# Trivy filesystem scan

Generated: 2026-09-19T06:06:32Z
Commit: f404f34b623be86434dcfa029e594f4d1943a8b4

2026-09-19T08:07:01+02:00	INFO	[vuln] Vulnerability scanning is enabled
2026-09-19T08:07:06+02:00	INFO	[pnpm] Run "pnpm install" to collect the license information of packages	dir="forms/node_modules"
2026-09-19T08:07:06+02:00	INFO	[pnpm] Run "pnpm install" to collect the license information of packages	dir="site/node_modules"
2026-09-19T08:07:06+02:00	INFO	[npm] Run "npm install" to collect the license information of packages	dir="integrations/zapier/node_modules"
2026-09-19T08:07:06+02:00	INFO	Suppressing dependencies for development and testing. To display them, try the '--include-dev-deps' flag.
2026-09-19T08:07:06+02:00	INFO	Number of language-specific files	num=9
2026-09-19T08:07:06+02:00	INFO	[cargo] Detecting vulnerabilities...
2026-09-19T08:07:06+02:00	INFO	[gomod] Detecting vulnerabilities...
2026-09-19T08:07:06+02:00	INFO	[hex] Detecting vulnerabilities...
2026-09-19T08:07:06+02:00	INFO	[npm] Detecting vulnerabilities...
2026-09-19T08:07:06+02:00	INFO	[pnpm] Detecting vulnerabilities...
2026-09-19T08:07:06+02:00	WARN	Using severities from other vendors for some vulnerabilities. Read https://trivy.dev/docs/v0.72/guide/scanner/vulnerability#severity-selection for details.

Report Summary

┌───────────────────────────────────────┬───────┬─────────────────┐
│                Target                 │ Type  │ Vulnerabilities │
├───────────────────────────────────────┼───────┼─────────────────┤
│ admin/pnpm-lock.yaml                  │ pnpm  │        0        │
├───────────────────────────────────────┼───────┼─────────────────┤
│ docs/pnpm-lock.yaml                   │ pnpm  │        0        │
├───────────────────────────────────────┼───────┼─────────────────┤
│ forms/pnpm-lock.yaml                  │ pnpm  │        0        │
├───────────────────────────────────────┼───────┼─────────────────┤
│ go.mod                                │ gomod │        1        │
├───────────────────────────────────────┼───────┼─────────────────┤
│ integrations/zapier/package-lock.json │  npm  │        0        │
├───────────────────────────────────────┼───────┼─────────────────┤
│ realtime/mix.lock                     │  hex  │        0        │
├───────────────────────────────────────┼───────┼─────────────────┤
│ site/pnpm-lock.yaml                   │ pnpm  │        0        │
├───────────────────────────────────────┼───────┼─────────────────┤
│ tracking/Cargo.lock                   │ cargo │        2        │
├───────────────────────────────────────┼───────┼─────────────────┤
│ web/pnpm-lock.yaml                    │ pnpm  │        0        │
└───────────────────────────────────────┴───────┴─────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


go.mod (gomod)
==============
Total: 1 (HIGH: 1, CRITICAL: 0)

┌─────────────────────────────┬────────────────┬──────────┬──────────┬─────────────────────┬───────────────┬─────────────────────────────────────────────────┐
│           Library           │ Vulnerability  │ Severity │  Status  │  Installed Version  │ Fixed Version │                      Title                      │
├─────────────────────────────┼────────────────┼──────────┼──────────┼─────────────────────┼───────────────┼─────────────────────────────────────────────────┤
│ github.com/dgrijalva/jwt-go │ CVE-2020-26160 │ HIGH     │ affected │ v3.2.0+incompatible │               │ jwt-go: access restriction bypass vulnerability │
│                             │                │          │          │                     │               │ https://avd.aquasec.com/nvd/cve-2020-26160      │
└─────────────────────────────┴────────────────┴──────────┴──────────┴─────────────────────┴───────────────┴─────────────────────────────────────────────────┘

tracking/Cargo.lock (cargo)
===========================
Total: 2 (HIGH: 2, CRITICAL: 0)

┌───────────────┬─────────────────────┬──────────┬────────┬───────────────────┬───────────────────────────┬─────────────────────────────────────────────────────────────┐
│    Library    │    Vulnerability    │ Severity │ Status │ Installed Version │       Fixed Version       │                            Title                            │
├───────────────┼─────────────────────┼──────────┼────────┼───────────────────┼───────────────────────────┼─────────────────────────────────────────────────────────────┤
│ rustls-webpki │ GHSA-82j2-j2ch-gfr8 │ HIGH     │ fixed  │ 0.101.7           │ 0.103.13, 0.104.0-alpha.7 │ rustls-webpki: Denial of service via panic on malformed CRL │
│               │                     │          │        │                   │                           │ BIT STRING                                                  │
│               │                     │          │        │                   │                           │ https://github.com/advisories/GHSA-82j2-j2ch-gfr8           │
│               │                     │          │        ├───────────────────┤                           │                                                             │
│               │                     │          │        │ 0.102.8           │                           │                                                             │
│               │                     │          │        │                   │                           │                                                             │
│               │                     │          │        │                   │                           │                                                             │
└───────────────┴─────────────────────┴──────────┴────────┴───────────────────┴───────────────────────────┴─────────────────────────────────────────────────────────────┘

📣 [34mNotices:[0m
  - Version 0.74.0 of Trivy is now available, current version is 0.72.0

To suppress version checks, run Trivy scans with the --skip-version-check flag

