← Back to scan
File as GitHub Issue repo: JKHeadley/instar

Push this scan report to JKHeadley/instar

Click the green button below to open GitHub’s new-issue form, pre-filled with the report title, summary table, top findings, and an embedded score-card image. No authentication needed — you review on GitHub before submitting. Repobility is credited as the scanner.

Embedded score card image

This image will render at the top of the issue body. Hosted on Repobility, refreshes automatically after re-scans.

Repobility score card

Issue title

Password embedded in URL

Curate findings to include

Pick exactly which findings appear in the issue body. By default the top 5 are included. Uncheck noise, check what matters.

Top 5 (default)
Severity Rule Title File:line
CRIT SECR004 Password embedded in URL tests/unit/crash-recovery-ux.test.ts:465
CRIT SECR004 Password embedded in URL tests/unit/crash-recovery-ux.test.ts:143
CRIT SECR004 Password embedded in URL tests/unit/output-privacy-router.test.ts:833
CRIT SECR004 Password embedded in URL tests/unit/output-privacy-router.test.ts:297
CRIT SECR004 Password embedded in URL tests/unit/output-privacy-router.test.ts:290
CRIT SECR004 Password embedded in URL tests/unit/output-privacy-router.test.ts:283
CRIT SECR004 Password embedded in URL tests/unit/output-privacy-router.test.ts:276
CRIT SECR004 Password embedded in URL tests/unit/secret-redactor.test.ts:393
CRIT SECR004 Password embedded in URL tests/unit/secret-redactor.test.ts:250
CRIT SECR004 Password embedded in URL tests/unit/secret-redactor.test.ts:193
CRIT SECR004 Password embedded in URL tests/unit/secret-redactor.test.ts:71
CRIT SECR004 Password embedded in URL tests/unit/secret-redactor.test.ts:68
CRIT SECR004 Password embedded in URL tests/unit/ContentClassifier.test.ts:186
CRIT SECR004 Password embedded in URL tests/unit/ContentClassifier.test.ts:176
CRIT SECR001 Hardcoded secret in source tests/e2e/security-lifecycle.test.ts:95
CRIT SECR001 Hardcoded secret in source tests/e2e/security-lifecycle.test.ts:81
CRIT SECR001 Hardcoded secret in source tests/e2e/security-pipeline-e2e.test.ts:1358
CRIT SECR001 Hardcoded secret in source tests/e2e/security-pipeline-e2e.test.ts:96
CRIT SECR001 Hardcoded secret in source tests/e2e/security-pipeline-e2e.test.ts:1423
CRIT SECR001 Hardcoded secret in source tests/e2e/security-pipeline-e2e.test.ts:1335
CRIT SECR001 Hardcoded secret in source tests/unit/PolicyEnforcementLayer.test.…:147
CRIT SECR001 Hardcoded secret in source tests/unit/PolicyEnforcementLayer.test.…:100
CRIT SECR001 Hardcoded secret in source tests/unit/PolicyEnforcementLayer.test.…:91
CRIT SECR001 Hardcoded secret in source tests/unit/PolicyEnforcementLayer.test.…:399
CRIT SECR001 Hardcoded secret in source tests/unit/PolicyEnforcementLayer.test.…:386
CRIT SECR001 Hardcoded secret in source tests/unit/PolicyEnforcementLayer.test.…:154
CRIT SECR001 Hardcoded secret in source tests/unit/PolicyEnforcementLayer.test.…:80
CRIT SECR001 Hardcoded secret in source tests/unit/PolicyEnforcementLayer.test.…:457
CRIT SECR001 Hardcoded secret in source tests/unit/PolicyEnforcementLayer.test.…:108
CRIT SECR001 Hardcoded secret in source tests/unit/ExecutionJournal.test.ts:545
CRIT SECR001 Hardcoded secret in source tests/unit/ExecutionJournal.test.ts:531
CRIT SECR001 Hardcoded secret in source tests/unit/CoherenceGateE2E.test.ts:483
CRIT SECR001 Hardcoded secret in source tests/unit/CoherenceGateE2E.test.ts:486
CRIT SECR001 Hardcoded secret in source tests/unit/crash-recovery-ux.test.ts:154
CRIT SECR001 Hardcoded secret in source tests/unit/crash-recovery-ux.test.ts:151
CRIT SECR001 Hardcoded secret in source tests/unit/serendipity-capture.test.ts:328
CRIT SECR001 Hardcoded secret in source tests/unit/serendipity-capture.test.ts:335
CRIT SECR001 Hardcoded secret in source tests/unit/serendipity-capture.test.ts:316
CRIT SECR001 Hardcoded secret in source tests/unit/serendipity-capture.test.ts:310
CRIT SECR001 Hardcoded secret in source tests/unit/output-privacy-router.test.ts:269
CRIT SECR001 Hardcoded secret in source tests/unit/output-privacy-router.test.ts:262
CRIT SECR001 Hardcoded secret in source tests/unit/secret-redactor.test.ts:82
CRIT SECR001 Hardcoded secret in source tests/unit/secret-redactor.test.ts:61
CRIT SECR001 Hardcoded secret in source tests/unit/secret-redactor.test.ts:105
CRIT SECR001 Hardcoded secret in source tests/unit/secret-redactor.test.ts:57
CRIT SECR001 Hardcoded secret in source tests/unit/secret-redactor.test.ts:54
CRIT SECR001 Hardcoded secret in source tests/unit/machine-identity.test.ts:344
CRIT SECR001 Hardcoded secret in source tests/unit/machine-identity.test.ts:343
CRIT SECR001 Hardcoded secret in source tests/unit/machine-identity.test.ts:92
CRIT SECR001 Hardcoded secret in source tests/unit/machine-identity.test.ts:53
CRIT SECR001 Hardcoded secret in source tests/unit/ContentClassifier.test.ts:452
