RepoPilot

yugabyte/yugabyte-db · Security & risks

Authoritative risk signals for yugabyte/yugabyte-db — dependency CVEs (deps.dev), OpenSSF Scorecard, and GitHub Code Scanning. Not a substitute for your own security review.

Dependency CVEs (deps.dev)

0
Critical
0 direct
0
High
0 direct
6
Moderate
55
Deps scanned
5 direct
  • GHSA-j88v-2chj-qfwx · github.com/jackc/pgx/v4 (direct)pgx: SQL Injection via placeholder confusion with dollar quoted string literalsMODERATE
  • GHSA-jqcq-xjh3-6g23 · github.com/jackc/pgproto3/v2Denial of service in github.com/jackc/pgproto3/v2MODERATE
  • GHSA-7jwh-3vrq-q3m8 · github.com/jackc/pgproto3 (direct)pgproto3 SQL Injection via Protocol Message Size OverflowMODERATE
  • GO-2026-4518 · github.com/jackc/pgproto3/v2Denial of service in github.com/jackc/pgproto3/v2MODERATE
  • GO-2026-5004 · github.com/jackc/pgx/v4 (direct)SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgxMODERATE
  • GO-2026-5932 · golang.org/x/cryptoThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issuesMODERATE

OpenSSF Scorecard · 5.3/10

  • Packaging
  • Signed-Releases
  • CII-Best-Practices0/10
  • Token-Permissions0/10
  • Security-Policy0/10
  • SAST0/10
  • Pinned-Dependencies0/10
  • Branch-Protection4/10

Ask AI about yugabyte/yugabyte-db

Grounded in the actual source code. Pick a starter question or write your own.

Or write your own question

Informational only. RepoPilot summarises public signals at the time of analysis; they can be incomplete or stale. Not professional, security, or legal advice.