CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
README.md:676
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
pkg/util/util/util.go:18
HIGH
MINED033
[MINED033] Go Recover Without Log: defer func() { recover() }() that silently swallows pa…
pkg/util/net/udp.go:71
HIGH
MINED016
[MINED016] Go Error Ignored: _, err := fn() with err not checked. Go anti-pattern.
pkg/util/system/system_android.go:53
HIGH
MINED016
[MINED016] Go Error Ignored: _, err := fn() with err not checked. Go anti-pattern.
pkg/sdk/client/client.go:87
HIGH
MINED016
[MINED016] Go Error Ignored: _, err := fn() with err not checked. Go anti-pattern.
pkg/proto/wire/wire.go:104
HIGH
MINED014
[MINED014] Disabled Tls Verify: verify=False in requests, rejectUnauthorized:false in nod…
pkg/transport/tls.go:149
HIGH
MINED014
[MINED014] Disabled Tls Verify: verify=False in requests, rejectUnauthorized:false in nod…
pkg/plugin/client/https2https.go:45
HIGH
MINED014
[MINED014] Disabled Tls Verify: verify=False in requests, rejectUnauthorized:false in nod…
pkg/plugin/client/http2https.go:45
HIGH
SEC088
[SEC088] Go: TLS InsecureSkipVerify=true: tls.Config{InsecureSkipVerify:true} disables ce…
pkg/plugin/client/https2https.go:45
HIGH
SEC088
[SEC088] Go: TLS InsecureSkipVerify=true: tls.Config{InsecureSkipVerify:true} disables ce…
pkg/plugin/client/http2https.go:45
HIGH
SEC093
[SEC093] Go: exec.Command with non-literal: exec.Command(<var>) — variable command name a…
pkg/config/v1/value_source.go:143
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
pkg/auth/oidc.go:70
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
client/connector.go:208
HIGH
MINED115
Action `goreleaser/goreleaser-action` pinned to mutable ref `@v7`
.github/workflows/goreleaser.yml:33
HIGH
MINED115
Action `actions/setup-node` pinned to mutable ref `@v6`
.github/workflows/goreleaser.yml:19
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v6`
.github/workflows/goreleaser.yml:16
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/goreleaser.yml:11
HIGH
MINED115
Action `actions/stale` pinned to mutable ref `@v10`
.github/workflows/stale.yml:22
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/build-and-push-image.…:22
HIGH
MINED115
Action `golangci/golangci-lint-action` pinned to mutable ref `@v9`
.github/workflows/golangci-lint.yml:32
HIGH
MINED115
Action `actions/setup-node` pinned to mutable ref `@v6`
.github/workflows/golangci-lint.yml:22
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v6`
.github/workflows/golangci-lint.yml:18
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/golangci-lint.yml:17
HIGH
MINED128
go.mod replaces `github.com/hashicorp/yamux` — redirects to fork `github.com/fatedier/yam…
go.mod:84
HIGH
GO-2026-5039
stdlib: GO-2026-5039
go.mod
HIGH
GO-2026-5038
stdlib: GO-2026-5038
go.mod
HIGH
GO-2026-5037
stdlib: GO-2026-5037
go.mod
HIGH
GO-2026-4986
stdlib: GO-2026-4986
go.mod
HIGH
GO-2026-4982
stdlib: GO-2026-4982
go.mod
HIGH
GO-2026-4981
stdlib: GO-2026-4981
go.mod
HIGH
GO-2026-4980
stdlib: GO-2026-4980
go.mod
HIGH
GO-2026-4977
stdlib: GO-2026-4977
go.mod
HIGH
GO-2026-4976
stdlib: GO-2026-4976
go.mod
HIGH
GO-2026-4971
stdlib: GO-2026-4971
go.mod
HIGH
GO-2026-4947
stdlib: GO-2026-4947
go.mod
HIGH
GO-2026-4946
stdlib: GO-2026-4946
go.mod
HIGH
GO-2026-4918
stdlib: GO-2026-4918
go.mod
HIGH
GO-2026-4870
stdlib: GO-2026-4870
go.mod
HIGH
GO-2026-4869
stdlib: GO-2026-4869
go.mod
HIGH
GO-2026-4865
stdlib: GO-2026-4865
go.mod
HIGH
GO-2026-4864
stdlib: GO-2026-4864
go.mod
HIGH
GO-2026-4603
stdlib: GO-2026-4603
go.mod
HIGH
GO-2026-4602
stdlib: GO-2026-4602
go.mod
HIGH
GO-2026-4601
stdlib: GO-2026-4601
go.mod
HIGH
GO-2026-4342
stdlib: GO-2026-4342
go.mod
HIGH
GO-2026-4341
stdlib: GO-2026-4341
go.mod
HIGH
GO-2026-4340
stdlib: GO-2026-4340
go.mod
HIGH
GO-2026-4337
stdlib: GO-2026-4337
go.mod
HIGH
GO-2025-4175
stdlib: GO-2025-4175
go.mod
HIGH
GO-2025-4155
stdlib: GO-2025-4155
