CRIT
curl-auth-header
Discovered a potential authorization token provided in a curl command header, which could…
docs/api-guide.mdx:166
CRIT
curl-auth-header
Discovered a potential authorization token provided in a curl command header, which could…
docs/api-guide.mdx:163
CRIT
curl-auth-header
Discovered a potential authorization token provided in a curl command header, which could…
docs/api-guide.mdx:128
CRIT
curl-auth-header
Discovered a potential authorization token provided in a curl command header, which could…
docs/api-guide.mdx:124
CRIT
curl-auth-header
Discovered a potential authorization token provided in a curl command header, which could…
docs/api-guide.mdx:120
CRIT
curl-auth-header
Discovered a potential authorization token provided in a curl command header, which could…
docs/howto/api-keys.mdx:26
CRIT
MINED116
Workflow uses `secrets.CONTEXT7_API_KEY` on a `pull_request` trigger
.github/workflows/test.yml:63
CRIT
MINED116
Workflow uses `secrets.AWS_BEARER_TOKEN_BEDROCK` on a `pull_request` trigger
.github/workflows/test.yml:62
CRIT
MINED116
Workflow uses `secrets.AWS_REGION` on a `pull_request` trigger
.github/workflows/test.yml:61
CRIT
GHSA-5xrq-8626-4rwp
vitest: GHSA-5xrq-8626-4rwp
pnpm-lock.yaml
HIGH
SEC018
[SEC018] AI-Agent Secret Retrieval Command: A command that prints or embeds credentials w…
packages/cli/src/utils/github.ts:88
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
packages/sdk/src/commands/command.ts:25
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
packages/sdk/src/client.ts:87
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
packages/cli/src/setup/mcp-writer.ts:146
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
packages/cli/src/setup/agents.ts:82
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
packages/cli/src/index.ts:28
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
packages/cli/src/commands/auth.ts:21
HIGH
SEC020
[SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-b…
packages/sdk/src/client.ts:31
HIGH
MINED115
Action `changesets/action` pinned to mutable ref `@v1`
.github/workflows/release.yml:43
HIGH
MINED115
Action `pnpm/action-setup` pinned to mutable ref `@v4`
.github/workflows/release.yml:27
HIGH
MINED115
Action `actions/setup-node` pinned to mutable ref `@v4`
.github/workflows/release.yml:22
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/release.yml:19
HIGH
MINED115
Action `aws-actions/amazon-ecr-login` pinned to mutable ref `@v2`
.github/workflows/ecr-deploy.yml:28
HIGH
MINED115
Action `aws-actions/configure-aws-credentials` pinned to mutable ref `@v5`
.github/workflows/ecr-deploy.yml:20
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/ecr-deploy.yml:17
HIGH
MINED115
Action `actions/setup-node` pinned to mutable ref `@v4`
.github/workflows/mcp-registry.yml:23
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/mcp-registry.yml:20
HIGH
MINED115
Action `pnpm/action-setup` pinned to mutable ref `@v4`
.github/workflows/canary-release.yml:29
HIGH
MINED115
Action `actions/setup-node` pinned to mutable ref `@v4`
.github/workflows/canary-release.yml:24