CRIT SECR001 Hardcoded secret in source tests/unit/ContentClassifier.test.ts:438
CRIT SECR001 Hardcoded secret in source tests/unit/ContentClassifier.test.ts:356
CRIT SECR001 Hardcoded secret in source tests/unit/ContentClassifier.test.ts:163
CRIT SECR001 Hardcoded secret in source tests/unit/ContentClassifier.test.ts:154
CRIT SECR001 Hardcoded secret in source tests/unit/ContentClassifier.test.ts:145
CRIT SECR001 Hardcoded secret in source tests/unit/ContentClassifier.test.ts:135
CRIT SECR001 Hardcoded secret in source tests/unit/ContentClassifier.test.ts:104
CRIT SECR001 Hardcoded secret in source tests/unit/ContentClassifier.test.ts:85
CRIT SECR001 Hardcoded secret in source tests/unit/ContentClassifier.test.ts:113
CRIT SECR001 Hardcoded secret in source tests/integration/security-wiring.test.…:149
CRIT SECR001 Hardcoded secret in source tests/integration/output-privacy-routin…:243
HIGH SUPC001 Supply chain — curl | bash anti-pattern tests/e2e/phase4-dispatch-scope-provena…:176
HIGH SUPC001 Supply chain — curl | bash anti-pattern tests/e2e/file-viewer-e2e.test.ts:497
HIGH SUPC001 Supply chain — curl | bash anti-pattern tests/unit/crash-recovery-ux.test.ts:483
HIGH SEC020 [SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-b… src/core/PostUpdateMigrator.ts:2638
HIGH AUC003 [AUC003] Object-level route lacks visible authorization: A route with an object id-like p… src/server/routes.ts:4541
HIGH AUC003 [AUC003] Object-level route lacks visible authorization: A route with an object id-like p… src/server/routes.ts:3684
HIGH AUC003 [AUC003] Object-level route lacks visible authorization: A route with an object id-like p… src/server/routes.ts:2610
HIGH AUC003 [AUC003] Object-level route lacks visible authorization: A route with an object id-like p… src/server/routes.ts:2486
HIGH AUC003 [AUC003] Object-level route lacks visible authorization: A route with an object id-like p… src/server/routes.ts:2474
HIGH AUC003 [AUC003] Object-level route lacks visible authorization: A route with an object id-like p… src/server/routes.ts:2403
HIGH AUC003 [AUC003] Object-level route lacks visible authorization: A route with an object id-like p… src/server/routes.ts:2392
HIGH AUC003 [AUC003] Object-level route lacks visible authorization: A route with an object id-like p… src/server/routes.ts:2157
HIGH AUC003 [AUC003] Object-level route lacks visible authorization: A route with an object id-like p… src/server/routes.ts:1817
HIGH AUC003 [AUC003] Object-level route lacks visible authorization: A route with an object id-like p… src/moltbridge/routes.ts:73
MED ERR002 [ERR002] Empty Catch Block: Empty catch blocks hide errors. src/messaging/WhatsAppAdapter.ts:329
MED ERR002 [ERR002] Empty Catch Block: Empty catch blocks hide errors. src/messaging/TelegramAdapter.ts:487
MED ERR002 [ERR002] Empty Catch Block: Empty catch blocks hide errors. src/core/DispatchExecutor.ts:373
MED SEC007 [SEC007] Unsafe Deserialization: Unsafe deserialization can execute arbitrary code. src/commands/jobMigrate.ts:110
MED SEC007 [SEC007] Unsafe Deserialization: Unsafe deserialization can execute arbitrary code. src/scheduler/AgentMdJobLoader.ts:715
MED SEC007 [SEC007] Unsafe Deserialization: Unsafe deserialization can execute arbitrary code. src/scheduler/InstallBuiltinJobs.ts:151
MED ERR001 [ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even… playbook-scripts/playbook-failsafe.py:171
MED ERR001 [ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even… playbook-scripts/playbook-retirement.py:169
MED ERR001 [ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even… playbook-scripts/build-state.py:192
MED AUC001 [AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks…
MED AIC003 Duplicated implementation block across source files src/monitoring/SessionWatchdog.ts:499
MED AIC003 Duplicated implementation block across source files src/monitoring/CommitmentTracker.ts:837
MED AIC003 Duplicated implementation block across source files src/core/reviewers/escalation-resolutio…:86
MED AIC003 Duplicated implementation block across source files src/core/SecretStore.ts:78
MED AIC003 Duplicated implementation block across source files src/core/AutoUpdater.ts:437
MED AIC003 Duplicated implementation block across source files playbook-scripts/playbook-offline-adapt…:186
MED AIC003 Duplicated implementation block across source files .instar/hooks/instar/claim-intercept.js:7
MED QUAL003 Magic number used as default arg tests/e2e/file-viewer-e2e.test.ts:108
MED QUAL003 Magic number used as default arg tests/e2e/scope-coherence-lifecycle.tes…:169
MED QUAL003 Magic number used as default arg tests/unit/activity-partitioner.test.ts:305
MED QUAL003 Magic number used as default arg tests/unit/InboundMessageGate.test.ts:66
MED QUAL003 Magic number used as default arg tests/unit/nonce-store-config.test.ts:49