go.mod
HIGH
GO-2025-4015
stdlib: GO-2025-4015
go.mod
HIGH
GO-2025-4014
stdlib: GO-2025-4014
go.mod
HIGH
GO-2025-4013
stdlib: GO-2025-4013
go.mod
HIGH
GO-2025-4012
stdlib: GO-2025-4012
go.mod
HIGH
GO-2025-4011
stdlib: GO-2025-4011
go.mod
HIGH
GO-2025-4010
stdlib: GO-2025-4010
go.mod
HIGH
GO-2025-4009
stdlib: GO-2025-4009
go.mod
HIGH
GO-2025-4008
stdlib: GO-2025-4008
go.mod
HIGH
GO-2025-4007
stdlib: GO-2025-4007
go.mod
HIGH
GO-2025-4006
stdlib: GO-2025-4006
go.mod
HIGH
GO-2025-3955
stdlib: GO-2025-3955
go.mod
HIGH
GO-2026-5024
golang.org/x/sys: GO-2026-5024
go.mod
HIGH
GO-2026-5030
golang.org/x/net: GO-2026-5030
go.mod
HIGH
GO-2026-5029
golang.org/x/net: GO-2026-5029
go.mod
HIGH
GO-2026-5028
golang.org/x/net: GO-2026-5028
go.mod
HIGH
GO-2026-5027
golang.org/x/net: GO-2026-5027
go.mod
HIGH
GO-2026-5026
golang.org/x/net: GO-2026-5026
go.mod
HIGH
GO-2026-5025
golang.org/x/net: GO-2026-5025
go.mod
HIGH
GO-2026-4918
golang.org/x/net: GO-2026-4918
go.mod
HIGH
GO-2026-5033
golang.org/x/crypto: GO-2026-5033
go.mod
HIGH
GO-2026-5023
golang.org/x/crypto: GO-2026-5023
go.mod
HIGH
GO-2026-5021
golang.org/x/crypto: GO-2026-5021
go.mod
HIGH
GO-2026-5020
golang.org/x/crypto: GO-2026-5020
go.mod
HIGH
GO-2026-5019
golang.org/x/crypto: GO-2026-5019
go.mod
HIGH
GO-2026-5018
golang.org/x/crypto: GO-2026-5018
go.mod
HIGH
GO-2026-5017
golang.org/x/crypto: GO-2026-5017
go.mod
HIGH
GO-2026-5016
golang.org/x/crypto: GO-2026-5016
go.mod
HIGH
GO-2026-5015
golang.org/x/crypto: GO-2026-5015
go.mod
HIGH
GO-2026-5014
golang.org/x/crypto: GO-2026-5014
go.mod
HIGH
GO-2026-5013
golang.org/x/crypto: GO-2026-5013
go.mod
HIGH
GO-2026-5006
golang.org/x/crypto: GO-2026-5006
go.mod
HIGH
GO-2026-5005
golang.org/x/crypto: GO-2026-5005
go.mod
HIGH
GO-2025-4233
github.com/quic-go/quic-go: GO-2025-4233
go.mod
HIGH
GO-2026-4479
github.com/pion/dtls/v3: GO-2026-4479
go.mod
HIGH
GO-2026-4945
github.com/go-jose/go-jose/v4: GO-2026-4945
go.mod
MED
SEC014
[SEC014] SSL Verification Disabled: SSL certificate verification is disabled, allowing ma…
pkg/transport/tls.go:149
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
pkg/plugin/client/internal/httpsserver/…:37
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
pkg/plugin/client/http_proxy.go:59
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
pkg/plugin/client/http_common.go:66
MED
SEC123
[SEC123] Production stack trace / debug output exposed: Debug mode left on in production …
hack/run-e2e.sh:14
MED
SEC123
[SEC123] Production stack trace / debug output exposed: Debug mode left on in production …
hack/run-e2e-compatibility.sh:15
MED
DEPCUR-NPM
npm package `unplugin-vue-components` is 32 major version(s) behind (0.26.0 -> 32.1.0)
web/frpc/package.json
MED
DEPCUR-NPM
npm package `unplugin-auto-import` is 21 major version(s) behind (0.17.8 -> 21.0.0)
web/frpc/package.json
MED
DEPCUR-NPM
npm package `eslint-plugin-vue` is 1 major version(s) behind (9.33.0 -> 10.9.2)
web/frpc/package.json
MED
DEPCUR-NPM
npm package `vue-router` is 1 major version(s) behind (4.6.4 -> 5.1.0)
web/frpc/package.json
MED
DEPCUR-NPM
npm package `unplugin-vue-components` is 32 major version(s) behind (0.26.0 -> 32.1.0)
web/frps/package.json
MED
DEPCUR-NPM
npm package `unplugin-auto-import` is 21 major version(s) behind (0.17.8 -> 21.0.0)
web/frps/package.json
MED
DEPCUR-NPM
npm package `eslint-plugin-vue` is 1 major version(s) behind (9.33.0 -> 10.9.2)
web/frps/package.json
MED
DEPCUR-NPM
npm package `vue-router` is 1 major version(s) behind (4.6.4 -> 5.1.0)
web/frps/package.json
MED
GHSA-jxxr-4gwj-5jf2
brace-expansion: GHSA-jxxr-4gwj-5jf2
web/package-lock.json
MED
GHSA-vvgj-x9jq-8cj9
github.com/quic-go/quic-go: GHSA-vvgj-x9jq-8cj9
go.mod
MED
GHSA-pjcq-xvwq-hhpj
github.com/Azure/go-ntlmssp: GHSA-pjcq-xvwq-hhpj
go.mod
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
cmd/frpc/sub/proxy.go:52
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
