Scan timing: clone 19.73s · analysis 57.14s · 76.9 MB · GitHub API rate-limit (preflight)
https://github.com/facebook/flow
· scanned 2026-06-06 00:54 UTC (4 days ago)
· 10 languages
1137 raw signals (137 security + 1000 graph) 11/13 scanners ran 88th percentile · Javascript · huge (>500K LoC) System graph score 52 (higher by 38)
Last scanned 4 days ago · v2 · 536 actionable findings from 2 signal sources. 101 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
72.0 | 0.15 | 10.80 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 90.5 |
Showing 278 of 536 actionable findings. 637 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.circleci/deploy_flow_bin.sh:20
src/analysis/env_builder/nonvoid_return.ml:63src/codemods/remove_react_import.ml:146src/lsp/selectionRangeProvider.ml:267src/parser_utils/type_sig/type_sig_hash.ml:150
src/analysis/env_builder/nonvoid_return.ml:63
src/parser_utils/type_sig/type_sig_hash.ml:150
src/analysis/env_builder/nonvoid_return.ml:63
website/docusaurus.config.js:105
src/commands/forceRecheckCommand.ml:33
src/commands/forceRecheckCommand.ml:33
src/typing/errors/suppression_comments.ml:89
rust_port/crates/flow_imports_exports/src/exports.rs:339
Eval used
rust_port/crates/flow_typing_statement/src/component_sig.rs:244
Eval used
rust_port/crates/flow_typing_ty_normalizer/src/normalizer.rs:800
Eval used
rust_port/crates/flow_typing_utils/src/type_sig_merge.rs:1497
Eval used
packages/flow-dev-tools/src/comment/getAst.js:36
Exec used
rust_port/crates/flow_common_vcs/src/git.rs:13
Exec used
rust_port/crates/flow_common_vcs/src/hg.rs:18
Exec used
src/lsp/selectionRangeProvider.ml:82
src/flow_dot_js_wasm_packager.js:73
src/commands/foregroundCheckCommands.ml:120
packages/flow-for-vscode/src/utils/which.ts:13
website/flow-typed/environment/jsx.js:866
Dangerous innerhtml
newtests/lsp/code-action/quickfix/react/test.js:2newtests/lsp/code-action/quickfix/ts_and_legacy_syntax/test.js:1newtests/lsp/code-action/refactor/readonly_conversion/test.js:1newtests/lsp/code-action/refactor/test.js:2newtests/lsp/completion/haste_package_auto_imports/test.js:1newtests/lsp/document_paste/test.js:1newtests/lsp/findReferences/__fixtures__/locals.js:1newtests/lsp/findReferences/test.js:25packages/package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/4930b5ba-4f83-4e87-9857-7da8af461489/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/4930b5ba-4f83-4e87-9857-7da8af461489/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.