← Back to scan
File as GitHub Issue repo: axios/axios

Push this scan report to axios/axios

Click the green button below to open GitHub’s new-issue form, pre-filled with the report title, summary table, top findings, and an embedded score-card image. No authentication needed — you review on GitHub before submitting. Repobility is credited as the scanner.

Embedded score card image

This image will render at the top of the issue body. Hosted on Repobility, refreshes automatically after re-scans.

Repobility score card

Issue title

vm2: GHSA-v37h-5mfm-c47c

Curate findings to include

Pick exactly which findings appear in the issue body. By default the top 5 are included. Uncheck noise, check what matters.

Top 5 (default)
Severity Rule Title File:line
CRIT private-key Identified a Private Key, which may compromise cryptographic security and sensitive data … test/unit/adapters/key.pem:1
CRIT MINED127 Cryptominer signature: `stratum+tcp://` test/unit/helpers/parseProtocol.js:15
CRIT GHSA-vwrp-x96c-mhwq vm2: GHSA-vwrp-x96c-mhwq package-lock.json
CRIT GHSA-v6mx-mf47-r5wg vm2: GHSA-v6mx-mf47-r5wg package-lock.json
CRIT GHSA-v37h-5mfm-c47c vm2: GHSA-v37h-5mfm-c47c package-lock.json
CRIT GHSA-rp36-8xq3-r6c4 vm2: GHSA-rp36-8xq3-r6c4 package-lock.json
CRIT GHSA-qvjj-29qf-hp7p vm2: GHSA-qvjj-29qf-hp7p package-lock.json
CRIT GHSA-qcp4-v2jj-fjx8 vm2: GHSA-qcp4-v2jj-fjx8 package-lock.json
CRIT GHSA-grj5-jjm8-h35p vm2: GHSA-grj5-jjm8-h35p package-lock.json
CRIT GHSA-g644-9gfx-q4q4 vm2: GHSA-g644-9gfx-q4q4 package-lock.json
CRIT GHSA-cchq-frgv-rjh5 vm2: GHSA-cchq-frgv-rjh5 package-lock.json
CRIT GHSA-9vg3-4rfj-wgcm vm2: GHSA-9vg3-4rfj-wgcm package-lock.json
CRIT GHSA-9qj6-qjgg-37qq vm2: GHSA-9qj6-qjgg-37qq package-lock.json
CRIT GHSA-99p7-6v5w-7xg8 vm2: GHSA-99p7-6v5w-7xg8 package-lock.json
CRIT GHSA-8hg8-63c5-gwmx vm2: GHSA-8hg8-63c5-gwmx package-lock.json
CRIT GHSA-76w7-j9cq-rx2j vm2: GHSA-76w7-j9cq-rx2j package-lock.json
CRIT GHSA-6j2x-vhqr-qr7q vm2: GHSA-6j2x-vhqr-qr7q package-lock.json
CRIT GHSA-55hx-c926-fr95 vm2: GHSA-55hx-c926-fr95 package-lock.json
CRIT GHSA-47x8-96vw-5wg6 vm2: GHSA-47x8-96vw-5wg6 package-lock.json
CRIT GHSA-248r-7h7q-cr24 vm2: GHSA-248r-7h7q-cr24 package-lock.json
CRIT GHSA-95m3-7q98-8xr5 sha.js: GHSA-95m3-7q98-8xr5 package-lock.json
CRIT GHSA-v62p-rq8g-8h59 pbkdf2: GHSA-v62p-rq8g-8h59 package-lock.json
CRIT GHSA-h7cp-r72f-jxh6 pbkdf2: GHSA-h7cp-r72f-jxh6 package-lock.json
CRIT GHSA-2w6w-674q-4c4q handlebars: GHSA-2w6w-674q-4c4q package-lock.json
CRIT GHSA-fjxv-7rqg-78g4 form-data: GHSA-fjxv-7rqg-78g4 package-lock.json
CRIT GHSA-vjh7-7g9h-fjfh elliptic: GHSA-vjh7-7g9h-fjfh package-lock.json
CRIT GHSA-cpq7-6gpm-g9rc cipher-base: GHSA-cpq7-6gpm-g9rc package-lock.json
CRIT GHSA-5rq4-664w-9x2c basic-ftp: GHSA-5rq4-664w-9x2c package-lock.json
CRIT GHSA-67hx-6x53-jw92 babel-traverse: GHSA-67hx-6x53-jw92 package-lock.json
