https://github.com/juspay/hyperswitch.git
· scanned 2026-05-17 02:58 UTC (12 hours, 24 minutes ago)
· 10 languages
2613 findings (201 legacy + 2412 scanner) 8/10 scanners ran Scanner says 59 (higher by 20)
Last scanned 12 hours, 25 minutes ago · v2 · 2613 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Showing 2545 of 2613 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
crates/hyperswitch_connectors/src/utils.rs:34
credential_exposurelegacy
crates/common_enums/src/enums.rs:6565
credential_exposurelegacy
crates/hsdev/src/input_file.rs:22
credential_exposurelegacy
crates/common_utils/src/lib.rs:324
credential_exposurelegacy
crates/analytics/src/sqlx.rs:45
credential_exposurelegacy
docker-compose.yml:522
dockerlegacy
docker-compose.yml:480
dockerlegacy
docker-compose.yml:26
dockerlegacy
docker-compose.yml:506
dockerlegacy
crates/connector_configs/toml/development.toml:5893
owaspprivate_key_in_repo
crates/connector_configs/toml/production.toml:5658
owaspprivate_key_in_repo
crates/connector_configs/toml/sandbox.toml:5857
owaspprivate_key_in_repo
config/deployments/drainer.toml:34
secrets
config/development.toml:24
secrets
config/development.toml:34
secrets
config/development.toml:1365
secrets
config/development.toml:1392
secrets
config/docker_compose.toml:31
secrets
config/docker_compose.toml:46
secrets
config/docker_compose.toml:1190
secrets
config/docker_compose.toml:1227
secrets
crates/hsdev/src/main.rs:103
secrets
crates/hsdev/src/main.rs:124
secrets
scripts/create_default_user.sh:3
secrets
crates/analytics/src/sqlx.rs:59
ssrflegacy
crates/analytics/src/errors.rs:20
ssrflegacy
connector-template/mod.rs:262
ssrflegacy
crates/hyperswitch_connectors/src/connectors/nuvei/transformers.rs:1129
open_redirectlegacy
crates/hyperswitch_connectors/src/connectors/mollie.rs:868
resource_exhaustionlegacy
crates/hyperswitch_connectors/src/connectors/checkout/transformers.rs:2185
resource_exhaustionlegacy
crates/hyperswitch_connectors/src/connectors/bluesnap.rs:1136
resource_exhaustionlegacy
docker-compose.yml:495
dockerlegacy
docker-compose.yml:480
dockerlegacy
docker-compose.yml:462
dockerlegacy
docker-compose.yml:26
dockerlegacy
docker-compose.yml:495
dockerlegacy
docker-compose.yml:480
dockerlegacy
docker-compose.yml:462
dockerlegacy
docker-compose.yml:447
dockerlegacy
docker-compose.yml:413
dockerlegacy
docker-compose.yml:402
dockerlegacy
docker-compose.yml:292
dockerlegacy
docker-compose.yml:45
dockerlegacy
docker-compose.yml:26
dockerlegacy
.github/workflows/postman-collection-runner.yml:88
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-stable-version.yml:96
supply-chaingithub-actionspinned-dependencies
.github/workflows/pr-convention-checks.yml:36
supply-chaingithub-actionspinned-dependencies
.github/workflows/pr-title-spell-check.yml:25
supply-chaingithub-actionspinned-dependencies
.github/workflows/migration-check.yaml:51
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-pr.yml:60
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-pr.yml:118
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-pr.yml:180
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-pr.yml:237
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-pr.yml:276
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-nightly-version-reusable.yml:59
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:46
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:87
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:180
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:248
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:287
supply-chaingithub-actionspinned-dependencies
.github/workflows/wasm-bulild-check.yml:22
supply-chaingithub-actionspinned-dependencies
crates/redis_interface/src/module/fred/commands.rs:1168
owaspeval_used
config/development.toml:150
qualitylegacy
docker-compose.yml:250
dockerlegacy
docker-compose.yml:333
dockerlegacy
monitoring/docker-compose.yaml:73
dockerlegacy
docker-compose.yml:231
dockerlegacy
docker-compose.yml:522
dockerlegacy
docker-compose.yml:212
dockerlegacy
docker-compose.yml:447
dockerlegacy
docker-compose.yml:350
dockerlegacy
monitoring/docker-compose.yaml:25
dockerlegacy
docker-compose.yml:110
dockerlegacy
docker-compose.yml:362
dockerlegacy
monitoring/docker-compose.yaml:36
dockerlegacy
docker-compose.yml:26
dockerlegacy
docker-compose.yml:272
dockerlegacy
docker-compose.yml:10
dockerlegacy
docker-compose.yml:376
dockerlegacy
monitoring/docker-compose.yaml:49
dockerlegacy
monitoring/docker-compose.yaml:15
dockerlegacy
docker-compose.yml:402
dockerlegacy
docker-compose.yml:92
dockerlegacy
docker-compose.yml:388
dockerlegacy
monitoring/docker-compose.yaml:59
dockerlegacy
docker-compose.yml:495
dockerlegacy
docker-compose.yml:480
dockerlegacy
docker-compose.yml:462
dockerlegacy
docker-compose.yml:447
dockerlegacy
docker-compose.yml:413
dockerlegacy
docker-compose.yml:402
dockerlegacy
docker-compose.yml:307
dockerlegacy
