Scan timing: clone 19.98s · analysis 14.13s · 33.0 MB · GitHub API rate-limit (preflight)
https://github.com/electron/electron
· scanned 2026-06-05 05:10 UTC (3 hours, 46 minutes ago)
· 10 languages
724 findings (92 legacy + 632 scanner) 11/13 scanners ran 11th percentile · Javascript · large (100-500K LoC) Scanner says 72 (lower by 4)
Last scanned 3 hours, 46 minutes ago · v2 · 408 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
0.0 | 0.20 | 0.00 |
documentation_score |
78.0 | 0.15 | 11.70 |
practices_score |
72.0 | 0.15 | 10.80 |
code_quality |
74.0 | 0.10 | 7.40 |
| Overall | 1.00 | 67.7 |
Showing 299 of 408 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
shell/browser/ui/devtools_ui_theme_data_source.cc:203
qualitylegacy
shell/browser/ui/devtools_ui_bundle_data_source.cc:32
qualitylegacy
shell/browser/relauncher_win.cc:57
qualitylegacy
.github/workflows/build.yml:188
dependencylegacy
.github/workflows/build.yml:187
dependencylegacy
.github/workflows/build.yml:156
dependencylegacy
.github/workflows/build.yml:126
dependencylegacy
.github/workflows/apply-patches.yml:58
dependencylegacy
.github/workflows/build.yml:157
dependencylegacy
.github/workflows/build.yml:159
dependencylegacy
.devcontainer/docker-compose.yml:3
dockerlegacy
script/patches-mtime-cache.py:138
qualitylegacy
script/release/uploaders/upload-node-checksums.py:27
qualitylegacy
script/codesign/gen-trust.ts:11
qualitylegacy
script/verify-mksnapshot.py:82
qualitylegacy
script/verify-ffmpeg.py:57
qualitylegacy
script/verify-chromedriver.py:29
qualitylegacy
shell/browser/osr/osr_host_display_client_mac.mm:18
qualitylegacy
shell/browser/notifications/mac/cocoa_notification.mm:170
qualitylegacy
shell/browser/api/electron_api_web_contents_mac.mm:50
qualitylegacy
script/run-clang-format.py:287
qualitylegacy
script/release/uploaders/upload-index-json.py:35
path_traversallegacy
docs/fiddles/native-ui/dialogs/save-dialog/renderer.js:5
xsslegacy
docs/fiddles/native-ui/dialogs/open-file-or-directory/renderer.js:5
xsslegacy
docs/fiddles/features/web-serial/renderer.js:9
xsslegacy
script/gen-libc++-filenames.js:38
qualitylegacy
script/release/prepare-release.ts:36
qualitylegacy
script/node/generate_node_headers.py:21
owaspeval_used
script/patches-mtime-cache.py:138
error_handlinglegacy
script/release/uploaders/upload-node-checksums.py:78
qualitylegacy
script/release/uploaders/upload-symbols.py:84
qualitylegacy
script/release/uploaders/upload-index-json.py:45
qualitylegacy
script/zip_manifests/check-zip-manifest.py:34
qualitylegacy
script/zip_manifests/check-zip-manifest.py:27
qualitylegacy
script/patches-mtime-cache.py:163
qualitylegacy
script/patches-mtime-cache.py:145
qualitylegacy
script/get-git-version.py:31
qualitylegacy
script/apply_all_patches.py:56
qualitylegacy
script/run-clang-format.py:287
injectionlegacy
.devcontainer/docker-compose.yml:3
dockerlegacy
.well-known/security.txt
qualitylegacy
manifest.json
qualitylegacy
.github/workflows/windows-publish.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/pipeline-segment-electron-publish.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/update-website-docs.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/linux-publish.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/pgo-generation.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/scorecards.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/macos-publish.yml
supply-chaingithub-actionsleast-privilege
script/lib/util.py:224
owaspsubprocess_shell_true
script/run-clang-format.py:138
owaspsubprocess_shell_true
script/codesign/gen-trust.ts:19
owaspweak_hash
package.json
supply-chainnpminstall-scripts
script/pgo/download-profiles.py:99
race_conditionlegacy
script/run-clang-format.py:158
qualitylegacy
script/generate-mas-config.py:11
qualitylegacy
shell/browser/native_window_views.h:20
qualitylegacy
shell/browser/electron_browser_client.h:104
qualitylegacy
shell/browser/electron_api_sw_ipc_handler_impl.h:28
qualitylegacy
lib/sandboxed_renderer/init.ts:9
qualitylegacy
build:1
qualitylegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
robots.txt
qualitylegacy
sitemap.xml
qualitylegacy
script/node/generate_node_headers.py:39
dead-code
script/apply_all_patches.py:16
dead-code
script/node/generate_node_headers.py:17
dead-code
script/actions/screencapture-nag-remover.sh:40
qualitylegacy
docs/fiddles/features/navigation-history/renderer.js:24
qualitylegacy
default_app/main.ts:330
qualitylegacy
shell/browser/api/electron_api_web_contents_mac.mm:31
qualitylegacy
script/release/version-utils.ts:26
qualitylegacy
default_app/default_app.ts:108
qualitylegacy
script/release/github-token.ts:76
qualitylegacy
script/release/get-url-hash.ts:36
qualitylegacy
default_app/main.ts:74
qualitylegacy
script/patches-mtime-cache.py:171
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/2a0b265b-a401-44a3-aadc-b28d2331293f/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/2a0b265b-a401-44a3-aadc-b28d2331293f/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.