← Scan another repo

github.com/doocs/advanced-java

@ 1659850d7de4

Submitted 8/4/2026, 10:25:55 AM · Status: ok

Risk grade
C
32 / 100
Findings
6
0 critical2 high4 medium0 low0 info0 on CISA KEV0ATT&CK
Showing 6 of 6 findings

Findings

  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    grype
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    ## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…
    trivy
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Compress)
    checkov.github/workflows/compress.yml:0
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Build and deploy)
    checkov.github/workflows/deploy.yml:42
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Starcharts)
    checkov.github/workflows/starcharts.yml:0
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    ## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…
    osv-scanner

This report is public.