docker-compose.yml:292
dockerlegacy
docker-compose.yml:45
dockerlegacy
Dockerfile:33
dockerlegacy
Dockerfile:34
dockerlegacy
crates/router/src/types/api/refunds_v2.rs:1
qualitylegacy
crates/router/src/types/api/payouts_v2.rs:1
qualitylegacy
crates/router/src/types/api/payments_v2.rs:1
qualitylegacy
crates/router/src/types/api/merchant_connector_webhook_management_v2.rs:1
qualitylegacy
crates/router/src/types/api/fraud_check_v2.rs:1
qualitylegacy
crates/router/src/types/api/files_v2.rs:1
qualitylegacy
crates/router/src/types/api/disputes_v2.rs:1
qualitylegacy
crates/router/src/types/api/authentication_v2.rs:1
qualitylegacy
crates/router/src/core/webhooks/outgoing_v2.rs:1
qualitylegacy
crates/router/src/core/webhooks/incoming_v2.rs:1
qualitylegacy
crates/router/src/core/payments/operations/payment_capture_v2.rs:1
qualitylegacy
crates/router/src/core/payments/operations/payment_cancel_v2.rs:1
qualitylegacy
crates/router/src/core/refunds_v2.rs:1
qualitylegacy
crates/openapi/src/openapi_v2.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/api/vault_v2.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/api/subscriptions_v2.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/api/revenue_recovery_v2.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/api/refunds_v2.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/api/payouts_v2.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/api/payments_v2.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/api/merchant_connector_webhook_management_v2.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/api/fraud_check_v2.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/api/files_v2.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/api/disputes_v2.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/api/authentication_v2.rs:1
qualitylegacy
crates/hyperswitch_domain_models/src/router_data_v2.rs:1
qualitylegacy
crates/hyperswitch_connectors/src/default_implementations_v2.rs:1
qualitylegacy
crates/diesel_models/src/schema_v2.rs:1
qualitylegacy
docker-compose.yml:65
dependencylegacy
docker-compose-development.yml:54
dependencylegacy
crates/router/src/core/payments/operations/payment_cancel_v2.rs:1
qualitylegacy
crates/openapi/src/openapi_v2.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/connector_integration_v2.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/api/merchant_connector_webhook_management_v2.rs:1
qualitylegacy
crates/hyperswitch_connectors/src/default_implementations_v2.rs:1
qualitylegacy
.github/workflows/postman-collection-runner.yml:94
supply-chaingithub-actionspinned-dependencies
.github/workflows/postman-collection-runner.yml:100
supply-chaingithub-actionspinned-dependencies
.github/workflows/postman-collection-runner.yml:106
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-stable-version.yml:101
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-stable-version.yml:107
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-pr.yml:106
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-pr.yml:123
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-pr.yml:128
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-pr.yml:174
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-pr.yml:186
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-pr.yml:191
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-pr.yml:196
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-nightly-version-reusable.yml:64
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:75
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:92
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:107
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:113
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:174
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:186
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:197
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:203
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:258
supply-chaingithub-actionspinned-dependencies
.github/workflows/CI-push.yml:281
supply-chaingithub-actionspinned-dependencies
.github/workflows/wasm-bulild-check.yml:27
supply-chaingithub-actionspinned-dependencies
.github/workflows/create-hotfix-tag.yml:25
supply-chaingithub-actionspinned-dependencies
crates/hyperswitch_connectors/src/connectors/trustly/transformers.rs:350
owaspweak_hash
crates/hyperswitch_connectors/src/connectors/zsl/transformers.rs:129
owaspweak_hash
crates/router/src/utils/user/two_factor_auth.rs:24
owaspweak_hash
.github/workflows/release-nightly-version.yml
securityports
.dockerignore
dockerlegacy
docker-compose.yml:522
dockerlegacy
docker-compose.yml:506
dockerlegacy
docker-compose.yml:462
dockerlegacy
docker-compose.yml:388
dockerlegacy
docker-compose.yml:376
dockerlegacy
docker-compose.yml:362
dockerlegacy
docker-compose.yml:350
dockerlegacy
docker-compose.yml:333
dockerlegacy
docker-compose.yml:231
dockerlegacy
