-
Dependency advisory GHSA-vxr8-fq34-vvx9:pkg:8a3c012a263ab8156620fb0e applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:32
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:128
-
zizmor reported template-injection · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:81
-
Dependency advisory GHSA-2v37-7h3g-55p8:pkg:a9b17cadf83e3a5de547592b applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-rp9w-3fw7-7cwq:pkg:4e16d185c39b16c1f350ca4f applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-xwg4-73v4-xw9w:pkg:b0abe8c9840bfaafb5747f78 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-qx2v-qp2m-jg93:pkg:d0433ccd51b55fc561da06bf applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-76mc-f452-cxcm:pkg:d0a18325b0cdabed3f35b2c7 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-hgv7-v322-mmgr:pkg:857cc203fb4acdf79b8e7afa applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-r47g-fvhr-h676:pkg:642ceee0c4b2cbc4a2e1b121 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-29g2-3rmr-qm68:pkg:0d943943a3e65d55c4ec32e3 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
zizmor reported template-injection · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:86
-
Dependency advisory GHSA-c2j3-45gr-mqc4:pkg:42053cd722737fc33c013501 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:45-49
-
Dependency advisory GHSA-cmwh-pvxp-8882:pkg:6965d223b6bd576889c01d10 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:50
-
Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:006e2a19c763cc0fc17b9679 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-9rmh-mm8f-r9h6:pkg:5d32cd47aeaee1205cf18fc6 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:109
-
Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:80dc2988b9d15a40674cea67 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:28
-
Dependency advisory GHSA-wqjv-9729-c5q2:pkg:6699abfbebd5d07abddaa45e applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-6g55-p6wh-862q:pkg:be20184562ed7ac60b9bb3c5 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-866w-xmhq-wj7x:pkg:d613be3ade05d602f01bb313 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-55q2-fjhq-7xh7:pkg:8332ecd5207902f58f4decb3 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-hpcv-96wg-7vj8:pkg:bc90a6f657d85810cfd9cd0b applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:45
-
Dependency advisory GHSA-fx2h-pf6j-xcff:pkg:7eb19f2c295342271bbc2245 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-r28c-9q8g-f849:pkg:309438d8c981844c76003c01 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-v6wh-96g9-6wx3:pkg:b37ba44174078c9afc2349cb applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-77vg-94rm-hx3p:pkg:91c6e2ad95c2c69b9ed18581 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-rcqx-6q8c-2c42:pkg:6c059b35236f63805cd31009 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-f3cj-j4f6-wq85:pkg:e3a54c277ee81743d557b6f7 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:92
-
Dependency advisory GHSA-pr6f-5x2q-rwfp:pkg:1d431e95b842ca17fabc7022 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
Dependency advisory GHSA-x4vx-rjvf-j5p4:pkg:f9e26ced39b613e63f6a02d9 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:28-31
-
Dependency advisory GHSA-gvmj-g25r-r7wr:pkg:2163f78fab2fec7de8db16b4 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
zizmor reported cache-poisoning · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:50