tariqbuilds/linux-dash · Security & risks
Authoritative risk signals for tariqbuilds/linux-dash — dependency CVEs (deps.dev), OpenSSF Scorecard, and GitHub Code Scanning. Not a substitute for your own security review.
Dependency CVEs (deps.dev)
0
Critical
0 direct
0
High
0 direct
10
Moderate
15
Deps scanned
15 direct
- GHSA-2qqx-w9hr-q5gx · angular (direct)angular vulnerable to regular expression denial of service via the $resource serviceMODERATE
- GHSA-2vrf-hf26-jrp5 · angular (direct)angular vulnerable to regular expression denial of service via the angular.copy() utilityMODERATE
- GHSA-4w4v-5hc9-xrr2 · angular (direct)angular vulnerable to super-linear runtime due to backtrackingMODERATE
- GHSA-7x27-g8rg-x87w · angular (direct)Angular's deprecated package has a Cross-Site Scripting issueMODERATE
- GHSA-j58c-ww9w-pwp5 · angular (direct)AngularJS improperly sanitizes SVG elementsMODERATE
- GHSA-m2h2-264f-f486 · angular (direct)angular vulnerable to regular expression denial of service (ReDoS)MODERATE
- GHSA-m9gf-397r-hwpg · angular (direct)AngularJS allows attackers to bypass common image source restrictionsMODERATE
- GHSA-mqm9-c95h-x2p6 · angular (direct)AngularJS allows attackers to bypass common image source restrictionsMODERATE
- GHSA-prc3-vjfx-vhm9 · angular (direct)Angular (deprecated package) Cross-site ScriptingMODERATE
- GHSA-qwqh-hm9m-p5hr · angular (direct)angular vulnerable to regular expression denial of service via the <input type="url"> elementMODERATE
OpenSSF Scorecard · 1.7/10
- Token-Permissions—
- Pinned-Dependencies—
- Branch-Protection—
- Maintained0/10
- CI-Tests0/10
- Dependency-Update-Tool0/10
- Security-Policy0/10
- SAST0/10
Ask AI about tariqbuilds/linux-dash
Grounded in the actual source code. Pick a starter question or write your own.
What does this repo do, in one paragraph?How would I get started using it?What are the main alternatives?Show me the entry point.
Or write your own questionInformational only. RepoPilot summarises public signals at the time of analysis; they can be incomplete or stale. Not professional, security, or legal advice.