docker-compose.yml:212
dockerlegacy
docker-compose.yml:121
dockerlegacy
docker-compose.yml:110
dockerlegacy
monitoring/docker-compose.yaml:73
dockerlegacy
monitoring/docker-compose.yaml:59
dockerlegacy
monitoring/docker-compose.yaml:49
dockerlegacy
monitoring/docker-compose.yaml:36
dockerlegacy
monitoring/docker-compose.yaml:25
dockerlegacy
docker-compose.yml:79
dockerlegacy
docker-compose.yml:522
dockerlegacy
docker-compose.yml:506
dockerlegacy
docker-compose.yml:462
dockerlegacy
docker-compose.yml:388
dockerlegacy
docker-compose.yml:376
dockerlegacy
docker-compose.yml:362
dockerlegacy
docker-compose.yml:350
dockerlegacy
docker-compose.yml:333
dockerlegacy
docker-compose.yml:231
dockerlegacy
docker-compose.yml:212
dockerlegacy
docker-compose.yml:121
dockerlegacy
docker-compose.yml:110
dockerlegacy
monitoring/docker-compose.yaml:73
dockerlegacy
monitoring/docker-compose.yaml:59
dockerlegacy
monitoring/docker-compose.yaml:49
dockerlegacy
monitoring/docker-compose.yaml:36
dockerlegacy
monitoring/docker-compose.yaml:25
dockerlegacy
docker-compose.yml:79
dockerlegacy
docker-compose.yml:447
dockerlegacy
docker-compose.yml:413
dockerlegacy
docker-compose.yml:402
dockerlegacy
docker-compose.yml:307
dockerlegacy
docker-compose.yml:292
dockerlegacy
Dockerfile:62
dockerlegacy
Dockerfile:6
dockerlegacy
Dockerfile:62
dockerlegacy
Dockerfile:6
dockerlegacy
crates/analytics/src/auth_events/metrics/authentication_funnel.rs:46
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_funnel.rs:22
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_funnel.rs:20
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_exemption_requested_count.rs:45
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_exemption_requested_count.rs:43
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_exemption_requested_count.rs:19
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_exemption_requested_count.rs:17
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_exemption_requested_count.rs:1
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_exemption_approved_count.rs:45
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_exemption_approved_count.rs:43
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_exemption_approved_count.rs:19
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_exemption_approved_count.rs:17
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_exemption_approved_count.rs:1
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_error_message.rs:46
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_error_message.rs:45
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_error_message.rs:23
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_error_message.rs:21
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_count.rs:45
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_count.rs:43
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_count.rs:19
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_count.rs:17
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_attempt_count.rs:46
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_attempt_count.rs:44
qualitylegacy
crates/analytics/src/auth_events/metrics/authentication_attempt_count.rs:20
qualitylegacy
crates/analytics/src/auth_events/metrics.rs:51
qualitylegacy
crates/analytics/src/auth_events/core.rs:46
qualitylegacy
crates/analytics/src/api_event/metrics/status_code_count.rs:47
qualitylegacy
crates/analytics/src/api_event/metrics/status_code_count.rs:1
qualitylegacy
crates/analytics/src/api_event/metrics/latency.rs:19
qualitylegacy
crates/analytics/src/active_payments/metrics/active_payments.rs:17
qualitylegacy
crates/router/src/core/payments/operations/payment_update.rs:1
qualitylegacy
crates/hyperswitch_interfaces/src/connector_integration_v2.rs:1
qualitylegacy
Dockerfile:40
supply-chaindockerpinned-dependencies
docker/fluentd/Dockerfile:2
supply-chaindockerpinned-dependencies
Dockerfile:1
supply-chaindockerpinned-dependencies
.github/workflows/api-migrations-compatibility.yml:35
supply-chaingithub-actionspinned-dependencies
.github/workflows/api-migrations-compatibility.yml:40
supply-chaingithub-actionspinned-dependencies
.github/workflows/api-migrations-compatibility.yml:128
supply-chaingithub-actionspinned-dependencies
.github/workflows/postman-collection-runner.yml:52
supply-chaingithub-actionspinned-dependencies
Showing first 300 of 2545. Refine filters or use the legacy findings page for deep search.
{# ── 2026-05-17 Round 14: AI-agent bridge footer ────────────────────── Discoverability: the /agents/voting/ guide + MCP manifest exist but aren't linked from anywhere users actually land. Small, opt-in footer. #}
This page is publicly accessible at:
https://repobility.com/scan/9c39f054-10cb-4584-aa89-251222603de5/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/9c39f054-10cb-4584-aa89-251222603de5/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.