Skip to content
goard
Go to anything
Open any GitHub user, repo or page
GitHub rate limit reached. Fresh data resumes in about 1 min. Sign in for a higher limit.

web development for the rest of us

JavaScript MIT 118.8 MB Created Nov 20, 2016
Stars 87.6K Forks 5K Watchers 917 Open issues 951 Open PRs 140
Grade B Checks passed 10/11 Open alerts 0 Critical 0 High 0 Advisories 13
Security checks
  • Dependabot updates warn
    No update config
  • Dependabot alerts n/a
    Needs admin access to check
  • Secret scanning n/a
    Needs admin access to check
  • Code scanning n/a
    Needs security access to check
  • License pass
    MIT license
  • Security policy pass
    SECURITY.md published
  • Private vulnerability reporting pass
    Private reporting enabled
  • Branch protection pass
    Default branch protected
  • Signed commits pass
    30/30 recent commits signed
  • CI workflows pass
    GitHub Actions configured
  • Maintained pass
    Pushed today
  • Code of conduct pass
    Other
  • Contributing guide pass
    CONTRIBUTING guide published
  • Issue templates pass
    Issue templates configured
10/11 checks passed Grade B
Published advisories
  • moderate

    SSR XSS via Insecure Promise Serialization in hydratable

    May 14, 2026

    GHSA-f3cj-j4f6-wq85
  • moderate

    ReDoS in `<svelte:element>` Tag Validation

    May 14, 2026

    CVE-2026-42567
  • moderate

    XSS via DOM Clobbering of Internal Framework State

    May 14, 2026

    CVE-2026-42573
  • moderate

    Cross-site scripting via spread attributes in Svelte SSR

    May 14, 2026

    CVE-2026-42599
  • moderate

    XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`

    Feb 25, 2026

    CVE-2026-27901
  • moderate

    XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers

    Feb 25, 2026

    CVE-2026-27902
  • moderate

    XSS in SSR `<option>` element

    Feb 18, 2026

    CVE-2026-27119
  • moderate

    Cross-site scripting via spread attributes in Svelte SSR

    Feb 18, 2026

    CVE-2026-27121
  • moderate

    Svelte SSR does not validate dynamic element tag names in `<svelte:element>`

    Feb 18, 2026

    CVE-2026-27122
  • moderate

    Svelte SSR attribute spreading includes inherited properties from prototype chain

    Feb 18, 2026

    CVE-2026-27125
  • high

    XSS with textarea bind:value

    Jan 16, 2026

    GHSA-gw32-9rmw-qwww
  • moderate

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in svelte

    Jan 15, 2026

    CVE-2025-15265
  • moderate

    Potential XSS vulnerability due to improper HTML attribute escaping

    Aug 30, 2024

    CVE-2024-45047