Home/any-auto-register/Trust report

Trust and health report

any-auto-register - trust report

Sourced, dated trust signals - maintenance label posture, repository provenance, and security scan status. Not a composite safety grade.

GraphCanon updated Aug 11, 2026 · GitHub synced Aug 11, 2026

29views this month

Maintenance

Recency and activity heuristics from public GitHub metadata (maintenance label, momentum); methodology: github_public_v1.

Steady60% signal

last push 35d ago · last release May 6, 2026

Provenance

Repository identity and fork provenance (github_public_v1).

  • GitHub repo id: 1185330299
  • Not a fork
  • Personal account
  • Computed Aug 11, 2026

Security intelligence

Source-by-source security scan results from public intelligence providers. Missing, partial, or failed queries are shown explicitly and are not treated as clean.

OSV dependency advisories

No lockfile (source not queried)
Last query
Jul 15, 2026
Scanner
osv@v1
View source evidence

deps.dev advisories

Published findings
Last query
Sep 6, 2026
Scanner
deps.dev@v1
Stored findings
14
View source evidence

OpenSSF Scorecard

No public record from this source
Last query
Aug 23, 2026
Scanner
openssf-scorecard@v1

Weekly public scans omit some checks at scale.

View source evidence

Dependency advisories (deduplicated)

curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)
curl_cffi@0.6.0 · CVE-2026-33752 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-qw2m-4pqf-rmpp
cbor2 has a Denial of Service via Uncontrolled Recursion in cbor2.loads
cbor2@5.4.0 · CVE-2026-26209 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-3c37-wwvx-h642
cbor2 C extension decoder flaws can cause denial of service
cbor2@5.4.0 · CVE-2025-64076 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-9q9c-vjxh-p795
Werkzeug possible resource exhaustion when parsing file data in forms
quart@0.19.0 · CVE-2024-49767 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-q34m-jh98-gwm2
Requests vulnerable to .netrc credentials leak via malicious URLs
requests@2.31.0 · CVE-2024-47081 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-9hjg-9r4m-mvj7
Requests `Session` object does not verify requests after making first request with verify=False
requests@2.31.0 · CVE-2024-35195 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-9wx4-h78v-vm56
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
requests@2.31.0 · CVE-2026-25645 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-gc5v-m9x4-r6x2
Pydantic regular expression denial of service
pydantic@2.0.0 · CVE-2024-3772 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-mr82-8j83-vxmv
DoS with algorithms that use PBKDF2 due to unbounded PBES2 Count value
jwcrypto@1.5.0 · CVE-2023-6681 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-cw2r-4p82-qv79
JWCrypto: JWE ZIP decompression bomb
jwcrypto@1.5.0 · CVE-2026-39373 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-fjrm-76x2-c4q4
JWCrypto vulnerable to JWT bomb Attack in `deserialize` function
jwcrypto@1.5.0 · CVE-2024-28102 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-j857-7rvv-vj97
pytest has vulnerable tmpdir handling
pytest@8.0.0 · CVE-2025-71176 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-6w46-j5rx-g56g
curl_cffi bundles a version of libcurl affected by High Severity vulnerability
curl_cffi@0.6.0 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-3vpc-4p9p-47hc
CBORDecoder reuse can leak shareable values across decode calls
cbor2@5.4.0 · CVE-2025-68131 · deps.dev@v1
https://osv.dev/vulnerability/GHSA-wcj4-jw5j-44wh

Method and caveats: these are sourced, dated heuristics from public GitHub data and external security intelligence providers. A status like "no published findings from this source" is not a guarantee of safety. Read the full trust methodology · JSON report at /api/graphcanon/tools/lxf746-any-auto-register/trust.

Common questions

Is any-auto-register maintained?
GraphCanon rates any-auto-register "Steady" (60% maintenance signal from public GitHub metadata, computed Aug 11, 2026). Last push was 35 days ago. This is a recency heuristic, not a guarantee the project will stay maintained.
Is any-auto-register safe to use?
Last scanned Jul 15, 2026 (none profile). Status: No lockfile. Absence of findings in our scan is not a security guarantee - see trust methodology for scope limits. GraphCanon does not certify any-auto-register as safe - review maintenance, provenance, and scan findings on this page before adopting.
Is any-auto-register a fork?
No. any-auto-register is not flagged as a fork in GitHub metadata at the time of the last refresh.
Does any-auto-register have known security vulnerabilities?
Last scanned Jul 15, 2026 (none profile). Status: No lockfile. Absence of findings in our scan is not a security guarantee - see trust methodology for scope limits.
How often is the any-auto-register trust report updated?
Trust signals refresh on GitHub ingest/refresh cycles and optional dependency/MCP scans. This report was computed Aug 11, 2026 (methodology github_public_v1).
What does GraphCanon never claim about any-auto-register?
We never publish a composite safety grade, pen-test endorsement, or "verified secure" label for any-auto-register. Signals are sourced heuristics with explicit limits - see trust methodology.
How does GraphCanon assess trust for any-auto-register?
Signals are sourced from public GitHub metadata and optional dependency/MCP manifest scans, each tagged with methodology version and computed date. GraphCanon does not publish a composite safety grade. Read trust methodology for full scope and limits.

Was this helpful?

Anonymous feedback helps us improve pages and translations.