Dependency Visibility
Every package in every repo, riskiest first.
| Package | Severity | CVE/GHSA ID | Installed Version | Fixed Version | Ecosystem | Exploit Risk |
|---|---|---|---|---|---|---|
| org.apache.logging.log4j:log4j-core | Critical | CVE-2021-44228 | 2.14.1 | 2.15.0 | Maven | 100% |
| golang.org/x/net | Medium | CVE-2023-45288 | v0.17.0 | v0.23.0 | Go | 92% |
| lodash | High | CVE-2021-23337 | 4.17.20 | 4.17.21 | npm | 21% |
| requests | Medium | CVE-2024-47081 | 2.31.0 | 2.32.4 | PyPI | 1% |
| Package Name | Malware ID | Ecosystem | Installed Version | Fixed Version | Affected Repos | Published |
|---|---|---|---|---|---|---|
| react-nodejs | MAL-2026-17294 | npm | 19.3.0 | No fix | 2 | 29-09-2026 |
| spo365-graph | MAL-2026-17421 | PyPI | 1.1.0 | No fix | 1 | 01-10-2026 |
| github.com/BufferZoneCorp/log-core | MAL-2026-3628 | Go | v0.1.0 | No fix | 1 | 13-05-2026 |
| Package | Ecosystem | Installed Version | License |
|---|---|---|---|
| example-pdf-render | Maven | 4.2.0 | GPL-3.0 |
| actions/checkout | GitHub Actions | v4 | MIT |
| lodash | npm | 4.17.20 | MIT |
| requests | PyPI | 2.31.0 | Apache-2.0 |
| Component | Category | Provider | Ecosystem | Installed Version | Severity | Exploit Risk |
|---|---|---|---|---|---|---|
| example-llm-gateway | Framework | Example AI | PyPI | 2.1.0 | High | 64% |
| demo-agent-core | Framework | Demo Labs | PyPI | 0.3.7 | Critical | 43% |
| sample-mcp-server | Framework | MCP | npm | 1.4.2 | Medium | 12% |
| demo-embeddings | Library | Demo Labs | PyPI | 5.2.0 | Low | 3% |
