8gxx-m782
OSV.dev reports `dojo` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-536q-8gxx-m782 (aka CVE-2010-2273). Note: `1.11.2` is the declared floor of a range — the installed version may be newer. Cross-Site Scripting in dojo Aliases: CVE-2010-2273 Advisory: https://osv.de…
webgui/package.json ScaOsvGhsa 536q 8gxx m782
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency dojo 1.11.2: GHSA-jxfh-8wgv-vfr2
OSV.dev reports `dojo` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-jxfh-8wgv-vfr2. Note: `1.11.2` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-jxfh-8wgv-vfr2 Fix: upgra…
webgui/package.json ScaOsvGhsa jxfh 8wgv vfr2
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency dojo 1.11.2: GHSA-m8gw-hjpr-rjv7
OSV.dev reports `dojo` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-m8gw-hjpr-rjv7. Note: `1.11.2` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-m8gw-hjpr-rjv7 Fix: upgra…
webgui/package.json ScaOsvGhsa m8gw hjpr rjv7
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency dojox 1.11.2: GHSA-84cm-x2q5-8225
OSV.dev reports `dojox` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-84cm-x2q5-8225. Note: `1.11.2` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-84cm-x2q5-8225 Fix: upgr…
webgui/package.json ScaOsvGhsa 84cm x2q5 8225
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency dojox 1.11.2: GHSA-pg97-ww7h-5mjr
OSV.dev reports `dojox` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-pg97-ww7h-5mjr. Note: `1.11.2` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-pg97-ww7h-5mjr Fix: upgr…
webgui/package.json ScaOsvGhsa pg97 ww7h 5mjr
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency http-proxy-middleware 3.0.5: GHSA-64mm-vxmg-q3vj
OSV.dev reports `http-proxy-middleware` at version `3.0.5` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-64mm-vxmg-q3vj (aka CVE-2026-55602). http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass Aliases: CVE-2026-55602 Adv…
webgui-new/package.json ScaOsvGhsa 64mm vxmg q3vj
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency http-proxy-middleware 3.0.5: GHSA-gcq2-9pq2-cxqm
OSV.dev reports `http-proxy-middleware` at version `3.0.5` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-gcq2-9pq2-cxqm. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-gcq2-9pq2-cxqm Fix: upgrade `http-proxy-middleware` past the affected range per the ad…
webgui-new/package.json ScaOsvGhsa gcq2 9pq2 cxqm
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency immutable 5.1.5: GHSA-v56q-mh7h-f735
OSV.dev reports `immutable` at version `5.1.5` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-v56q-mh7h-f735. Note: `immutable` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vul…
webgui-new/package-lock.json ScaOsvGhsa v56q mh7h f735
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency immutable 5.1.5: GHSA-xvcm-6775-5m9r
OSV.dev reports `immutable` at version `5.1.5` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-xvcm-6775-5m9r. Note: `immutable` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vul…
webgui-new/package-lock.json ScaOsvGhsa xvcm 6775 5m9r
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency jquery 3.1.1: GHSA-6c3j-c64m-qhgq
OSV.dev reports `jquery` at version `3.1.1` (declared in `webgui/package.json`) is affected by GHSA-6c3j-c64m-qhgq. Note: `3.1.1` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-6c3j-c64m-qhgq Fix: upgra…
webgui/package.json ScaOsvGhsa 6c3j c64m qhgq
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency jquery 3.1.1: GHSA-gxr4-xjj5-5px2
OSV.dev reports `jquery` at version `3.1.1` (declared in `webgui/package.json`) is affected by GHSA-gxr4-xjj5-5px2. Note: `3.1.1` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-gxr4-xjj5-5px2 Fix: upgra…
webgui/package.json ScaOsvGhsa gxr4 xjj5 5px2
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency jquery 3.1.1: GHSA-jpcq-cgw6-v4j6
OSV.dev reports `jquery` at version `3.1.1` (declared in `webgui/package.json`) is affected by GHSA-jpcq-cgw6-v4j6. Note: `3.1.1` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-jpcq-cgw6-v4j6 Fix: upgra…
webgui/package.json ScaOsvGhsa jpcq cgw6 v4j6