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/canary-release.yml:19
HIGH
MINED115
Action `actions/github-script` pinned to mutable ref `@v7`
.github/workflows/changeset-check.yml:18
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/changeset-check.yml:13
HIGH
MINED115
Action `actions/cache` pinned to mutable ref `@v5`
.github/workflows/test.yml:36
HIGH
MINED115
Action `pnpm/action-setup` pinned to mutable ref `@v4`
.github/workflows/test.yml:25
HIGH
MINED115
Action `actions/setup-node` pinned to mutable ref `@v4`
.github/workflows/test.yml:20
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/test.yml:17
HIGH
MINED118
Dockerfile FROM `node:lts-alpine` not pinned by digest
packages/mcp/Dockerfile:15
HIGH
MINED118
Dockerfile FROM `node:lts-alpine` not pinned by digest
packages/mcp/Dockerfile:2
HIGH
GHSA-v2wj-q39q-566r
vite: GHSA-v2wj-q39q-566r
pnpm-lock.yaml
HIGH
GHSA-p9ff-h696-f583
vite: GHSA-p9ff-h696-f583
pnpm-lock.yaml
HIGH
GHSA-vrm6-8vpv-qv8q
undici: GHSA-vrm6-8vpv-qv8q
pnpm-lock.yaml
HIGH
GHSA-v9p9-hfj2-hcw8
undici: GHSA-v9p9-hfj2-hcw8
pnpm-lock.yaml
HIGH
GHSA-f269-vfmq-vjvj
undici: GHSA-f269-vfmq-vjvj
pnpm-lock.yaml
HIGH
GHSA-mw96-cpmx-2vgc
rollup: GHSA-mw96-cpmx-2vgc
pnpm-lock.yaml
HIGH
GHSA-c2c7-rcm5-vvqj
picomatch: GHSA-c2c7-rcm5-vvqj
pnpm-lock.yaml
HIGH
GHSA-j3q9-mxjg-w52f
path-to-regexp: GHSA-j3q9-mxjg-w52f
pnpm-lock.yaml
HIGH
GHSA-7r86-cg39-jmmj
minimatch: GHSA-7r86-cg39-jmmj
pnpm-lock.yaml
HIGH
GHSA-3ppc-4f35-3m26
minimatch: GHSA-3ppc-4f35-3m26
pnpm-lock.yaml
HIGH
GHSA-23c5-xmqv-rm74
minimatch: GHSA-23c5-xmqv-rm74
pnpm-lock.yaml
HIGH
GHSA-q5qw-h33p-qvwr
hono: GHSA-q5qw-h33p-qvwr
pnpm-lock.yaml
HIGH
GHSA-f67f-6cw9-8mq4
hono: GHSA-f67f-6cw9-8mq4
pnpm-lock.yaml
HIGH
GHSA-3vhc-576x-3qv4
hono: GHSA-3vhc-576x-3qv4
pnpm-lock.yaml
HIGH
GHSA-rf6f-7fwh-wjgh
flatted: GHSA-rf6f-7fwh-wjgh
pnpm-lock.yaml
HIGH
GHSA-25h7-pfq9-p65f
flatted: GHSA-25h7-pfq9-p65f
pnpm-lock.yaml
HIGH
GHSA-v39h-62p7-jpjc
fast-uri: GHSA-v39h-62p7-jpjc
pnpm-lock.yaml
HIGH
GHSA-q3j6-qgpj-74h6
fast-uri: GHSA-q3j6-qgpj-74h6
pnpm-lock.yaml
HIGH
GHSA-345p-7cg4-v4c7
@modelcontextprotocol/sdk: GHSA-345p-7cg4-v4c7
pnpm-lock.yaml
HIGH
GHSA-wc8c-qw6v-h7f6
@hono/node-server: GHSA-wc8c-qw6v-h7f6
pnpm-lock.yaml
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
packages/cli/src/utils/tracking.ts:9
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
packages/sdk/src/commands/command.ts:25
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
packages/sdk/src/client.ts:87
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
packages/cli/src/setup/mcp-writer.ts:146
MED
DKR007
Docker build context has no .dockerignore
.dockerignore
MED
DEPCUR-GHA
GitHub Action `pnpm/action-setup@v4` is 2 major version(s) behind (latest v6.0.8)
.github/workflows/release.yml:27
MED
DEPCUR-GHA
GitHub Action `actions/setup-node@v4` is 2 major version(s) behind (latest v6.4.0)
.github/workflows/release.yml:22
MED
DEPCUR-GHA
GitHub Action `aws-actions/configure-aws-credentials@v5` is 1 major version(s) behind (la…
.github/workflows/ecr-deploy.yml:20
MED