MED QUAL003 Magic number used as default arg tests/unit/nonce-store-config.test.ts:42
MED QUAL003 Magic number used as default arg tests/unit/branch-manager.test.ts:91
MED QUAL003 Magic number used as default arg tests/unit/branch-manager.test.ts:81
MED QUAL003 Magic number used as default arg tests/unit/middleware-behavioral.test.ts:208
MED QUAL003 Magic number used as default arg tests/unit/CommitmentTracker.test.ts:865
MED QUAL003 Magic number used as default arg tests/unit/request-timeout.test.ts:43
MED QUAL003 Magic number used as default arg tests/unit/agent-bus-replay-protection.…:707
MED QUAL003 Magic number used as default arg tests/unit/agent-bus-replay-protection.…:687
MED QUAL003 Magic number used as default arg tests/unit/intent-reflect.test.ts:150
MED QUAL003 Magic number used as default arg tests/unit/ForegroundRestartWatcher.tes…:53
MED QUAL003 Magic number used as default arg tests/integration/quota-collection.test…:278
MED QUAL003 Magic number used as default arg tests/integration/drift-routes.test.ts:99
MED LOG001 PII printed to stdout/stderr src/cli.ts:214
MED LOG001 PII printed to stdout/stderr src/cli.ts:97
MED LOG001 PII printed to stdout/stderr src/cli.ts:57
MED LOG001 PII printed to stdout/stderr src/cli.ts:55
MED LOG001 PII printed to stdout/stderr src/cli.ts:52
MED CORS001 CORS misconfiguration — wildcard Access-Control-Allow-Origin tests/unit/middleware-behavioral.test.ts:16
MED JRN002 Browser storage is used for session token material dashboard/index.html:3325
MED JRN002 Browser storage is used for session token material dashboard/index.html:3305
MED DKR001 Docker final stage has no non-root USER Dockerfile.relay:26
MED WEB003 Public web service has no security.txt .well-known/security.txt
MED JRN003 Frontend API reference is not matched by discovered backend routes src/core/PostUpdateMigrator.ts:1604
MED AUC002 [AUC002] Low visible authorization coverage in route inventory: Only 22.5% of discovered …
MED AGT012 Agent control bridge may listen on a network interface without visible auth src/core/FeedbackManager.ts:69
MED AGT012 Agent control bridge may listen on a network interface without visible auth src/core/DispatchManager.ts:135
MED AUC009 [AUC009] Sensitive function route lacks elevated authorization evidence: A route appears … src/server/routes.ts:2403
MED AUC009 [AUC009] Sensitive function route lacks elevated authorization evidence: A route appears … src/server/routes.ts:2157
MED AUC009 [AUC009] Sensitive function route lacks elevated authorization evidence: A route appears … src/server/routes.ts:2011
MED AUC009 [AUC009] Sensitive function route lacks elevated authorization evidence: A route appears … src/server/routes.ts:2006
MED AUC009 [AUC009] Sensitive function route lacks elevated authorization evidence: A route appears … src/server/routes.ts:2000
MED AUC009 [AUC009] Sensitive function route lacks elevated authorization evidence: A route appears … src/server/routes.ts:1967
MED AUC009 [AUC009] Sensitive function route lacks elevated authorization evidence: A route appears … src/server/machineRoutes.ts:150
MED AUC009 [AUC009] Sensitive function route lacks elevated authorization evidence: A route appears … src/server/AgentServer.ts:223
MED AUC009 [AUC009] Sensitive function route lacks elevated authorization evidence: A route appears … src/server/AgentServer.ts:207
MED AUC009 [AUC009] Sensitive function route lacks elevated authorization evidence: A route appears … src/moltbridge/routes.ts:178
MED AGT013 Agent auto-approve or skip-permissions mode is easy to enable skills/instar-session/SKILL.md:48
MED AUC004 [AUC004] Admin route does not show super_admin separation: An administrative route was de… src/server/routes.ts:2260
MED AUC004 [AUC004] Admin route does not show super_admin separation: An administrative route was de… src/server/routes.ts:2248
MED AUC004 [AUC004] Admin route does not show super_admin separation: An administrative route was de… src/server/routes.ts:2225
MED AUC004 [AUC004] Admin route does not show super_admin separation: An administrative route was de… src/server/routes.ts:2211
MED AUC004 [AUC004] Admin route does not show super_admin separation: An administrative route was de… src/server/routes.ts:2200
MED AUC004 [AUC004] Admin route does not show super_admin separation: An administrative route was de… src/server/routes.ts:2146
MED AUC004 [AUC004] Admin route does not show super_admin separation: An administrative route was de… src/server/routes.ts:2136
MED AUC004 [AUC004] Admin route does not show super_admin separation: An administrative route was de… src/server/routes.ts:1091
MED AUC004 [AUC004] Admin route does not show super_admin separation: An administrative route was de… src/server/worktreeRoutes.ts:245
MED AUC004 [AUC004] Admin route does not show super_admin separation: An administrative route was de… src/server/worktreeRoutes.ts:108
