See https://api.securityscorecards.dev/projects/github.com/nebraska-dev/cronk
{
"name":"Vulnerabilities",
"score":-1,
"reason":"internal error: vulnerabilitiesClient.ListUnfixedVulnerabilities: osvscanner.DoScan: vulnerabilities found",
"details":null,
"documentation": {
"short":"Determines if the project has open, known unfixed vulnerabilities.",
"url": "https://github.com/ossf/scorecard/blob/376f465c111c39c6a5ad7408e8896cd790cb5219/docs/checks.md#vulnerabilities"
}
The project has two vulnerable dependencies (requirements.txt).
Running on the CLI works:
$ scorecard --repo=nebraska-dev/cronk
# ...
| 8 / 10 | Vulnerabilities | 2 existing vulnerabilities | https://github.com/ossf/scorecard/blob/main/docs/checks.md#vulnerabilities |
| | | detected | |