DEPCUR-GHA
GitHub Action `actions/setup-node@v4` is 2 major version(s) behind (latest v6.4.0)
.github/workflows/mcp-registry.yml:23
MED
DEPCUR-GHA
GitHub Action `pnpm/action-setup@v4` is 2 major version(s) behind (latest v6.0.8)
.github/workflows/canary-release.yml:29
MED
DEPCUR-GHA
GitHub Action `actions/setup-node@v4` is 2 major version(s) behind (latest v6.4.0)
.github/workflows/canary-release.yml:24
MED
DEPCUR-GHA
GitHub Action `actions/github-script@v7` is 2 major version(s) behind (latest v9.0.0)
.github/workflows/changeset-check.yml:18
MED
DEPCUR-GHA
GitHub Action `pnpm/action-setup@v4` is 2 major version(s) behind (latest v6.0.8)
.github/workflows/test.yml:25
MED
DEPCUR-GHA
GitHub Action `actions/setup-node@v4` is 2 major version(s) behind (latest v6.4.0)
.github/workflows/test.yml:20
MED
DEPCUR-NPM
npm package `undici` is 2 major version(s) behind (^6.6.3 -> 8.3.0)
packages/mcp/package.json
MED
DEPCUR-NPM
npm package `commander` is 1 major version(s) behind (^14.0.0 -> 15.0.0)
packages/mcp/package.json
MED
DEPCUR-NPM
npm package `open` is 1 major version(s) behind (^10.1.0 -> 11.0.0)
packages/cli/package.json
MED
DEPCUR-NPM
npm package `commander` is 2 major version(s) behind (^13.1.0 -> 15.0.0)
packages/cli/package.json
MED
GHSA-4w7w-66w2-5vf9
vite: GHSA-4w7w-66w2-5vf9
pnpm-lock.yaml
MED
GHSA-g9mf-h72j-4rw9
undici: GHSA-g9mf-h72j-4rw9
pnpm-lock.yaml
MED
GHSA-4992-7rv2-5pvq
undici: GHSA-4992-7rv2-5pvq
pnpm-lock.yaml
MED
GHSA-2mjp-6q6p-2qxm
undici: GHSA-2mjp-6q6p-2qxm
pnpm-lock.yaml
MED
GHSA-q8mj-m7cp-5q26
qs: GHSA-q8mj-m7cp-5q26
pnpm-lock.yaml
MED
GHSA-6rw7-vpxm-498p
qs: GHSA-6rw7-vpxm-498p
pnpm-lock.yaml
MED
GHSA-qx2v-qp2m-jg93
postcss: GHSA-qx2v-qp2m-jg93
pnpm-lock.yaml
MED
GHSA-3v7f-55p6-f55p
picomatch: GHSA-3v7f-55p6-f55p
pnpm-lock.yaml
MED
GHSA-27v5-c462-wpq7
path-to-regexp: GHSA-27v5-c462-wpq7
pnpm-lock.yaml
MED
GHSA-xrhx-7g5j-rcj5
hono: GHSA-xrhx-7g5j-rcj5
pnpm-lock.yaml
MED
GHSA-xpcf-pg52-r92g
hono: GHSA-xpcf-pg52-r92g
pnpm-lock.yaml
MED
GHSA-xf4j-xp2r-rqqx
hono: GHSA-xf4j-xp2r-rqqx
pnpm-lock.yaml
MED
GHSA-wmmm-f939-6g9c
hono: GHSA-wmmm-f939-6g9c
pnpm-lock.yaml
MED
GHSA-w332-q679-j88p
hono: GHSA-w332-q679-j88p
pnpm-lock.yaml
MED
GHSA-v8w9-8mx6-g223
hono: GHSA-v8w9-8mx6-g223
pnpm-lock.yaml
MED
GHSA-r5rp-j6wh-rvv4
hono: GHSA-r5rp-j6wh-rvv4
pnpm-lock.yaml
MED
GHSA-r354-f388-2fhh
hono: GHSA-r354-f388-2fhh
pnpm-lock.yaml
MED
GHSA-qp7p-654g-cw7p
hono: GHSA-qp7p-654g-cw7p
pnpm-lock.yaml
MED
GHSA-p77w-8qqv-26rm
hono: GHSA-p77w-8qqv-26rm
pnpm-lock.yaml
MED
GHSA-p6xx-57qc-3wxr
hono: GHSA-p6xx-57qc-3wxr
pnpm-lock.yaml
MED
GHSA-f577-qrjj-4474
hono: GHSA-f577-qrjj-4474
pnpm-lock.yaml
MED
GHSA-9vqf-7f2p-gf9v
hono: GHSA-9vqf-7f2p-gf9v
pnpm-lock.yaml
MED
GHSA-9r54-q6cx-xmh5
hono: GHSA-9r54-q6cx-xmh5
pnpm-lock.yaml
MED
GHSA-6wqw-2p9w-4vw4
hono: GHSA-6wqw-2p9w-4vw4
pnpm-lock.yaml
MED
GHSA-69xw-7hcm-h432
hono: GHSA-69xw-7hcm-h432
pnpm-lock.yaml
MED
GHSA-5pq2-9x2x-5p6w
hono: GHSA-5pq2-9x2x-5p6w
pnpm-lock.yaml
MED
GHSA-458j-xx4x-4375
hono: GHSA-458j-xx4x-4375
pnpm-lock.yaml
MED
GHSA-3hrh-pfw6-9m5x
hono: GHSA-3hrh-pfw6-9m5x
