ogham/exa · Security & risks
Authoritative risk signals for ogham/exa — dependency CVEs (deps.dev), OpenSSF Scorecard, and GitHub Code Scanning. Not a substitute for your own security review.
Dependency CVEs (deps.dev)
0
Critical
0 direct
2
High
0 direct
31
Moderate
45
Deps scanned
14 direct
- GHSA-jcr6-4frq-9gjj · usersUsers vulnerable to unaligned read of `*const *const c_char` pointerMODERATE
- RUSTSEC-2021-0139 · ansi_term (direct)ansi_term is UnmaintainedMODERATE
- GHSA-3wx7-46ch-7rq2 · openssl-srcAES OCB fails to encrypt some bytesMODERATE
- RUSTSEC-2025-0119 · number_prefix (direct)number_prefix crate is unmaintainedMODERATE
- GHSA-22q8-ghmq-63vf · libgit2-syslibgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2MODERATE
- GHSA-5ww6-px42-wc85 · openssl-srcSM2 Decryption Buffer OverflowMODERATE
- GHSA-m65q-v92h-cm7q · usersusers may append `root` to group listingsMODERATE
- GHSA-m4ch-rfv5-x5g3 · libgit2-sysgit2-rs fails to verify SSH keys by defaultMODERATE
- GHSA-83mx-573x-5rw9 · openssl-srcopenssl-src NULL pointer Dereference in signature_algorithms processingMODERATE
- RUSTSEC-2023-0040 · users`users` crate is unmaintainedMODERATE
OpenSSF Scorecard · 3.1/10
- Packaging—
- Maintained0/10
- Token-Permissions0/10
- Pinned-Dependencies0/10
- CII-Best-Practices0/10
- Security-Policy0/10
- Fuzzing0/10
- Signed-Releases0/10
GitHub Code Scanning · 0 open / 0 total
Tools: —
Ask AI about ogham/exa
Grounded in the actual source code. Pick a starter question or write your own.
What does this repo do, in one paragraph?How would I get started using it?What are the main alternatives?Show me the entry point.
Or write your own questionInformational only. RepoPilot summarises public signals at the time of analysis; they can be incomplete or stale. Not professional, security, or legal advice.