HIGH SEC040 [SEC040] innerHTML XSS — template literal with server-supplied data: Setting .innerHTML w… gulpfile.js:62
HIGH MINED115 Action `actions/setup-node` pinned to mutable ref `@v6` .github/workflows/publish.yml:20
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/publish.yml:18
HIGH MINED115 Action `peter-evans/create-pull-request` pinned to mutable ref `@v7` .github/workflows/update-sponsor-block.…:49
HIGH MINED115 Action `actions/setup-node` pinned to mutable ref `@v6` .github/workflows/update-sponsor-block.…:28
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/update-sponsor-block.…:20
HIGH MINED115 Action `github/codeql-action/analyze` pinned to mutable ref `@v4` .github/workflows/run-ci.yml:60
HIGH MINED115 Action `github/codeql-action/init` pinned to mutable ref `@v4` .github/workflows/run-ci.yml:54
HIGH MINED115 Action `actions/dependency-review-action` pinned to mutable ref `@v4` .github/workflows/run-ci.yml:51
HIGH MINED115 Action `actions/setup-node` pinned to mutable ref `@v6` .github/workflows/run-ci.yml:35
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/run-ci.yml:31
HIGH MINED115 Action `peter-evans/create-pull-request` pinned to mutable ref `@v7` .github/workflows/release-branch.yml:59
HIGH MINED115 Action `phips28/gh-action-bump-version` pinned to mutable ref `@v9` .github/workflows/release-branch.yml:40
HIGH MINED115 Action `actions/setup-node` pinned to mutable ref `@v6` .github/workflows/release-branch.yml:32
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/release-branch.yml:30
HIGH MINED122 package.json dep `axios` pulled from URL/Git test/module/typings/esm/package.json:1
HIGH MINED122 package.json dep `axios` pulled from URL/Git test/module/typings/cjs/package.json:1
HIGH MINED122 package.json dep `axios` pulled from URL/Git test/module/esm/package.json:1
HIGH MINED122 package.json dep `axios` pulled from URL/Git test/module/ts-require-default/package.…:1
HIGH MINED122 package.json dep `axios` pulled from URL/Git test/module/ts/package.json:1
HIGH MINED122 package.json dep `axios` pulled from URL/Git test/module/ts-require/package.json:1
HIGH MINED122 package.json dep `axios` pulled from URL/Git test/module/cjs/package.json:1
HIGH GHSA-3h5v-q93c-6h6q ws: GHSA-3h5v-q93c-6h6q package-lock.json
HIGH GHSA-r9pm-gxmw-wv6p vm2: GHSA-r9pm-gxmw-wv6p package-lock.json
HIGH GHSA-m5q2-4fm3-vfqp vm2: GHSA-m5q2-4fm3-vfqp package-lock.json
HIGH GHSA-hw58-p9xv-2mjh vm2: GHSA-hw58-p9xv-2mjh package-lock.json
HIGH GHSA-c4cf-2hgv-2qv6 vm2: GHSA-c4cf-2hgv-2qv6 package-lock.json
HIGH GHSA-6785-pvv7-mvg7 vm2: GHSA-6785-pvv7-mvg7 package-lock.json
HIGH GHSA-ph9p-34f9-6g65 tmp: GHSA-ph9p-34f9-6g65 package-lock.json
HIGH GHSA-r6q2-hw4h-h46w tar: GHSA-r6q2-hw4h-h46w package-lock.json
HIGH GHSA-qffp-2rhf-9h96 tar: GHSA-qffp-2rhf-9h96 package-lock.json