pnpm-lock.yaml
MED
GHSA-2gcr-mfcq-wcc3
hono: GHSA-2gcr-mfcq-wcc3
pnpm-lock.yaml
MED
GHSA-26pp-8wgv-hjvm
hono: GHSA-26pp-8wgv-hjvm
pnpm-lock.yaml
MED
GHSA-f886-m6hf-6m8v
brace-expansion: GHSA-f886-m6hf-6m8v
pnpm-lock.yaml
MED
GHSA-wqch-xfxh-vrr4
body-parser: GHSA-wqch-xfxh-vrr4
pnpm-lock.yaml
MED
GHSA-2g4f-4pwh-qvx6
ajv: GHSA-2g4f-4pwh-qvx6
pnpm-lock.yaml
MED
GHSA-92pp-h63x-v22m
@hono/node-server: GHSA-92pp-h63x-v22m
pnpm-lock.yaml
MED
DKR001
Docker final stage has no non-root USER
packages/mcp/Dockerfile:15
LOW
DEPCUR-GHA
GitHub Action `changesets/action@v1` is minor version(s) behind (latest v1.9.0)
.github/workflows/release.yml:43
LOW
DEPCUR-GHA
GitHub Action `aws-actions/amazon-ecr-login@v2` is minor version(s) behind (latest v2.1.5)
.github/workflows/ecr-deploy.yml:28
LOW
DEPCUR-NPM
npm package `@earendil-works/pi-coding-agent` is minor version(s) behind (^0.75.4 -> 0.78…
packages/pi/package.json
LOW
DEPCUR-NPM
npm package `jose` is minor version(s) behind (^6.1.3 -> 6.2.3)
packages/mcp/package.json
LOW
DEPCUR-NPM
npm package `express` is minor version(s) behind (^5.1.0 -> 5.2.1)
packages/mcp/package.json
LOW
DEPCUR-NPM
npm package `@modelcontextprotocol/sdk` is minor version(s) behind (^1.25.1 -> 1.29.0)
packages/mcp/package.json
LOW
DEPCUR-NPM
npm package `prettier` is minor version(s) behind (^3.6.2 -> 3.8.3)
packages/cli/package.json
LOW
DEPCUR-NPM
npm package `eslint-plugin-prettier` is minor version(s) behind (^5.2.5 -> 5.5.6)
packages/cli/package.json
LOW
DEPCUR-NPM
npm package `ora` is minor version(s) behind (^9.0.0 -> 9.4.0)
packages/cli/package.json
LOW
DEPCUR-NPM
npm package `figlet` is minor version(s) behind (^1.9.4 -> 1.11.0)
packages/cli/package.json
LOW
DEPCUR-NPM
npm package `@inquirer/prompts` is minor version(s) behind (^8.2.0 -> 8.5.2)
packages/cli/package.json
LOW
DEPCUR-NPM
npm package `@inquirer/core` is minor version(s) behind (^11.1.1 -> 11.2.1)
packages/cli/package.json
LOW
DEPCUR-NPM
npm package `dotenv` is minor version(s) behind (^17.2.3 -> 17.4.2)
packages/tools-ai-sdk/package.json
LOW
DEPCUR-NPM
npm package `dotenv` is minor version(s) behind (^17.2.3 -> 17.4.2)
packages/sdk/package.json
LOW
DEPCUR-NPM
npm package `prettier` is minor version(s) behind (^3.6.2 -> 3.8.3)
package.json
LOW
DEPCUR-NPM
npm package `eslint-plugin-prettier` is minor version(s) behind (^5.2.5 -> 5.5.6)
package.json
LOW
DEPCUR-NPM
npm package `@changesets/cli` is minor version(s) behind (^2.29.8 -> 2.31.0)
package.json
LOW
DEPCUR-NPM
npm package `@inquirer/core` is minor version(s) behind (^11.1.1 -> 11.2.1)
package.json
LOW
GHSA-w7fw-mjwx-w883
qs: GHSA-w7fw-mjwx-w883
pnpm-lock.yaml
LOW
GHSA-hm8q-7f3q-5f36
hono: GHSA-hm8q-7f3q-5f36
pnpm-lock.yaml
LOW
GHSA-gq3j-xvxp-8hrf
hono: GHSA-gq3j-xvxp-8hrf
pnpm-lock.yaml
LOW
AIC003
Duplicated implementation block across source files
packages/tools-ai-sdk/src/prompts/syste…:34
LOW
AIC003
Duplicated implementation block across source files
packages/tools-ai-sdk/src/prompts/syste…:31
LOW
AIC003
Duplicated implementation block across source files
packages/tools-ai-sdk/eslint.config.js:7
