Scan timing: clone 4.12s · analysis 21.99s · 17.8 MB · GitHub API rate-limit (preflight)
https://github.com/github/copilot-sdk
· scanned 2026-06-04 23:18 UTC (9 hours, 38 minutes ago)
· 10 languages
1079 findings (223 legacy + 856 scanner) Scanner says 80 (lower by 14)
Last scanned 9 hours, 37 minutes ago · v4 · 437 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
34.6 | 0.25 | 8.65 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
82.0 | 0.15 | 12.30 |
code_quality |
44.7 | 0.10 | 4.47 |
| Overall | 1.00 | 66.4 |
Showing 303 of 437 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/java-codegen-check.yml:196
dependencylegacy
.github/workflows/java-codegen-check.yml:112
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:1267
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:854
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:791
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:146
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:855
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:802
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:675
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:443
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:426
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:424
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:1405
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:1119
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:1082
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:1067
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:1052
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:1035
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:856
dependencylegacy
.github/workflows/sdk-consistency-review.lock.yml:442
dependencylegacy
python/samples/chat.py:52
qualitylegacy
rust/src/canvas.rs:229
path_traversallegacy
python/copilot/canvas.py:152
path_traversallegacy
go/canvas.go:95
path_traversallegacy
python/scripts/build-wheels.mjs:111
qualitylegacy
.github/workflows/copilot-setup-steps.yml:28
dependencylegacy
.github/workflows/docs-validation.yml:137
dependencylegacy
.github/workflows/docs-validation.yml:110
dependencylegacy
.github/workflows/docs-validation.yml:86
dependencylegacy
.github/workflows/docs-validation.yml:53
dependencylegacy
.github/workflows/docs-validation.yml:28
dependencylegacy
.github/workflows/copilot-setup-steps.yml:61
dependencylegacy
.github/workflows/docs-validation.yml:115
dependencylegacy
.github/workflows/copilot-setup-steps.yml:55
dependencylegacy
.github/workflows/docs-validation.yml:91
dependencylegacy
.github/workflows/docs-validation.yml:142
dependencylegacy
.github/workflows/copilot-setup-steps.yml:32
dependencylegacy
.github/workflows/docs-validation.yml:138
dependencylegacy
.github/workflows/docs-validation.yml:111
dependencylegacy
.github/workflows/docs-validation.yml:87
dependencylegacy
.github/workflows/docs-validation.yml:54
dependencylegacy
.github/workflows/docs-validation.yml:29
dependencylegacy
.github/workflows/copilot-setup-steps.yml:43
dependencylegacy
.github/workflows/docs-validation.yml:58
dependencylegacy
.github/workflows/copilot-setup-steps.yml:49
dependencylegacy
.github/workflows/docs-validation.yml:64
dependencylegacy
python/samples/chat.py:35
qualitylegacy
go/samples/go.mod:17
dependencylegacy
nodejs/samples/package.json:1
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
go/samples/go.mod
dependencylegacy
go/go.mod
dependencylegacy
python/copilot/generated/session_events.py:6878
llm_injectionlegacy
nodejs/src/generated/session-events.ts:463
llm_injectionlegacy
.github/workflows/verify-compiled.yml:20
supply-chaingithub-actionspinned-dependencies
.github/workflows/update-copilot-dependency.yml:54
supply-chaingithub-actionspinned-dependencies
.github/workflows/codegen-check.yml:54
supply-chaingithub-actionspinned-dependencies
java/src/generated/java/com/github/copilot/generated/rpc/SessionShellApi.java:41
owaspexec_used
python/scripts/build-wheels.mjs:258
path_traversallegacy
python/copilot/session.py:1709
qualitylegacy
python/copilot/session.py:1658
qualitylegacy
python/copilot/session_fs_provider.py:303
qualitylegacy
python/copilot/session_fs_provider.py:262
qualitylegacy
python/copilot/session_fs_provider.py:255
qualitylegacy
python/copilot/session_fs_provider.py:241
qualitylegacy
python/copilot/session_fs_provider.py:233
qualitylegacy
python/copilot/session_fs_provider.py:226
qualitylegacy
python/copilot/session_fs_provider.py:206
qualitylegacy
