CRIT
MINED107
Missing import: `array` used but not imported
tests/benchmarks/highlighting-speed-src…:7397
CRIT
MINED116
Workflow uses `secrets.WINGET_TOKEN` on a `pull_request` trigger
.github/workflows/CICD.yml:464
CRIT
GHSA-pr76-5cm5-w9cj
gitpython: GHSA-pr76-5cm5-w9cj
assets/syntaxes/02_Extra/syntax_test_re…
CRIT
GHSA-hcpj-qp55-gfph
gitpython: GHSA-hcpj-qp55-gfph
assets/syntaxes/02_Extra/syntax_test_re…
HIGH
MINED003
[MINED003] Rust Unwrap In Prod: .unwrap() panics if None/Err. Acceptable in tests; risky …
examples/cat.rs:12
HIGH
MINED003
[MINED003] Rust Unwrap In Prod: .unwrap() panics if None/Err. Acceptable in tests; risky …
examples/buffer.rs:19
HIGH
MINED003
[MINED003] Rust Unwrap In Prod: .unwrap() panics if None/Err. Acceptable in tests; risky …
examples/advanced.rs:17
HIGH
MINED108
`self.three` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:274
HIGH
MINED108
`self.three` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:268
HIGH
MINED108
`self.two` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:267
HIGH
MINED108
`self.one` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:266
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:225
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:224
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:222
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:228
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:227
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:226
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:220
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:219
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:218
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:217
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:216
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:215
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:214
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:213
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:212
HIGH
MINED108
`self.arr` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:107
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:84
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:81
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:86
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:85
HIGH
MINED108
`self.a` used but never assigned in __init__
tests/benchmarks/highlighting-speed-src…:77
HIGH
MINED106
Phantom test coverage: test_dtypeattr
tests/benchmarks/highlighting-speed-src…:291
HIGH
MINED106
Phantom test coverage: test_attributes
tests/benchmarks/highlighting-speed-src…:270
HIGH
MINED106
Phantom test coverage: test_int
tests/benchmarks/highlighting-speed-src…:244
HIGH
MINED106
Phantom test coverage: test_void_align
tests/benchmarks/highlighting-speed-src…:237
HIGH
MINED106
Phantom test coverage: test_string_align
tests/benchmarks/highlighting-speed-src…:230
HIGH
MINED106
Phantom test coverage: test_otherflags
tests/benchmarks/highlighting-speed-src…:211
HIGH
MINED106
Phantom test coverage: test_warnonwrite
tests/benchmarks/highlighting-speed-src…:201
HIGH
MINED106
Phantom test coverage: test_writeable_pickle
tests/benchmarks/highlighting-speed-src…:150
HIGH
MINED106
Phantom test coverage: test_writeable_from_buffer
tests/benchmarks/highlighting-speed-src…:132
HIGH
MINED106
Phantom test coverage: test_writeable_from_readonly
tests/benchmarks/highlighting-speed-src…:121
HIGH
MINED106
Phantom test coverage: test_writeable_any_base
tests/benchmarks/highlighting-speed-src…:88
HIGH
MINED106
Phantom test coverage: test_writeable
tests/benchmarks/highlighting-speed-src…:79
HIGH
MINED106
Phantom test coverage: test_getfield
tests/benchmarks/highlighting-speed-src…:8457
HIGH
MINED106
Phantom test coverage: test_uintalignment_and_alignment
tests/benchmarks/highlighting-speed-src…:8350
HIGH
MINED106
Phantom test coverage: test_npymath_real
tests/benchmarks/highlighting-speed-src…:8329
HIGH
MINED106
Phantom test coverage: test_npymath_complex
tests/benchmarks/highlighting-speed-src…:8310
HIGH
MINED106
Phantom test coverage: test_equal_override
