Scan timing: clone 6.82s · analysis 9.62s · 59.3 MB · GitHub API rate-limit (preflight)
https://github.com/neovim/neovim
· scanned 2026-06-05 06:13 UTC (1 hour, 37 minutes ago)
· 10 languages
123 findings (59 legacy + 64 scanner) 11/13 scanners ran Scanner says 86 (lower by 18)
Last scanned 1 hour, 37 minutes ago · v2 · 91 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
20.0 | 0.20 | 4.00 |
documentation_score |
76.0 | 0.15 | 11.40 |
practices_score |
86.0 | 0.15 | 12.90 |
code_quality |
50.0 | 0.10 | 5.00 |
| Overall | 1.00 | 68.0 |
Showing 61 of 91 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
runtime/lua/vim/treesitter/language.lua:74
qualitylegacy
runtime/lua/vim/treesitter/health.lua:49
qualitylegacy
runtime/lua/vim/_core/exrc.lua:12
qualitylegacy
src/nvim/state.c:279
qualitylegacy
src/nvim/sha256.c:323
qualitylegacy
src/nvim/garray.c:157
qualitylegacy
scripts/shadacat.py:109
qualitylegacy
.github/workflows/release.yml:61
dependencylegacy
.github/workflows/docs.yml:16
dependencylegacy
.github/workflows/vim_patches.yml:24
dependencylegacy
.github/workflows/vim_patches.yml:20
dependencylegacy
.github/workflows/reviewers_remove.yml:14
dependencylegacy
.github/workflows/labeler_pr.yml:16
dependencylegacy
.github/workflows/reviewers_add.yml:20
dependencylegacy
.github/workflows/lintdocurls.yml:17
dependencylegacy
.github/workflows/codeql.yml:27
dependencylegacy
.github/workflows/coverity.yml:14
dependencylegacy
.github/workflows/reviewers_remove.yml:19
dependencylegacy
.github/workflows/labeler_pr.yml:93
dependencylegacy
.github/workflows/reviewers_add.yml:25
dependencylegacy
.github/workflows/labeler_issue.yml:15
dependencylegacy
.github/workflows/labeler_pr.yml:19
dependencylegacy
.github/workflows/codeql.yml:41
dependencylegacy
.github/workflows/codeql.yml:34
dependencylegacy
runtime/lua/vim/log.lua:197
file_uploadlegacy
scripts/shadacat.py:69
owaspeval_used
.dockerignore
dockerlegacy
.github/workflows/codeql.yml:34
supply-chaingithub-actionspinned-dependencies
.github/workflows/codeql.yml:41
supply-chaingithub-actionspinned-dependencies
.github/workflows/labeler_pr.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/vim_patches.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/docs.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/backport.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/coverity.yml
securityports
.github/workflows/response.yml
securityports
src/nlua0.zig:42
error_handlinglegacy
runtime/gen_runtime.zig:17
error_handlinglegacy
src/nvim/lua/stdlib.c:279
qualitylegacy
.github/workflows/labeler_issue.yml:15
supply-chaingithub-actionspinned-dependencies
.github/workflows/reviewers_add.yml:25
supply-chaingithub-actionspinned-dependencies
.github/workflows/labeler_pr.yml:93
supply-chaingithub-actionspinned-dependencies
.github/workflows/reviewers_remove.yml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:185
supply-chaingithub-actionspinned-dependencies
contrib/gdb/nvim-gdb-pretty-printers.py:82
dead-code
scripts/shadacat.py:41
dead-code
scripts/shadacat.py:30
dead-code
contrib/gdb/nvim-gdb-pretty-printers.py:55
dead-code
scripts/download-unicode-files.sh:9
qualitylegacy
runtime/plugin/net.lua:7
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/44e473c4-3273-4b5c-a0b6-dfcb3d13c11b/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/44e473c4-3273-4b5c-a0b6-dfcb3d13c11b/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.