Data-driven insights from analyzing 128,000+ repositories and 3.27 billion lines of code. Vulnerability trends, code quality patterns, and actionable intelligence for engineering teams.
RSS FeedA point-in-time study of 51 GitHub Trending repositories found 10,363 security, supply-chain, quality, and architecture observations, with a new assurance label that …
3 min readLarge AI-coded repo scans reveal why scanner reliability depends on archive fallback, context-aware detection, and supply-chain-level scoring.
2 min readSimple gates around dependencies, CI, auth boundaries, and public discovery files catch practical risks before they become incidents.
1 min readAnalysis of 128 security findings across 16 repositories for April 2026.
Analysis of 115 security findings across 9 repositories for April 2026.
Analysis of 109 security findings across 4 repositories for April 2026.
We counted every shadcn/ui component import across 12K Opus 4.7 repos. Four components dominate — the rest are long tail.
When Opus 4.7 writes Python, 84% of functions declare return types. That's 2× the typical community rate.
Median file size by language across the Opus 4.7 corpus reveals a clear ordering — and it matches the language's native verbosity.
The correct pattern (.env.example) exists in 1,877 repos. The leaky pattern (.env in git) exists in 52. Small number, real problem.
Every AI coding tool has its self-documentation file. Across the Opus 4.7 corpus, CLAUDE.md appears 50× more often than .cursorrules.
12,095 repos, 84 GitHub Actions workflows. That's under 1%. Here's the full story of Opus 4.7's automation gap.
Counting actual page.tsx files vs pages/ files across 12K Opus 4.7 repos. App Router wins 2:1.
3,006 TypeScript repos. 3,006 tsconfig.json files. No "JavaScript wearing a costume" in the Opus 4.7 corpus.
Despite tRPC's popularity in "modern TypeScript" discussions, Opus 4.7 uses it in only 17 of 12,095 repos. Here's why.
Our research is based on continuous analysis of 128,000+ repositories and 3.27 billion lines of code using Repobility's proprietary scanning engine.
All data is aggregated and anonymized. No individual repository names or source code is disclosed.
Access our proprietary datasets for your own research, product development, or competitive intelligence.
Browse DatasetsGet our latest research and intelligence reports delivered to your inbox.
No spam. Unsubscribe anytime.