tests/benchmarks/highlighting-speed-src…:8284
HIGH
MINED106
Phantom test coverage: test_orderconverter_with_nonASCII_unicode_ordering
tests/benchmarks/highlighting-speed-src…:8278
HIGH
MINED106
Phantom test coverage: test_scalar_element_deletion
tests/benchmarks/highlighting-speed-src…:7461
HIGH
MINED106
Phantom test coverage: test_flat_element_deletion
tests/benchmarks/highlighting-speed-src…:7450
HIGH
MINED106
Phantom test coverage: test_array_interface_offset
tests/benchmarks/highlighting-speed-src…:7436
HIGH
MINED106
Phantom test coverage: test_array_interface_empty_shape
tests/benchmarks/highlighting-speed-src…:7411
HIGH
MINED106
Phantom test coverage: test_array_interface_itemsize
tests/benchmarks/highlighting-speed-src…:7401
HIGH
MINED106
Phantom test coverage: test_interface_no_shape
tests/benchmarks/highlighting-speed-src…:7394
HIGH
MINED106
Phantom test coverage: test_matmul_inplace
tests/benchmarks/highlighting-speed-src…:6329
HIGH
MINED115
Action `softprops/action-gh-release` pinned to mutable ref `@v2`
.github/workflows/CICD.yml:445
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@master`
.github/workflows/CICD.yml:431
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@master`
.github/workflows/CICD.yml:425
HIGH
MINED115
Action `dtolnay/rust-toolchain` pinned to mutable ref `@stable`
.github/workflows/CICD.yml:192
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/CICD.yml:181
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/CICD.yml:153
HIGH
MINED115
Action `dtolnay/rust-toolchain` pinned to mutable ref `@stable`
.github/workflows/CICD.yml:140
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/CICD.yml:138
HIGH
MINED115
Action `dtolnay/rust-toolchain` pinned to mutable ref `@stable`
.github/workflows/CICD.yml:127
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/CICD.yml:122
HIGH
MINED115
Action `dtolnay/rust-toolchain` pinned to mutable ref `@stable`
.github/workflows/CICD.yml:97
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/CICD.yml:93
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/CICD.yml:83
HIGH
MINED115
Action `dtolnay/rust-toolchain` pinned to mutable ref `@master`
.github/workflows/CICD.yml:73
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/CICD.yml:71
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/CICD.yml:61
HIGH
MINED115
Action `dtolnay/rust-toolchain` pinned to mutable ref `@stable`
.github/workflows/CICD.yml:58
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/CICD.yml:38
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/require-changelog-for…:16
HIGH
MINED121
requirements.txt installs from `https://github.com/pallets/click/archive/7.0.zip#e...` (g…
tests/syntax-tests/source/Requirements.…:40
HIGH
MINED121
requirements.txt installs from `-e bzr+https://bzr.myproject.org/MyProject/trunk@2...` (g…
tests/syntax-tests/source/Requirements.…:37
HIGH
MINED121
requirements.txt installs from `-e bzr+ssh://[email protected] /MyProject/trunk#eg...` (g…
tests/syntax-tests/source/Requirements.…:36
HIGH
MINED121
requirements.txt installs from `-e svn+http://svn.myproject.org/svn/MyProject/trun...` (g…
tests/syntax-tests/source/Requirements.…:35
HIGH
MINED121
requirements.txt installs from `-e hg+http://hg.myproject.org/MyProject@da39a3ee5e...` (g…
tests/syntax-tests/source/Requirements.…:34
HIGH
MINED121
requirements.txt installs from `-e hg+https://hg.myproject.org/MyProject#egg=MyPro...` (g…
tests/syntax-tests/source/Requirements.…:33
HIGH
MINED121
requirements.txt installs from `-e git+git://git.myproject.org/MyProject#egg=MyPro...` (g…
tests/syntax-tests/source/Requirements.…:31
HIGH
MINED121
requirements.txt installs from `pip @ https://github.com/pypa/pip/archive/1.3.1.zi...` (g…
tests/syntax-tests/source/Requirements.…:26
HIGH
GO-2026-5039
stdlib: GO-2026-5039
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-5038
stdlib: GO-2026-5038
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-5037
stdlib: GO-2026-5037
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4986
stdlib: GO-2026-4986
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4982
