acme/payments-api
main·npm, go
How RedFlag works
Most teams assume their security scanners catch everything. They don't. RedFlag plants real CVEs in a safe test branch, runs your scanners against them, and scores exactly what got through. Then tells you how to fix it.
- Step 1Connect your repo
Link any GitHub repository using a Personal Access Token. RedFlag never touches your production code.
- Step 2We inject real CVEs
RedFlag plants 12+ known vulnerabilities (Log4Shell, Text4Shell, vm2 escape and more) into a temporary test branch that gets deleted after the scan.
- Step 3Get your score
Your Dependabot and GitHub Actions scanners run against the injected vulnerabilities. RedFlag scores how many they catch, weighted by severity. See exactly what was missed.
84
Detection score
Injected
10
Detected
8
Missed
2
Avg detection
00:05:11
Injection results
10 CVEs planted in test branch
| CVE | Package | Severity | Ecosystem | Detected | Time to alert |
|---|---|---|---|---|---|
| CVE-2023-45857 | axios@1.5.0 | high | npm | Detected | 00:04:12 |
| CVE-2024-21626 | runc@1.1.11 | critical | go | Detected | 00:02:48 |
| CVE-2023-26136 | tough-cookie@4.0.0 | medium | npm | Detected | 00:08:31 |
| CVE-2024-28849 | follow-redirects@1.15.4 | medium | npm | Missed | — |
| CVE-2023-50447 | Pillow@10.1.0 | high | pypi | Detected | 00:06:09 |
| CVE-2024-22195 | Jinja2@3.1.2 | medium | pypi | Detected | 00:11:54 |
| CVE-2023-44487 | golang.org/x/net | high | go | Missed | — |
| CVE-2024-27983 | node@20.11.0 | high | npm | Detected | 00:03:22 |
| CVE-2023-38545 | curl@8.3.0 | critical | system | Detected | 00:01:55 |
| CVE-2024-3094 | xz-utils@5.6.0 | critical | system | Missed | — |
Activity
Recent events for this repository
- 12:04:22Initialized scan session #4821
- 12:04:25Created branch redflag/inject-2024
- 12:04:31Injected 10 CVE payloads across 3 ecosystems
- 12:04:48Triggered GitHub Actions workflow
- 12:06:12Dependabot alert: CVE-2024-21626 detected
- 12:07:34Dependabot alert: CVE-2023-38545 detected
- 12:11:02Missed: CVE-2024-3094 (xz-utils backdoor)
- 12:14:48Scan complete — score 70/100