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency js-cookie 2.2.1: GHSA-qjx8-664m-686j
OSV.dev reports `js-cookie` at version `2.2.1` (declared in `webgui/package.json`) is affected by GHSA-qjx8-664m-686j. Note: `2.2.1` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-qjx8-664m-686j Fix: up…
webgui/package.json ScaOsvGhsa qjx8 664m 686j
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 4.1.1: GHSA-h67p-54hq-rp68
OSV.dev reports `js-yaml` at version `4.1.1` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-h67p-54hq-rp68 (aka CVE-2026-53550). Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. JS-YAML: Quadratic-complexity DoS in me…
webgui-new/package-lock.json ScaOsvGhsa h67p 54hq rp68
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-3x4c-7xq6-9pq8
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-3x4c-7xq6-9pq8 (aka CVE-2026-27980). Next.js: Unbounded next/image disk cache growth can exhaust storage Aliases: CVE-2026-27980 Advisory: https://osv.dev/vulnerability/GHSA-3x4c-7xq6-9pq8…
webgui-new/package.json ScaOsvGhsa 3x4c 7xq6 9pq8
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-4633-3j49-mh5q
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-4633-3j49-mh5q (aka CVE-2026-64647). Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences Aliases: CVE-2026-64647 Advisory: https://…
webgui-new/package.json ScaOsvGhsa 4633 3j49 mh5q
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-4c39-4ccg-62r3
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-4c39-4ccg-62r3 (aka CVE-2026-64646). Next.js: Unbounded Server Action payload in Edge runtime Aliases: CVE-2026-64646 Advisory: https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3 Fix: upgra…
webgui-new/package.json ScaOsvGhsa 4c39 4ccg 62r3
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-68g3-v927-f742
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-68g3-v927-f742 (aka CVE-2026-64648). Next.js: Cache confusion of response bodies for requests with bodies Aliases: CVE-2026-64648 Advisory: https://osv.dev/vulnerability/GHSA-68g3-v927-f74…
webgui-new/package.json ScaOsvGhsa 68g3 v927 f742
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-955p-x3mx-jcvp
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-955p-x3mx-jcvp (aka CVE-2026-64643). Next.js: Unauthenticated disclosure of internal Server Function endpoints Aliases: CVE-2026-64643 Advisory: https://osv.dev/vulnerability/GHSA-955p-x3m…
webgui-new/package.json ScaOsvGhsa 955p x3mx jcvp
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-9g9p-9gw9-jx7f
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-9g9p-9gw9-jx7f. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-9g9p-9gw9-jx7f Fix: upgrade `next` past the affected range per the advisory.
webgui-new/package.json ScaOsvGhsa 9g9p 9gw9 jx7f
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-ffhc-5mcf-pf4q
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-ffhc-5mcf-pf4q (aka CVE-2026-44581). Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces Aliases: CVE-2026-44581 Advisory: https://osv.dev/vulnerability/…
webgui-new/package.json ScaOsvGhsa ffhc 5mcf pf4q
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-ggv3-7p47-pfv8
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-ggv3-7p47-pfv8 (aka CVE-2026-29057). Next.js: HTTP request smuggling in rewrites Aliases: CVE-2026-29057 Advisory: https://osv.dev/vulnerability/GHSA-ggv3-7p47-pfv8 Fix: upgrade `next` pas…
webgui-new/package.json ScaOsvGhsa ggv3 7p47 pfv8
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-gx5p-jg67-6x7h
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-gx5p-jg67-6x7h (aka CVE-2026-44580). Next.js has cross-site scripting in beforeInteractive scripts with untrusted input Aliases: CVE-2026-44580 Advisory: https://osv.dev/vulnerability/GHSA…
webgui-new/package.json ScaOsvGhsa gx5p jg67 6x7h
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-h25m-26qc-wcjf
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-h25m-26qc-wcjf. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-h25m-26qc-wcjf Fix: upgrade `next` past the affected range per the advisory.