stdlib: GO-2026-4982
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4981
stdlib: GO-2026-4981
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4980
stdlib: GO-2026-4980
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4977
stdlib: GO-2026-4977
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4976
stdlib: GO-2026-4976
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4971
stdlib: GO-2026-4971
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4947
stdlib: GO-2026-4947
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4946
stdlib: GO-2026-4946
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4918
stdlib: GO-2026-4918
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4870
stdlib: GO-2026-4870
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4869
stdlib: GO-2026-4869
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4865
stdlib: GO-2026-4865
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4864
stdlib: GO-2026-4864
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4603
stdlib: GO-2026-4603
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4602
stdlib: GO-2026-4602
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4601
stdlib: GO-2026-4601
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4342
stdlib: GO-2026-4342
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4341
stdlib: GO-2026-4341
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4340
stdlib: GO-2026-4340
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2026-4337
stdlib: GO-2026-4337
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2025-4175
stdlib: GO-2025-4175
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2025-4155
stdlib: GO-2025-4155
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2025-4015
stdlib: GO-2025-4015
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2025-4014
stdlib: GO-2025-4014
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2025-4013
stdlib: GO-2025-4013
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2025-4012
stdlib: GO-2025-4012
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2025-4011
stdlib: GO-2025-4011
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2025-4010
stdlib: GO-2025-4010
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2025-4009
stdlib: GO-2025-4009
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2025-4008
stdlib: GO-2025-4008
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2025-4007
stdlib: GO-2025-4007
tests/syntax-tests/source/Go/go.mod
HIGH
GO-2025-4006
stdlib: GO-2025-4006
tests/syntax-tests/source/Go/go.mod
HIGH
GHSA-x2qx-6953-8485
gitpython: GHSA-x2qx-6953-8485
assets/syntaxes/02_Extra/syntax_test_re…
HIGH
GHSA-v87r-6q3f-2j67
gitpython: GHSA-v87r-6q3f-2j67
assets/syntaxes/02_Extra/syntax_test_re…
HIGH
GHSA-mv93-w799-cj2w
gitpython: GHSA-mv93-w799-cj2w
assets/syntaxes/02_Extra/syntax_test_re…
HIGH
GHSA-7545-fcxq-7j24
gitpython: GHSA-7545-fcxq-7j24
assets/syntaxes/02_Extra/syntax_test_re…
HIGH
GHSA-2mqj-m65w-jghx
gitpython: GHSA-2mqj-m65w-jghx
assets/syntaxes/02_Extra/syntax_test_re…
HIGH
PYSEC-2023-165
gitpython: PYSEC-2023-165
assets/syntaxes/02_Extra/syntax_test_re…
HIGH
PYSEC-2023-161
gitpython: PYSEC-2023-161
assets/syntaxes/02_Extra/syntax_test_re…
HIGH
PYSEC-2023-117
pygments: PYSEC-2023-117
assets/syntaxes/02_Extra/syntax_test_re…
HIGH
PYSEC-2021-66
jinja2: PYSEC-2021-66
assets/syntaxes/02_Extra/syntax_test_re…
HIGH
PYSEC-2019-217
jinja2: PYSEC-2019-217
assets/syntaxes/02_Extra/syntax_test_re…
HIGH
RUSTSEC-2024-0320
yaml-rust: RUSTSEC-2024-0320
Cargo.lock
HIGH
RUSTSEC-2025-0141
bincode: RUSTSEC-2025-0141
Cargo.lock
MED
DKR007
Docker build context has no .dockerignore
.dockerignore
MED
DEPCUR-GHA
GitHub Action `softprops/action-gh-release@v2` is 1 major version(s) behind (latest v3.0.…
.github/workflows/CICD.yml:445
MED
DEPCUR-PY
Python package `zope.interface` is 4 major version(s) behind (4.2.0 -> 8.5)
tests/syntax-tests/source/Requirements.…:21
MED
DEPCUR-PY
Python package `sphinx-rtd-theme` is 3 major version(s) behind (0.1.9 -> 3.1.0)
tests/syntax-tests/source/Requirements.…:19
MED
DEPCUR-PY