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/e2e/threadline/A2AE2E.test.ts:852
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/e2e/launchd-node-boot-wrapper.tes…:444
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/e2e/phase4-dispatch-scope-provena…:176
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/e2e/discernment-layer-e2e.test.ts:674
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/e2e/messaging-lifecycle.test.ts:203
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/AdaptationValidator.test.ts:194
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/message-router-cross-machine…:112
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/ExecutionJournal.test.ts:516
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/ExecutionJournal.test.ts:99
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/ExecutionJournal.test.ts:87
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/agent-token-manager.test.ts:223
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/DiscoverySecurity.test.ts:253
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/CoherenceGate.test.ts:535
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/git-sync-transport.test.ts:390
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/git-sync-transport.test.ts:381
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/git-sync-transport.test.ts:374
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/git-sync-transport.test.ts:368
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/git-sync-transport.test.ts:362
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/git-sync-transport.test.ts:62
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/message-router.test.ts:346
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/message-router.test.ts:315
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/message-router.test.ts:280
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/unit/messaging-types.test.ts:358
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/integration/threadline/A2AIntegra…:659
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/integration/execution-journal-lif…:210
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/integration/execution-journal-lif…:177
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/integration/execution-journal-lif…:160
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/integration/execution-journal-lif…:123
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/integration/messaging-routes.test…:393
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/integration/messaging-routes.test…:364
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/integration/messaging-routes.test…:326
MED CRYP001 Crypto — plaintext HTTP for sensitive endpoint tests/integration/messaging-routes.test…:292
LOW ERR003 [ERR003] Ignored Error (Go): Ignoring error return values. scripts/attachments-sync/main.go:206
LOW QUAL004 Placeholder default username (admin/admin) tests/e2e/sync-lifecycle.test.ts:43
LOW QUAL004 Placeholder default username (admin/admin) tests/e2e/sync-lifecycle.test.ts:34
LOW QUAL004 Placeholder default username (admin/admin) tests/e2e/sync-lifecycle.test.ts:32
LOW QUAL004 Placeholder default username (admin/admin) tests/e2e/branch-lifecycle.test.ts:46
LOW QUAL004 Placeholder default username (admin/admin) tests/e2e/branch-lifecycle.test.ts:34
LOW QUAL004 Placeholder default username (admin/admin) tests/e2e/branch-lifecycle.test.ts:32
LOW QUAL004 Placeholder default username (admin/admin) tests/e2e/handoff-lifecycle.test.ts:50
LOW QUAL004 Placeholder default username (admin/admin) tests/e2e/handoff-lifecycle.test.ts:36
LOW QUAL004 Placeholder default username (admin/admin) tests/e2e/handoff-lifecycle.test.ts:34
LOW QUAL004 Placeholder default username (admin/admin) tests/e2e/sync-edge-cases.test.ts:40
LOW QUAL004 Placeholder default username (admin/admin) tests/unit/worktree-monitor.test.ts:63
LOW QUAL004 Placeholder default username (admin/admin) tests/unit/git-state-manager.test.ts:52
LOW QUAL004 Placeholder default username (admin/admin) tests/unit/RelationshipManager.test.ts:654
LOW QUAL004 Placeholder default username (admin/admin) tests/unit/branch-manager.test.ts:62
LOW QUAL004 Placeholder default username (admin/admin) tests/unit/handoff-manager.test.ts:107
LOW QUAL004 Placeholder default username (admin/admin) tests/unit/user-manager-edge.test.ts:195
LOW QUAL004 Placeholder default username (admin/admin) tests/unit/user-manager-edge.test.ts:184
LOW QUAL004 Placeholder default username (admin/admin) tests/integration/branch-wiring.test.ts:81
LOW QUAL004 Placeholder default username (admin/admin) tests/integration/handoff-wiring.test.ts:46
LOW WEB005 robots.txt does not advertise a sitemap CLAUDE.md
LOW DKR008 .dockerignore misses sensitive defaults .dockerignore
Reset to top 5 199 findings available (after auto-suppression of test files + won't-fix)

