Scan timing: clone 6.82s · analysis 9.62s · 59.3 MB · GitHub API rate-limit (preflight)
https://github.com/neovim/neovim
· scanned 2026-06-05 06:13 UTC (2 hours, 58 minutes ago)
· 10 languages
123 findings (59 legacy + 64 scanner) 11/13 scanners ran Scanner says 86 (lower by 18)
Last scanned 2 hours, 58 minutes ago · v2 · 91 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
20.0 | 0.20 | 4.00 |
documentation_score |
76.0 | 0.15 | 11.40 |
practices_score |
86.0 | 0.15 | 12.90 |
code_quality |
50.0 | 0.10 | 5.00 |
| Overall | 1.00 | 68.0 |
Bug-class explainers. Each card groups findings of the same shape — these are the patterns most likely to ship to prod and reappear in future scans unless you systematically fix the cause, not just the instance.
src/nvim/lua/stdlib.c:279
src/nlua0.zig:42
runtime/gen_runtime.zig:17
src/nlua0.zig:87
src/tee/tee.c:95
src/coverity-model.c:63
scripts/shadacat.py:32
runtime/lua/vim/uri.lua:1
scripts/download-unicode-files.sh:9
runtime/plugin/net.lua:7
runtime/lua/vim/inspect.lua:4
This page is publicly accessible at:
https://repobility.com/scan/44e473c4-3273-4b5c-a0b6-dfcb3d13c11b/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/44e473c4-3273-4b5c-a0b6-dfcb3d13c11b/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.