Python package `Sphinx` is 8 major version(s) behind (1.3.3 -> 9.1.0)
tests/syntax-tests/source/Requirements.…:18
MED
DEPCUR-PY
Python package `snowballstemmer` is 2 major version(s) behind (1.2.0 -> 3.1.1)
tests/syntax-tests/source/Requirements.…:17
MED
DEPCUR-PY
Python package `pytz` is 11 major version(s) behind (2015.7 -> 2026.2)
tests/syntax-tests/source/Requirements.…:15
MED
DEPCUR-PY
Python package `MarkupSafe` is 3 major version(s) behind (0.23 -> 3.0.3)
tests/syntax-tests/source/Requirements.…:13
MED
DEPCUR-PY
Python package `alabaster` is 1 major version(s) behind (0.7.6 -> 1.0.0)
tests/syntax-tests/source/Requirements.…:6
MED
MINED124
requirements.txt: `[4;38;2;166;226;46mhttps://github.com/pallets/click/archive/7.0.zip#e…
tests/syntax-tests/highlighted/Requirem…:40
MED
MINED124
requirements.txt: `[38;2;117;113;94m#[0m[38;2;117;113;94m Project or archive URL[0m` …
tests/syntax-tests/highlighted/Requirem…:39
MED
MINED124
requirements.txt: `[38;2;166;226;46m-e[0m[38;2;248;248;242m [0m[4;38;2;166;226;46mhg…
tests/syntax-tests/highlighted/Requirem…:33
MED
MINED124
requirements.txt: `[38;2;166;226;46m-e[0m[38;2;248;248;242m [0m[4;38;2;166;226;46mgi…
tests/syntax-tests/highlighted/Requirem…:31
MED
MINED124
requirements.txt: `[38;2;117;113;94m#[0m[38;2;117;113;94m VCS repositories[0m` has no…
tests/syntax-tests/highlighted/Requirem…:30
MED
MINED124
requirements.txt: `[38;2;117;113;94m#[0m[38;2;117;113;94m c.f. https://www.python.org/…
tests/syntax-tests/highlighted/Requirem…:24
MED
MINED124
requirements.txt: `[38;2;117;113;94m#[0m[38;2;117;113;94m Examples from PEP508[0m` ha…
tests/syntax-tests/highlighted/Requirem…:23
MED
MINED124
requirements.txt: `[38;2;117;113;94m#[0m[38;2;117;113;94m Freeze packages[0m` has no …
tests/syntax-tests/highlighted/Requirem…:5
MED
MINED124
requirements.txt: `[38;2;166;226;46m--allow-unverified[0m` has no version pin
tests/syntax-tests/highlighted/Requirem…:3
MED
MINED124
requirements.txt: `[38;2;166;226;46m--allow-external[0m` has no version pin
tests/syntax-tests/highlighted/Requirem…:2
MED
MINED124
requirements.txt: `[38;2;117;113;94m#[0m[38;2;117;113;94m Options[0m` has no version …
tests/syntax-tests/highlighted/Requirem…:1
MED
GHSA-q2x7-8rv6-6q7h
jinja2: GHSA-q2x7-8rv6-6q7h
assets/syntaxes/02_Extra/syntax_test_re…
MED
GHSA-h75v-3vvj-5mfj
jinja2: GHSA-h75v-3vvj-5mfj
assets/syntaxes/02_Extra/syntax_test_re…
MED
GHSA-h5c8-rqwp-cp95
jinja2: GHSA-h5c8-rqwp-cp95
assets/syntaxes/02_Extra/syntax_test_re…
MED
GHSA-cpwx-vrp4-4pq7
jinja2: GHSA-cpwx-vrp4-4pq7
assets/syntaxes/02_Extra/syntax_test_re…
MED
DKR001
Docker final stage has no non-root USER
tests/syntax-tests/source/Dockerfile/Do…:2
LOW
DEPCUR-PY
Python package `six` is minor version(s) behind (1.10.0 -> 1.17.0)
tests/syntax-tests/source/Requirements.…:16
LOW
DEPCUR-PY
Python package `Pygments` is minor version(s) behind (2.7.4 -> 2.20.0)
tests/syntax-tests/source/Requirements.…:14
LOW
DEPCUR-PY
Python package `gitpython` is minor version(s) behind (3.0.7 -> 3.1.50)
tests/syntax-tests/source/Requirements.…:10
LOW
DEPCUR-PY
Python package `docutils` is minor version(s) behind (0.12 -> 0.23)
tests/syntax-tests/source/Requirements.…:8
LOW
GHSA-5239-wwwm-4pmq
pygments: GHSA-5239-wwwm-4pmq
assets/syntaxes/02_Extra/syntax_test_re…
LOW
AIC007
Generated build artifact directory is present at repository root
build:1
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
src/less.rs:48
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
src/assets/build_assets/acknowledgement…:96
INFO
MINED059
[MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message.
src/output.rs:36
INFO
MINED059
[MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message.
src/assets/build_assets/acknowledgement…:137
INFO
MINED059
[MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message.
src/assets/assets_metadata.rs:69
INFO
DEPCUR-GHA
GitHub Action `actions/checkout@v6` is patch version(s) behind (latest v6.0.3)
.github/workflows/CICD.yml:38
INFO
DEPCUR-GHA
GitHub Action `actions/checkout@v6` is patch version(s) behind (latest v6.0.3)
.github/workflows/require-changelog-for…:16