client/proxy/proxy_wrapper.go:187
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
client/health/health.go:179
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
client/control_session.go:58
LOW
DEPCUR-GHA
GitHub Action `goreleaser/goreleaser-action@v7` is minor version(s) behind (latest v7.2.2)
.github/workflows/goreleaser.yml:33
LOW
DEPCUR-GHA
GitHub Action `actions/setup-node@v6` is minor version(s) behind (latest v6.4.0)
.github/workflows/goreleaser.yml:19
LOW
DEPCUR-GHA
GitHub Action `actions/setup-go@v6` is minor version(s) behind (latest v6.4.0)
.github/workflows/goreleaser.yml:16
LOW
DEPCUR-GHA
GitHub Action `actions/stale@v10` is minor version(s) behind (latest v10.3.0)
.github/workflows/stale.yml:22
LOW
DEPCUR-GHA
GitHub Action `golangci/golangci-lint-action@v9` is minor version(s) behind (latest v9.2.…
.github/workflows/golangci-lint.yml:32
LOW
DEPCUR-GHA
GitHub Action `actions/setup-node@v6` is minor version(s) behind (latest v6.4.0)
.github/workflows/golangci-lint.yml:22
LOW
DEPCUR-GHA
GitHub Action `actions/setup-go@v6` is minor version(s) behind (latest v6.4.0)
.github/workflows/golangci-lint.yml:18
LOW
DEPCUR-NPM
npm package `terser` is minor version(s) behind (5.46.1 -> 5.48.0)
web/frpc/package.json
LOW
DEPCUR-NPM
npm package `sass` is minor version(s) behind (1.98.0 -> 1.100.0)
web/frpc/package.json
LOW
DEPCUR-NPM
npm package `@vueuse/core` is minor version(s) behind (14.2.1 -> 14.3.0)
web/frpc/package.json
LOW
DEPCUR-NPM
npm package `@vue/tsconfig` is minor version(s) behind (0.8.1 -> 0.9.1)
web/frpc/package.json
LOW
DEPCUR-NPM
npm package `@vue/eslint-config-typescript` is minor version(s) behind (14.7.0 -> 14.8.0)
web/frpc/package.json
LOW
DEPCUR-NPM
npm package `element-plus` is minor version(s) behind (2.13.5 -> 2.14.1)
web/frpc/package.json
LOW
DEPCUR-NPM
npm package `vue-tsc` is minor version(s) behind (3.2.6 -> 3.3.3)
web/frps/package.json
LOW
DEPCUR-NPM
npm package `terser` is minor version(s) behind (5.46.1 -> 5.48.0)
web/frps/package.json
LOW
DEPCUR-NPM
npm package `sass` is minor version(s) behind (1.98.0 -> 1.100.0)
web/frps/package.json
LOW
DEPCUR-NPM
npm package `@vueuse/core` is minor version(s) behind (14.2.1 -> 14.3.0)
web/frps/package.json
LOW
DEPCUR-NPM
npm package `@vue/tsconfig` is minor version(s) behind (0.8.1 -> 0.9.1)
web/frps/package.json
LOW
DEPCUR-NPM
npm package `@vue/eslint-config-typescript` is minor version(s) behind (14.7.0 -> 14.8.0)
web/frps/package.json
LOW
DEPCUR-NPM
npm package `element-plus` is minor version(s) behind (2.13.5 -> 2.14.1)
web/frps/package.json
LOW
AIC003
Duplicated implementation block across source files
web/frps/src/views/Proxies.vue:81
LOW
AIC003
Duplicated implementation block across source files
web/frps/src/views/ClientDetail.vue:285
LOW
AIC003
Duplicated implementation block across source files
web/frps/src/utils/format.ts:1
LOW
AIC003
Duplicated implementation block across source files
web/frps/src/api/http.ts:22
LOW
AIC003
Duplicated implementation block across source files
web/frps/src/App.vue:20
LOW
AIC003
Duplicated implementation block across source files
web/frps/eslint.config.js:1
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/views/VisitorList.vue:281
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/views/VisitorList.vue:231
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/views/VisitorList.vue:162
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/views/VisitorEdit.vue:8
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/views/VisitorDetail.vue:33
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/views/ProxyList.vue:323
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/components/visitor-form/Vi…:27
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/components/visitor-form/Vi…:22
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/components/visitor-form/Vi…:7