python/copilot/session_fs_provider.py:193
qualitylegacy
python/copilot/session_fs_provider.py:186
qualitylegacy
python/copilot/session_fs_provider.py:179
qualitylegacy
python/copilot/session_fs_provider.py:171
qualitylegacy
python/copilot/tools.py:218
qualitylegacy
nodejs/package.json
dependencylegacy
.github/workflows/docs-validation.yml:64
supply-chaingithub-actionspinned-dependencies
.github/workflows/copilot-setup-steps.yml:49
supply-chaingithub-actionspinned-dependencies
.github/workflows/copilot-setup-steps.yml:75
supply-chaingithub-actionspinned-dependencies
.github/workflows/update-copilot-dependency.yml:48
supply-chaingithub-actionspinned-dependencies
.github/workflows/codegen-check.yml:43
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:140
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:165
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:211
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:226
supply-chaingithub-actionspinned-dependencies
.github/workflows/java-codegen-fix.lock.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release-changelog.lock.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/java-publish-maven.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/update-copilot-dependency.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/java-adapt-handwritten-code-to-accept-upgrade-changes.lock.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/java-codegen-check.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/publish.yml
supply-chaingithub-actionsleast-privilege
go/mode_empty.go:262
error_handlinglegacy
go/internal/flock/flock.go:13
error_handlinglegacy
java/src/main/java/com/github/copilot/rpc/ToolSet.java:112
qualitylegacy
rust/src/session_fs_dispatch.rs:22
qualitylegacy
java/src/main/java/com/github/copilot/rpc/ResumeSessionRequest.java:15
qualitylegacy
scripts/corrections/package.json
dependencylegacy
nodejs/package.json
dependencylegacy
nodejs/package.json
dependencylegacy
nodejs/package.json
dependencylegacy
java/scripts/codegen/package.json
dependencylegacy
nodejs/samples/package.json
dependencylegacy
scripts/codegen/package.json
dependencylegacy
scripts/docs-validation/package.json
dependencylegacy
nodejs/package.json
dependencylegacy
.github/workflows/copilot-setup-steps.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/copilot-setup-steps.yml:32
supply-chaingithub-actionspinned-dependencies
.github/workflows/copilot-setup-steps.yml:43
supply-chaingithub-actionspinned-dependencies
.github/workflows/copilot-setup-steps.yml:55
supply-chaingithub-actionspinned-dependencies
.github/workflows/copilot-setup-steps.yml:61
supply-chaingithub-actionspinned-dependencies
.github/workflows/copilot-setup-steps.yml:67
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:106
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:132
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:184
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:220
supply-chaingithub-actionspinned-dependencies
python/copilot/generated/rpc.py:18687
dead-code
python/copilot/generated/rpc.py:18706
dead-code
python/copilot/generated/rpc.py:18681
dead-code
python/copilot/generated/rpc.py:31
dead-code
python/copilot/client.py:3469
dead-code
python/copilot/generated/rpc.py:19119
dead-code
python/copilot/generated/rpc.py:19126
dead-code
python/copilot/generated/rpc.py:19105
dead-code
python/copilot/generated/rpc.py:19112
dead-code
python/copilot/generated/rpc.py:18656
dead-code
python/copilot/generated/rpc.py:18662
dead-code
python/copilot/generated/rpc.py:18700
dead-code
python/copilot/generated/rpc.py:18768
dead-code
python/copilot/_jsonrpc.py:216
dead-code
python/copilot/generated/rpc.py:18784
dead-code
python/copilot/generated/rpc.py:18748
dead-code
python/copilot/generated/rpc.py:17460
dead-code
python/copilot/generated/rpc.py:17463
dead-code
python/copilot/generated/rpc.py:18497
dead-code
python/copilot/generated/rpc.py:18758
dead-code
python/copilot/generated/rpc.py:18774
dead-code
python/copilot/generated/rpc.py:18719
dead-code
python/copilot/generated/rpc.py:17942
dead-code
python/copilot/client.py:2965
dead-code
python/copilot/client.py:2952
dead-code
python/copilot/generated/rpc.py:18650
dead-code
python/copilot/session_fs_provider.py:44
qualitylegacy
Showing first 300 of 303. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/5ef0a980-c2f9-417c-a367-43c5f959e224/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/5ef0a980-c2f9-417c-a367-43c5f959e224/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.