Scan timing: clone 4.12s · analysis 21.99s · 17.8 MB · GitHub API rate-limit (preflight)
https://github.com/github/copilot-sdk
· scanned 2026-06-04 23:18 UTC (15 hours, 27 minutes ago)
· 10 languages
1079 findings (223 legacy + 856 scanner) 0th percentile · Java · large (100-500K LoC) Scanner says 80 (lower by 14)
Last scanned 15 hours, 27 minutes ago · v4 · 437 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
34.6 | 0.25 | 8.65 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
82.0 | 0.15 | 12.30 |
code_quality |
44.7 | 0.10 | 4.47 |
| Overall | 1.00 | 66.4 |
Showing 21 of 437 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
python/scripts/build-wheels.mjs:258
path_traversallegacy
nodejs/package.json
dependencylegacy
.github/workflows/docs-validation.yml:64
supply-chaingithub-actionspinned-dependencies
.github/workflows/copilot-setup-steps.yml:49
supply-chaingithub-actionspinned-dependencies
.github/workflows/copilot-setup-steps.yml:75
supply-chaingithub-actionspinned-dependencies
.github/workflows/update-copilot-dependency.yml:48
supply-chaingithub-actionspinned-dependencies
.github/workflows/codegen-check.yml:43
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:140
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:165
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:211
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:226
supply-chaingithub-actionspinned-dependencies
.github/workflows/java-codegen-fix.lock.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release-changelog.lock.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/java-publish-maven.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/update-copilot-dependency.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/java-adapt-handwritten-code-to-accept-upgrade-changes.lock.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/java-codegen-check.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/publish.yml
supply-chaingithub-actionsleast-privilege
This page is publicly accessible at:
https://repobility.com/scan/5ef0a980-c2f9-417c-a367-43c5f959e224/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/5ef0a980-c2f9-417c-a367-43c5f959e224/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.