raven
Install command:
brew install ravenRisk Analysis and Vulnerability Enumeration for CI/CD
https://github.com/CycodeLabs/raven
License: Apache-2.0
Development: Pull requests
Formula JSON API: /api/formula/raven.json
Formula code: raven.rb on GitHub
Bottle (binary package) installation support provided for:
| macOS on Apple Silicon |
tahoe | ✅ |
|---|---|---|
| sequoia | ✅ | |
| sonoma | ✅ | |
| macOS on Intel |
sonoma | ✅ |
| Linux | ARM64 | ✅ |
| x86_64 | ✅ | |
Current versions:
| stable | ✅ | 1.0.9 |
Depends on:
| certifi | 2026.7.22 | Mozilla CA bundle for Python |
| libyaml | 0.2.5 | YAML Parser |
| python@3.14 | 3.14.7 | Interpreted, interactive, object-oriented programming language |
Known vulnerabilities in the current version:
| GHSA-g7vv-2v7x-gj9p (low) | tqdm CLI arguments injection attack |
| GHSA-9wx4-h78v-vm56 (medium) | Requests `Session` object does not verify requests after making first request with verify=False |
| GHSA-34jh-p97f-mpxf (medium) | urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects |
| GHSA-9hjg-9r4m-mvj7 (medium) | Requests vulnerable to .netrc credentials leak via malicious URLs |
| GHSA-pq67-6m6q-mj2v (medium) | urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation |
| GHSA-48p4-8xcf-vxj5 (medium) | urllib3 does not control redirects in browsers and Node.js |
| GHSA-gm62-xv2j-4w53 | urllib3 allows an unbounded number of links in the decompression chain |
| GHSA-2xpw-w6gg-jr37 | urllib3 streaming API improperly handles highly compressed data |
| GHSA-6w46-j5rx-g56g (medium) | pytest has vulnerable tmpdir handling |
| GHSA-38jv-5279-wg99 (high) | Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) |
| GHSA-gc5v-m9x4-r6x2 (medium) | Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function |
| GHSA-qccp-gfcp-xxvc (medium) | urllib3: Sensitive headers forwarded across origins in proxied low-level redirects |
| GHSA-5239-wwwm-4pmq (low) | Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching |
| GHSA-65pc-fj4g-8rjx (medium) | Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() ... |
Data from Homebrew/advisory-database. Run brew vulns raven for a live check.
Analytics:
| 30 days | 90 days | 365 days | |
|---|---|---|---|
| Installs | 18 | 44 | 162 |
| Installs on Request | 18 | 44 | 162 |
| Build Errors | 0 |