Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 1 committed production secret and 10 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 1 password or key found in code that ships to production and 10 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
1 committed secret and 10 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
485 of 22635 files scanned (2%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Read 485 of 500 selected files — this repository's archive was too large to finish in one scan.
Two scanners read 485 of 22635 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 1 committed credential on production paths and 10 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
1.5.1-0.20260427112133-525d1bab07e0 — GHSA-ffqx-q65f-36jf, GHSA-p4r4-xvrq-gvmc
Grafana Tempo has Inadequate Encryption Strength — HIGH
Grafana Tempo has an Uncontrolled Resource Consumption issue — HIGH
5.1.5 — GHSA-v56q-mh7h-f735, GHSA-xvcm-6775-5m9r
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS — HIGH
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set — HIGH
4.1.0 — GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj
js-yaml: YAML merge-key chains can force quadratic CPU consumption — HIGH
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — HIGH
4.17.21 — GHSA-r5fr-rjxr-66jc
lodash vulnerable to Code Injection via `_.template` imports key names — HIGH
4.17.23 — GHSA-r5fr-rjxr-66jc
lodash vulnerable to Code Injection via `_.template` imports key names — HIGH
5.0.9 — GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8
nanoid: non-secure generators can loop indefinitely with negative size — HIGH
nanoid: custom generators can loop indefinitely when size is zero — HIGH
3.4.0 — GHSA-55q2-fjhq-7xh7, GHSA-76mc-f452-cxcm, GHSA-c2j3-45gr-mqc4
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS — MODERATE
DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR` — MODERATE
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. — LOW
4.17.21 — GHSA-f23m-r3pf-42rh, GHSA-xxjr-mmjv-4gpg
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` — MODERATE
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions — MODERATE
4.17.23 — GHSA-f23m-r3pf-42rh
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` — MODERATE
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 485 of 22635 files (highest-priority subset) · grafana/grafana
Dependency manifests: 28 package roots found, 25 scanned; 1 Python manifest read; 86 Go manifests read — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)