LOW
AIC003
Duplicated implementation block across source files
packages/tools-ai-sdk/eslint.config.js:4
LOW
AIC003
Duplicated implementation block across source files
packages/tools-ai-sdk/eslint.config.js:1
LOW
AIC003
Duplicated implementation block across source files
packages/sdk/eslint.config.js:7
LOW
AIC003
Duplicated implementation block across source files
packages/sdk/eslint.config.js:4
LOW
AIC003
Duplicated implementation block across source files
packages/sdk/eslint.config.js:1
LOW
AIC003
Duplicated implementation block across source files
packages/pi/lib/types.ts:1
LOW
AIC003
Duplicated implementation block across source files
packages/pi/lib/prompts.ts:3
LOW
AIC003
Duplicated implementation block across source files
packages/pi/lib/format.ts:2
LOW
AIC003
Duplicated implementation block across source files
packages/pi/eslint.config.js:7
LOW
AIC003
Duplicated implementation block across source files
packages/pi/eslint.config.js:1
LOW
AIC003
Duplicated implementation block across source files
packages/mcp/eslint.config.js:16
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
packages/cli/src/utils/github.ts:136
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
packages/cli/src/setup/mcp-writer.ts:21
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
packages/cli/src/commands/upgrade.ts:88
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
packages/cli/src/index.ts:68
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
packages/cli/src/commands/docs.ts:89
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
packages/cli/src/commands/auth.ts:119
INFO
DEPCUR-GHA
GitHub Action `actions/checkout@v6` is patch version(s) behind (latest v6.0.3)
.github/workflows/release.yml:19
INFO
DEPCUR-GHA
GitHub Action `actions/checkout@v6` is patch version(s) behind (latest v6.0.3)
.github/workflows/ecr-deploy.yml:17
INFO
DEPCUR-GHA
GitHub Action `actions/checkout@v6` is patch version(s) behind (latest v6.0.3)
.github/workflows/mcp-registry.yml:20
INFO
DEPCUR-GHA
GitHub Action `actions/checkout@v6` is patch version(s) behind (latest v6.0.3)
.github/workflows/canary-release.yml:19
INFO
DEPCUR-GHA
GitHub Action `actions/checkout@v6` is patch version(s) behind (latest v6.0.3)
.github/workflows/changeset-check.yml:13
INFO
DEPCUR-GHA
GitHub Action `actions/cache@v5` is patch version(s) behind (latest v5.0.5)
.github/workflows/test.yml:36
INFO
DEPCUR-GHA
GitHub Action `actions/checkout@v6` is patch version(s) behind (latest v6.0.3)
.github/workflows/test.yml:17
INFO
DEPCUR-NPM
npm package `@types/express` is patch version(s) behind (^5.0.4 -> 5.0.6)
packages/mcp/package.json
INFO
DEPCUR-NPM
npm package `tsup` is patch version(s) behind (^8.5.0 -> 8.5.1)
packages/cli/package.json
INFO
DEPCUR-NPM
npm package `@ai-sdk/amazon-bedrock` is patch version(s) behind (^4.0.9 -> 4.0.113)
packages/tools-ai-sdk/package.json
INFO
DEPCUR-NPM
npm package `eslint-config-prettier` is patch version(s) behind (^10.1.1 -> 10.1.8)
package.json
INFO
DEPCUR-NPM
npm package `@inquirer/type` is patch version(s) behind (^4.0.3 -> 4.0.7)
package.json