webgui-new/package.json ScaOsvGhsa h25m 26qc wcjf
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-h64f-5h5j-jqjh
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-h64f-5h5j-jqjh (aka CVE-2026-44577). Next.js has a Denial of Service in the Image Optimization API Aliases: CVE-2026-44577 Advisory: https://osv.dev/vulnerability/GHSA-h64f-5h5j-jqjh Fix: …
webgui-new/package.json ScaOsvGhsa h64f 5h5j jqjh
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-wfc6-r584-vfw7
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-wfc6-r584-vfw7 (aka CVE-2026-44576). Next.js vulnerable to cache poisoning in React Server Component responses Aliases: CVE-2026-44576 Advisory: https://osv.dev/vulnerability/GHSA-wfc6-r58…
webgui-new/package.json ScaOsvGhsa wfc6 r584 vfw7
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency qs 6.14.1: GHSA-q8mj-m7cp-5q26
OSV.dev reports `qs` at version `6.14.1` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-q8mj-m7cp-5q26. Note: `qs` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GH…
webgui-new/package-lock.json ScaOsvGhsa q8mj m7cp 5q26
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency qs 6.14.1: GHSA-w7fw-mjwx-w883
OSV.dev reports `qs` at version `6.14.1` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-w7fw-mjwx-w883. Note: `qs` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GH…
webgui-new/package-lock.json ScaOsvGhsa w7fw mjwx w883
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency thrift 0.16.0: GHSA-r67j-r569-jrwp
OSV.dev reports `thrift` at version `0.16.0` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-r67j-r569-jrwp. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-r67j-r569-jrwp Fix: upgrade `thrift` past the affected range per the advisory.
webgui-new/package.json ScaOsvGhsa r67j r569 jrwp
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — plugins/git/webgui/js/gitNavigator.js:175
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
plugins/git/webgui/js/gitNavigator.js:175 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — webgui-new/src/components/cookie-notice/cookie-notice.tsx:61
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
webgui-new/src/components/cookie-notice/cookie-notice.tsx:61 Fq console leak
low System graph quality Debug conf 1.00 Debug logging residue appears in source files
Found 10 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup.
CleanupRepo hardeningGenerated repo pattern
low System graph dependencies dependencies conf 0.90 Dependency codemirror is a major version behind
`codemirror` is pinned at `5.19.0` in `webgui/package.json` while the latest release on the npm registry is `6.0.2` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `codemirror` to `6.0.2…
webgui/package.json FreshnessOutdated
low System graph dependencies dependencies conf 0.90 Dependency jquery is a major version behind
`jquery` is pinned at `3.1.1` in `webgui/package.json` while the latest release on the npm registry is `4.0.0` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `jquery` to `4.0.0`.
webgui/package.json FreshnessOutdated
low System graph dependencies dependencies conf 0.90 Dependency js-cookie is a major version behind
`js-cookie` is pinned at `2.2.1` in `webgui/package.json` while the latest release on the npm registry is `3.0.8` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `js-cookie` to `3.0.8`.
webgui/package.json FreshnessOutdated
low System graph dependencies dependencies conf 0.90 Dependency react is a major version behind
`react` is pinned at `18.3.1` in `webgui-new/package.json` while the latest release on the npm registry is `19.2.8` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react` to `19.2.8`.
