Skip to content
Tools / ebook2audiobook / Security

Security Deep Dive

ebook2audiobook

Security posture and CVE patch evidence from tracked releases.

Back to Tool

7 critical dependency CVEs affects v26.5.20.

Audit transitive dependencies; consider upgrading or pinning replacements.

— Signed — SLSA — SBOM ✗ Security policy Weekly cadence · 2d median Active maintainer

Trust Signals — 2 of 9 Present

Evidence already collected from releases and repository metadata.

2/9 Present
Signed releases Unknown
Latest release artifact signature Latest release
SLSA provenance Unknown
Attestation predicate level Latest release
SBOM published Unknown
GitHub SBOM API Latest release
SECURITY.md Absent
GitHub repository metadata Repository policy
Checked: 23d ago
Release cadence: weekly Present
2d median over recent releases Release history
Latest release: 13d ago
Maintainer active Present
Recent commit activity Repository
Last commit: 5d ago
Checksums (SHA256SUMS) Not active yet
SHA256SUMS or equivalent Release asset
Latest release: 13d ago
GitHub Actions attestation Not active yet
actions/attest-build-provenance Workflow file
Latest release: 13d ago
Signing assets Not active yet
.sig, .crt, cosign.pub, or similar Release asset
Latest release: 13d ago
3.8/10 Security Score
Dependency Exposure 59 transitive dependency CVEs found in the latest SBOM. 7 critical.

Security Score

A composite score aggregating Scorecard performance, CVE patch history, OpenSSF badge tier, and dependency vulnerability exposure. Score ≥ 7.0 is healthy; < 4.0 warrants attention.

epss

0.25 / 0.5

No EPSS data

freshness

1.00 / 1.0

5d stale

scorecard

2.00 / 4.0

⚠ Estimated — not yet collected

cve health

0.00 / 2.5

⚠ No direct scan — 7c/21h transitive CVEs

patch speed

0.50 / 0.5

⚠ Estimated — no CVE patch history

kev exposure

1.50 / 1.5

No KEV exposure

supply chain risk

-1.50 / 10.0

Risk 70.8/100

Score breakdown

schema v2

Vulnerability posture

vulnerability posture

0.0

25%

direct cves: clear cve scan: estimated

Release responsiveness

release responsiveness

10.0

5%

patch speed days: no_history

Dependency exposure

dependency exposure

2.9

10%

supply chain risk: 70.85 transitive cves: 7c/21h

Provenance trust

provenance trust

5.0

40%

scorecard score: estimated openssf badge: none

Maintainer health

maintainer health

10.0

10%

activity freshness: 5d

Operational risk

operational risk

8.5

10%

kev exposure: clear epss max: none
How is this calculated?

The six dimensions group the legacy score signals into weighted categories: direct vulnerability status, patch responsiveness, dependency exposure, provenance checks, maintainer activity, and exploitability risk. The flat component values above remain available for compatibility.

Supply Chain Risk

Risk 70.8/100
7 Transitive critical CVEs
0 KEV-transitive CVEs
57% Dependency freshness

OpenSSF Badge

OpenSSF none

Badge indicates adherence to open-source best practices.

Dependency Vulnerabilities

110 dependencies scanned View full dependency list →

Scanning the SBOM (Software Bill of Materials) of the latest release for known vulnerabilities in transitive dependencies.

Critical

7

High

21

Medium

20

Low

9

Unknown

2

Critical 7 High 21 Medium 20 Low 9 Unknown 2
CVE Severity KEV Dependency Affected version Cleared in release
CVE-2017-18342 critical pyyaml v26.5.8
CVE-2019-20477 critical pyyaml v26.5.8
CVE-2020-14343 critical pyyaml v26.5.8
CVE-2020-1747 critical pyyaml v26.5.8
CVE-2022-45907 critical torch v26.5.8
CVE-2024-48063 critical torch v26.5.8
CVE-2025-32434 critical torch v26.5.8
CVE-2016-10075 high tqdm v26.5.8
CVE-2016-5851 high python-docx v26.5.8
CVE-2016-9243 high cryptography v26.5.8
CVE-2018-10903 high cryptography v26.5.8
CVE-2020-25659 high cryptography v26.5.8
CVE-2020-36242 high cryptography v26.5.8
CVE-2021-32677 high fastapi v26.5.8
CVE-2023-0286 high cryptography v26.5.8
CVE-2023-38325 high cryptography v26.5.8
CVE-2023-50782 high cryptography v26.5.8
CVE-2024-11392 high transformers 4.44.2 v26.5.8
CVE-2024-11393 high transformers 4.44.2 v26.5.8
CVE-2024-11394 high transformers 4.44.2 v26.5.8
CVE-2024-24762 high fastapi v26.5.8
CVE-2024-26130 high cryptography v26.5.8
CVE-2024-31580 high torch v26.5.8
CVE-2024-31583 high torch v26.5.8
CVE-2026-1260 high sentencepiece 0.2.0 v26.5.8
CVE-2026-26007 high cryptography v26.5.8
CVE-2026-28414 high gradio 5.49.1 v26.5.8
CVE-2026-28416 high gradio 5.49.1 v26.5.8
CVE-2023-23931 medium cryptography v26.5.8
CVE-2023-49083 medium cryptography v26.5.8
CVE-2024-0727 medium cryptography v26.5.8
CVE-2024-12720 medium transformers 4.44.2 v26.5.8
CVE-2025-1194 medium transformers 4.44.2 v26.5.8
CVE-2025-2099 medium transformers 4.44.2 v26.5.8
CVE-2025-3263 medium transformers 4.44.2 v26.5.8
CVE-2025-3264 medium transformers 4.44.2 v26.5.8
CVE-2025-3730 medium torch v26.5.8
CVE-2025-3933 medium transformers 4.44.2 v26.5.8
CVE-2025-5197 medium transformers 4.44.2 v26.5.8
CVE-2025-6051 medium transformers 4.44.2 v26.5.8
CVE-2025-6638 medium transformers 4.44.2 v26.5.8
CVE-2025-6921 medium transformers 4.44.2 v26.5.8
CVE-2026-1839 medium transformers 4.57.6 v26.5.8
CVE-2026-28415 medium gradio 5.49.1 v26.5.8
CVE-2026-3029 medium pymupdf v26.5.8
CVE-2026-39892 medium cryptography v26.5.8
GHSA-39hc-v87j-747x medium cryptography v26.5.8
GHSA-h4gh-qq45-vh27 medium cryptography v26.5.8
CVE-2024-12797 low cryptography v26.5.8
CVE-2024-34062 low tqdm v26.5.8
CVE-2025-2953 low torch v26.5.8
CVE-2025-3777 low transformers 4.44.2 v26.5.8
CVE-2026-27167 low gradio 5.49.1 v26.5.8
CVE-2026-34073 low cryptography v26.5.8
GHSA-5cpq-8wj7-hf2v low cryptography v26.5.8
GHSA-jm77-qphf-c4w8 low cryptography v26.5.8
GHSA-v8gr-m533-ghj9 low cryptography v26.5.8
CVE-2020-13091 unknown pandas v26.5.8
CVE-2024-31584 unknown torch v26.5.8

Showing 59 of 59

Beta — feedback welcome: [email protected]