Scan timing: clone 19.98s · analysis 14.13s · 33.0 MB · GitHub API rate-limit (preflight)
https://github.com/electron/electron
· scanned 2026-06-05 05:10 UTC (1 week, 1 day ago)
· 10 languages
724 raw signals (92 security + 632 graph) 11/13 scanners ran 38th percentile · Javascript · large (100-500K LoC) System graph score 72 (lower by 4)
Last scanned 1 week, 1 day ago · v2 · 348 actionable findings from 2 signal sources. 60 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
0.0 | 0.20 | 0.00 |
documentation_score |
78.0 | 0.15 | 11.70 |
practices_score |
72.0 | 0.15 | 10.80 |
code_quality |
74.0 | 0.10 | 7.40 |
| Overall | 1.00 | 67.7 |
Showing 245 of 348 actionable findings. 408 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.devcontainer/docker-compose.yml:3
CI/CD securitycontainers
.github/workflows/build.yml:126, 156, 157, 159, 187, 188 (6 hits).github/workflows/apply-patches.yml:58script/verify-chromedriver.py:29script/verify-ffmpeg.py:57script/verify-mksnapshot.py:82script/run-clang-format.py:287
script/release/uploaders/upload-index-json.py:35
script/node/generate_node_headers.py:21
Eval used
script/patches-mtime-cache.py:138
script/run-clang-format.py:287
script/patches-mtime-cache.py:145, 163 (2 hits)script/zip_manifests/check-zip-manifest.py:27, 34 (2 hits)script/apply_all_patches.py:56script/get-git-version.py:31script/lib/native_tests.py:262script/release/uploaders/upload-index-json.py:45script/release/uploaders/upload-node-checksums.py:78script/release/uploaders/upload-symbols.py:84.devcontainer/docker-compose.yml:3
CI/CD securitycontainers
.well-known/security.txt
manifest.json
.github/workflows/linux-publish.yml.github/workflows/macos-publish.yml.github/workflows/pgo-generation.yml.github/workflows/pipeline-segment-electron-publish.yml.github/workflows/scorecards.yml.github/workflows/update-website-docs.yml.github/workflows/windows-publish.ymlscript/lib/util.py:224
Subprocess shell true
script/run-clang-format.py:138
Subprocess shell true
script/codesign/gen-trust.ts:19
Weak hash
package.json
CI/CD securitySupply chainNpm
script/pgo/download-profiles.py:99
lib/sandboxed_renderer/init.ts:9shell/browser/electron_api_sw_ipc_handler_impl.h:28shell/browser/electron_browser_client.h:104shell/browser/native_window_views.h:20shell/browser/ui/inspectable_web_contents.h:198build:1
llms.txt
humans.txt
robots.txt
sitemap.xml
repo-level (5 hits)spec/fixtures/native-addon/dialog-helper/package.jsonspec/fixtures/native-addon/echo/package.jsonspec/fixtures/native-addon/external-ab/package.jsonspec/fixtures/native-addon/is-valid-window/package.jsonspec/fixtures/native-addon/osr-gpu/package.jsonspec/fixtures/native-addon/uv-dlopen/package.jsonscript/node/generate_node_headers.py:39
script/apply_all_patches.py:16
script/node/generate_node_headers.py:17
This page is publicly accessible at:
https://repobility.com/scan/2a0b265b-a401-44a3-aadc-b28d2331293f/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/2a0b265b-a401-44a3-aadc-b28d2331293f/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.