CRIT
MINED025
[MINED025] Php Eval: eval() executes arbitrary PHP. Code injection.
R/autocompletion.R:86
CRIT
MINED025
[MINED025] Php Eval: eval() executes arbitrary PHP. Code injection.
R/as_polars_df.R:182
CRIT
MINED024
[MINED024] Js Eval Usage: eval() executes arbitrary code. Code injection risk.
R/autocompletion.R:86
CRIT
MINED024
[MINED024] Js Eval Usage: eval() executes arbitrary code. Code injection risk.
R/as_polars_df.R:182
CRIT
MINED015
[MINED015] Ruby Eval Call: eval() executes arbitrary code. Code injection.
R/infer_polars_dtype.R:122
CRIT
MINED015
[MINED015] Ruby Eval Call: eval() executes arbitrary code. Code injection.
R/autocompletion.R:86
CRIT
MINED015
[MINED015] Ruby Eval Call: eval() executes arbitrary code. Code injection.
R/as_polars_df.R:182
CRIT
MINED022
[MINED022] C Strcpy: strcpy/strcat dont bounds-check; use strncpy or snprintf.
R/as_polars_dtype_expr.R:7
CRIT
MINED022
[MINED022] C Strcpy: strcpy/strcat dont bounds-check; use strncpy or snprintf.
R/as_polars_df.R:91
CRIT
MINED022
[MINED022] C Strcpy: strcpy/strcat dont bounds-check; use strncpy or snprintf.
R/000-utils-s7.R:19
CRIT
MINED116
Workflow uses `secrets.PAT` on a `pull_request` trigger
.github/workflows/lint-mega-linter.yaml:63
HIGH
MINED003
[MINED003] Rust Unwrap In Prod: .unwrap() panics if None/Err. Acceptable in tests; risky …
src/rust/src/conversion/clock.rs:27
HIGH
MINED003
[MINED003] Rust Unwrap In Prod: .unwrap() panics if None/Err. Acceptable in tests; risky …
src/rust/src/conversion/chunked_array.rs:10
HIGH
MINED003
[MINED003] Rust Unwrap In Prod: .unwrap() panics if None/Err. Acceptable in tests; risky …
src/rust/src/conversion/categorical.rs:28
HIGH
MINED029
[MINED029] Kotlin Null Bang: x!! throws NullPointerException if x is null. Bypasses Kotli…
R/as_polars_df.R:182
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/release-lib.yml:222
HIGH
MINED115
Action `r-lib/actions/setup-r-dependencies` pinned to mutable ref `@v2`
.github/workflows/release-lib.yml:193
HIGH
MINED115
Action `r-lib/actions/setup-r` pinned to mutable ref `@v2`
.github/workflows/release-lib.yml:187
HIGH
MINED115
Action `r-lib/actions/setup-pandoc` pinned to mutable ref `@v2`
.github/workflows/release-lib.yml:185
HIGH
MINED115
Action `actions/download-artifact` pinned to mutable ref `@v8`
.github/workflows/release-lib.yml:173
HIGH
MINED115
Action `rui314/setup-mold` pinned to mutable ref `@v1`
.github/workflows/release-lib.yml:156
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/release-lib.yml:155
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/release-lib.yml:119
HIGH
MINED115
Action `r-lib/actions/setup-r-dependencies` pinned to mutable ref `@v2`
.github/workflows/release-lib.yml:95
HIGH
MINED115
Action `r-lib/actions/setup-r` pinned to mutable ref `@v2`
.github/workflows/release-lib.yml:91
HIGH
MINED115
Action `Swatinem/rust-cache` pinned to mutable ref `@v2`
.github/workflows/release-lib.yml:63
HIGH
MINED115
Action `rui314/setup-mold` pinned to mutable ref `@v1`
.github/workflows/release-lib.yml:61
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/release-lib.yml:51
HIGH
MINED115
Action `actions/deploy-pages` pinned to mutable ref `@v5`
.github/workflows/build-docs.yml:170
HIGH
MINED115
Action `actions/upload-pages-artifact` pinned to mutable ref `@v5`
.github/workflows/build-docs.yml:153
HIGH
MINED115
Action `Swatinem/rust-cache` pinned to mutable ref `@v2`
.github/workflows/build-docs.yml:117
HIGH
MINED115
Action `rui314/setup-mold` pinned to mutable ref `@v1`
.github/workflows/build-docs.yml:115
HIGH
MINED115
Action `actions/configure-pages` pinned to mutable ref `@v6`
.github/workflows/build-docs.yml:108
HIGH
MINED115
Action `arduino/setup-task` pinned to mutable ref `@v2`
.github/workflows/build-docs.yml:98
HIGH
MINED115
Action `r-lib/actions/setup-r-dependencies` pinned to mutable ref `@v2`
.github/workflows/build-docs.yml:91
HIGH
MINED115
Action `quarto-dev/quarto-actions/setup` pinned to mutable ref `@v2`
.github/workflows/build-docs.yml:89
HIGH
MINED115
Action `actions/setup-python` pinned to mutable ref `@v6`
.github/workflows/build-docs.yml:85
HIGH
MINED115
Action `r-lib/actions/setup-r` pinned to mutable ref `@v2`
.github/workflows/build-docs.yml:79
HIGH
MINED115
Action `r-lib/actions/setup-pandoc` pinned to mutable ref `@v2`
.github/workflows/build-docs.yml:77
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/build-docs.yml:60
HIGH
RUSTSEC-2025-0141
bincode: RUSTSEC-2025-0141
src/rust/Cargo.lock
HIGH
CORE_NO_TESTS
No test files found
—
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
src/rust/src/r_udf.rs:55
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
R/autocompletion.R:86
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
R/as_polars_df.R:182
MED
AGT015
Remote install command pipes network code directly to a shell
.devcontainer/devcontainer.json:39
LOW
WEB005
robots.txt does not advertise a sitemap
.github/workflows/test-r.yml
INFO
MINED059
[MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message.
src/rust/src/r_threads.rs:53
INFO
MINED059
[MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message.
src/rust/src/lazyframe/mod.rs:30
INFO
MINED059
[MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message.
src/rust/src/dataframe/mod.rs:26
INFO
MINED068
[MINED068] Rust Unsafe Block: unsafe { ... } block. Compiler safety guarantees disabled i…
src/rust/src/conversion/data_table.rs:22
INFO
MINED068
[MINED068] Rust Unsafe Block: unsafe { ... } block. Compiler safety guarantees disabled i…
src/rust/src/conversion/clock.rs:27
INFO
MINED068
[MINED068] Rust Unsafe Block: unsafe { ... } block. Compiler safety guarantees disabled i…
src/rust/src/conversion/chunked_array.rs:10
INFO
MINED064
[MINED064] Python Input Call: input() blocks for stdin. Inappropriate in services.
R/utils-parse-expr.R:39
INFO
MINED050
[MINED050] Stub Only Function: Function declared but body is just pass, return None, rais…
R/import-standalone-lifecycle.R:209
INFO
MINED046
[MINED046] Dart Print: print() in Flutter goes to console. Use debugPrint / logger.
R/meta-versions.R:67
INFO
MINED046
[MINED046] Dart Print: print() in Flutter goes to console. Use debugPrint / logger.
R/lazyframe-utils.R:57
INFO
MINED046
[MINED046] Dart Print: print() in Flutter goes to console. Use debugPrint / logger.
R/dataframe-html.R:21
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
R/infer_polars_dtype.R:147
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
R/expr-s3-operators.R:127
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
R/as_polars_df.R:182
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
.github/scripts/generate-lib-sums.mjs:29