← Scan another repo

github.com/shadowsocks/ShadowsocksX-NG

@ 719203afc60e

Submitted 8/4/2026, 10:28:02 AM · Status: ok

Risk grade
C
30 / 100
Findings
5
0 critical2 high3 medium0 low0 info0 on CISA KEV0ATT&CK
Showing 5 of 5 findings

Findings

  • Detected square-access-token: Detected a Square Access Token, risking unauthorized payment processing and financial transaction exposure
    Detected a Square Access Token, risking unauthorized payment processing and financial transaction exposure.
    gitleaks
  • Detected square-access-token: Detected a Square Access Token, risking unauthorized payment processing and financial transaction exposure
    Detected a Square Access Token, risking unauthorized payment processing and financial transaction exposure.
    gitleaks
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Release Building)
    checkov.github/workflows/release.yml:0
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Feature Building)
    checkov.github/workflows/feature.yml:0
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepShadowsocksX-NG/zh-Hans.lproj/PreferencesWindowController.strings:23

This report is public.