webgui-new/package.json FreshnessOutdated
low System graph dependencies dependencies conf 0.90 Dependency react-diff-viewer-continued is a major version behind
`react-diff-viewer-continued` is pinned at `3.4.0` in `webgui-new/package.json` while the latest release on the npm registry is `4.4.0` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `r…
webgui-new/package.json FreshnessOutdated
low System graph dependencies dependencies conf 0.90 Dependency react-dom is a major version behind
`react-dom` is pinned at `18.3.1` in `webgui-new/package.json` while the latest release on the npm registry is `19.2.8` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-dom` to `19…
webgui-new/package.json FreshnessOutdated
low System graph dependencies dependencies conf 0.90 Dependency react-ga4 is a major version behind
`react-ga4` is pinned at `2.1.0` in `webgui-new/package.json` while the latest release on the npm registry is `3.0.1` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-ga4` to `3.0.…
webgui-new/package.json FreshnessOutdated
low System graph dependencies dependencies conf 0.90 Dependency react-icons is a major version behind
`react-icons` is pinned at `4.12.0` in `webgui-new/package.json` while the latest release on the npm registry is `5.7.0` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-icons` to …
webgui-new/package.json FreshnessOutdated
low System graph dependencies dependencies conf 0.90 Dependency react-zoom-pan-pinch is a major version behind
`react-zoom-pan-pinch` is pinned at `3.7.0` in `webgui-new/package.json` while the latest release on the npm registry is `4.0.4` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-zo…
webgui-new/package.json FreshnessOutdated
low System graph dependencies dependencies conf 0.90 Dependency recharts is a major version behind
`recharts` is pinned at `2.15.4` in `webgui-new/package.json` while the latest release on the npm registry is `3.10.1` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `recharts` to `3.10…
webgui-new/package.json FreshnessOutdated
low System graph hardware Supply chain conf 1.00 Docker base image is tag-pinned but not digest-pinned: codecompass:dev
Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter.
docker/runtime/Dockerfile:6 containersPinned dependencies
low System graph hardware Supply chain conf 1.00 Docker base image is tag-pinned but not digest-pinned: codecompass:runtime
Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter.
docker/web/Dockerfile:4 containersPinned dependencies
low System graph hardware Supply chain conf 1.00 3 occurrences Docker base image is tag-pinned but not digest-pinned: ubuntu:22.04
Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter.
3 files, 3 locations
docker/dev/Dockerfile:1
docker/runtime/Dockerfile:43
docker/web/Dockerfile:10
containersPinned dependencies
low System graph cicd CI/CD security conf 1.00 2 occurrences GitHub Action is tag-pinned rather than SHA-pinned
actions/cache/restore@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA.
2 files, 2 locations
.github/workflows/ci.yml:72
.github/workflows/linting.yml:16
CI/CD securitySupply chainGithub actions
low System graph dependencies dependencies conf 1.00 Node manifest has dependencies but no lockfile: webgui/package.json
`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely.
webgui/package.json LockfileReproducibilityGenerated repo pattern
low System graph software Dead code conf 1.00 Possibly dead Python function: parseProject
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
plugins/python/parser/pyparser/parser.py:16
low System graph frontend Frontend quality conf 0.85 React Flow <Controls> without dark theming — webgui-new/src/components/codebites/codebites.tsx:52
`<Controls>` ships with white buttons. Override `.react-flow__controls` and `.react-flow__controls-button` in your stylesheet or pass a styled wrapper. Why: P1 in CHECKLIST.md — vendor defaults bleed light through. Rule id: fq.controls.no-bg
webgui-new/src/components/codebites/codebites.tsx:52 Fq controls no bg
low System graph dependencies dependencies conf 0.90 Vulnerable dependency body-parser 1.20.3: GHSA-v422-hmwv-36x6
OSV.dev reports `body-parser` at version `1.20.3` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-v422-hmwv-36x6 (aka CVE-2026-12590). Note: `body-parser` is a transitive dependency — pulled in by another package, not declared directly in a manifest. body-parser vulnerable to deni…
webgui-new/package-lock.json ScaOsvGhsa v422 hmwv 36x6
low System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-3g8h-86w9-wvmq
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-3g8h-86w9-wvmq (aka CVE-2026-44572). Next.js's Middleware / Proxy redirects can be cache-poisoned Aliases: CVE-2026-44572 Advisory: https://osv.dev/vulnerability/GHSA-3g8h-86w9-wvmq Fix: u…
webgui-new/package.json ScaOsvGhsa 3g8h 86w9 wvmq
low System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.35: GHSA-vfv6-92ff-j949
OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-vfv6-92ff-j949 (aka CVE-2026-44582). Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting Aliases: CVE-2026-44582 Advisory: https://osv.dev/vulnerab…
webgui-new/package.json ScaOsvGhsa vfv6 92ff j949
For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/550dbb34-b51e-45bd-94e7-0ce306fcd838/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/550dbb34-b51e-45bd-94e7-0ce306fcd838/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.