Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-15
5 active CVEs reported via OSV.dev
dbt-core's secret env vars written to package-lock.json in plaintext
dbt has an implicit override for built-in materializations from installed packages
dbt uses a SQLparse version with a high vulnerability
dbt allows Binding to an Unrestricted IP Address via socketsocket
Other Data Science projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for dbt Core โ without relying on volunteer maintainers.
Talk to an Expert โ