Issue body (markdown)

## Code-quality scan: `JKHeadley/instar`

**Score: 71/100 (B)**  ·  209 findings  ·  scanned 2026-05-15 20:53 UTC  ·  606,499 LOC

| Severity | Count |
|---|---|
| CRITICAL | 62 |
| HIGH | 14 |
| MEDIUM | 101 |
| LOW | 22 |

📊 [Full filterable report](https://repobility.com/scan/00f3e9b4-a692-4d73-b1d2-2e06abed64cd/)  ·  ![scorecard](https://repobility.com/scan/00f3e9b4-a692-4d73-b1d2-2e06abed64cd/report.png?v=1778878424-s2)

### Top findings

1. **CRITICAL** `SECR004` — Password embedded in URL
   `tests/unit/crash-recovery-ux.test.ts:465`
2. **CRITICAL** `SECR004` — Password embedded in URL
   `tests/unit/crash-recovery-ux.test.ts:143`
3. **CRITICAL** `SECR004` — Password embedded in URL
   `tests/unit/output-privacy-router.test.ts:833`
4. **CRITICAL** `SECR004` — Password embedded in URL
   `tests/unit/output-privacy-router.test.ts:297`
5. **CRITICAL** `SECR004` — Password embedded in URL
   `tests/unit/output-privacy-router.test.ts:290`

---

**Security note**: this issue is public. If any flagged finding is a real, exploitable vulnerability, please redirect to your `SECURITY.md` policy or open a [private security advisory](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability) instead. We're happy to close this and re-submit privately.

---

_Filed automatically. Close this issue if not useful — we won't refile. Full report: https://repobility.com/scan/00f3e9b4-a692-4d73-b1d2-2e06abed64cd/_
Already filed
This repo publishes a SECURITY.md policy and the scan contains 50 Critical/High security finding(s). Public issue filing would violate coordinated disclosure. Submit privately via the project's security reporting channel.
Megaproject â high spam risk
Could not determine 'JKHeadley/instar' star count (GitHub API rate-limited or unreachable). When in doubt about repo size, prefer opening a focused PR or a discussion rather than an issue.
Already filed
137/209 findings (66%) on this scan are already flagged as test-file, won't-fix, or suppressed. The scan is too noisy to file as a single issue. Curate down to specific actionable findings, or address the FP source first.

The button opens GitHubâs new-issue page in a new tab. You will see the title + body pre-filled â review, edit if you want, then click GitHubâs "Submit new issue" button. Repobility never posts anything on your behalf.

For real security findings on big repos: use the project's SECURITY.md or private advisory flow instead of a public issue.