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/components/visitor-form/Vi…:8
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/components/proxy-form/Prox…:15
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/components/proxy-form/Prox…:14
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/components/proxy-form/Prox…:23
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/components/proxy-form/Prox…:5
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/components/proxy-form/Prox…:5
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/components/proxy-form/Prox…:7
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/components/proxy-form/Prox…:8
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/components/proxy-form/Prox…:18
LOW
AIC003
Duplicated implementation block across source files
web/frpc/src/components/StatusPills.vue:64
LOW
AIC003
Duplicated implementation block across source files
test/e2e/v1/plugin/server.go:97
LOW
AIC003
Duplicated implementation block across source files
test/e2e/v1/plugin/client.go:35
LOW
AIC003
Duplicated implementation block across source files
test/e2e/v1/features/real_ip.go:32
LOW
AIC003
Duplicated implementation block across source files
cmd/frps/verify.go:2
LOW
AIC003
Duplicated implementation block across source files
client/http/model/visitor_definition.go:68
INFO
MINED042
[MINED042] Cpp New Without Delete: C++ raw new without RAII / unique_ptr — memory leak ri…
web/frps/vite.config.mts:27
INFO
MINED042
[MINED042] Cpp New Without Delete: C++ raw new without RAII / unique_ptr — memory leak ri…
web/frpc/vite.config.mts:27
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
web/frpc/src/stores/proxy.ts:82
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
web/frpc/src/api/http.ts:55
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
web/frpc/src/stores/visitor.ts:25
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
web/frpc/src/stores/proxy.ts:34
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
web/frpc/src/api/http.ts:44
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
web/frpc/src/api/http.ts:51
INFO
MINED069
[MINED069] Debug True Prod: Django/Flask DEBUG=True or app.debug=True in non-test files.
hack/run-e2e.sh:14
INFO
MINED069
[MINED069] Debug True Prod: Django/Flask DEBUG=True or app.debug=True in non-test files.
hack/run-e2e-compatibility.sh:15
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
pkg/plugin/client/plugin.go:43
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
pkg/auth/oidc.go:279
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
cmd/frpc/sub/proxy.go:52
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
pkg/sdk/client/client.go:36
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
pkg/plugin/server/http.go:53
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
client/health/health.go:70
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
cmd/frpc/sub/root.go:218
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
cmd/frpc/sub/admin.go:78
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
client/connector.go:167
INFO
DEPCUR-GHA
GitHub Action `actions/checkout@v6` is patch version(s) behind (latest v6.0.3)
.github/workflows/goreleaser.yml:11
INFO
DEPCUR-GHA
GitHub Action `actions/checkout@v6` is patch version(s) behind (latest v6.0.3)
.github/workflows/build-and-push-image.…:22
INFO
DEPCUR-GHA
GitHub Action `actions/checkout@v6` is patch version(s) behind (latest v6.0.3)
.github/workflows/golangci-lint.yml:17
INFO
DEPCUR-NPM
npm package `prettier` is patch version(s) behind (3.8.1 -> 3.8.3)
web/frpc/package.json
INFO
DEPCUR-NPM
npm package `@vitejs/plugin-vue` is patch version(s) behind (6.0.5 -> 6.0.7)
web/frpc/package.json
INFO
DEPCUR-NPM
npm package `prettier` is patch version(s) behind (3.8.1 -> 3.8.3)
web/frps/package.json
INFO
DEPCUR-NPM
npm package `@vitejs/plugin-vue` is patch version(s) behind (6.0.5 -> 6.0.7)
web/frps/package.json