HIGH GHSA-9ppj-qmqm-q256 tar: GHSA-9ppj-qmqm-q256 package-lock.json
HIGH GHSA-8qq5-rm4j-mr97 tar: GHSA-8qq5-rm4j-mr97 package-lock.json
HIGH GHSA-83g3-92jg-28cx tar: GHSA-83g3-92jg-28cx package-lock.json
HIGH GHSA-5955-9wpr-37jh tar: GHSA-5955-9wpr-37jh package-lock.json
HIGH GHSA-3jfq-g458-7qm9 tar: GHSA-3jfq-g458-7qm9 package-lock.json
HIGH GHSA-34x7-hfp2-rc4v tar: GHSA-34x7-hfp2-rc4v package-lock.json
HIGH GHSA-677m-j7p3-52f9 socket.io-parser: GHSA-677m-j7p3-52f9 package-lock.json
HIGH GHSA-5c6j-r48x-rmvq serialize-javascript: GHSA-5c6j-r48x-rmvq package-lock.json
HIGH GHSA-44c6-4v22-4mhx semver-regex: GHSA-44c6-4v22-4mhx package-lock.json
HIGH GHSA-c2qf-rxjj-qqgw semver: GHSA-c2qf-rxjj-qqgw package-lock.json
HIGH GHSA-mw96-cpmx-2vgc rollup: GHSA-mw96-cpmx-2vgc package-lock.json
HIGH GHSA-gcx4-mw62-g8wm rollup: GHSA-gcx4-mw62-g8wm package-lock.json
HIGH GHSA-c2c7-rcm5-vvqj picomatch: GHSA-c2c7-rcm5-vvqj package-lock.json
HIGH GHSA-9wv6-86v2-598j path-to-regexp: GHSA-9wv6-86v2-598j package-lock.json
HIGH GHSA-rhx6-c78j-4q9w path-to-regexp: GHSA-rhx6-c78j-4q9w package-lock.json
HIGH GHSA-37ch-88jc-xwx2 path-to-regexp: GHSA-37ch-88jc-xwx2 package-lock.json
HIGH GHSA-q67f-28xg-22rw node-forge: GHSA-q67f-28xg-22rw package-lock.json
HIGH GHSA-ppp5-5v6c-4jwp node-forge: GHSA-ppp5-5v6c-4jwp package-lock.json
HIGH GHSA-5m6q-g25r-mvwx node-forge: GHSA-5m6q-g25r-mvwx package-lock.json
HIGH GHSA-2328-f5f3-gj25 node-forge: GHSA-2328-f5f3-gj25 package-lock.json
HIGH GHSA-xf7r-hgr6-v32p multer: GHSA-xf7r-hgr6-v32p package-lock.json
HIGH GHSA-v52c-386h-88mc multer: GHSA-v52c-386h-88mc package-lock.json
HIGH GHSA-g5hg-p3ph-g8qg multer: GHSA-g5hg-p3ph-g8qg package-lock.json
HIGH GHSA-fjgf-rc76-4x9p multer: GHSA-fjgf-rc76-4x9p package-lock.json
HIGH GHSA-5528-5vmv-3xc2 multer: GHSA-5528-5vmv-3xc2 package-lock.json
HIGH GHSA-4pg4-qvpc-4q3h multer: GHSA-4pg4-qvpc-4q3h package-lock.json
HIGH GHSA-44fp-w29j-9vj5 multer: GHSA-44fp-w29j-9vj5 package-lock.json
HIGH GHSA-7r86-cg39-jmmj minimatch: GHSA-7r86-cg39-jmmj package-lock.json
HIGH GHSA-3ppc-4f35-3m26 minimatch: GHSA-3ppc-4f35-3m26 package-lock.json
HIGH GHSA-23c5-xmqv-rm74 minimatch: GHSA-23c5-xmqv-rm74 package-lock.json
HIGH GHSA-r5fr-rjxr-66jc lodash: GHSA-r5fr-rjxr-66jc package-lock.json
HIGH GHSA-2p57-rm9w-gvfp ip: GHSA-2p57-rm9w-gvfp package-lock.json
HIGH GHSA-rc47-6667-2j5j http-cache-semantics: GHSA-rc47-6667-2j5j package-lock.json
HIGH GHSA-xjpj-3mr7-gcpf handlebars: GHSA-xjpj-3mr7-gcpf package-lock.json
HIGH GHSA-xhpv-hc6g-r9c6 handlebars: GHSA-xhpv-hc6g-r9c6 package-lock.json
HIGH GHSA-9cx6-37pm-9jff handlebars: GHSA-9cx6-37pm-9jff package-lock.json
HIGH GHSA-3mfm-83xf-c92r handlebars: GHSA-3mfm-83xf-c92r package-lock.json
HIGH GHSA-5j98-mcp5-4vw2 glob: GHSA-5j98-mcp5-4vw2 package-lock.json
HIGH GHSA-rf6f-7fwh-wjgh flatted: GHSA-rf6f-7fwh-wjgh package-lock.json
HIGH GHSA-25h7-pfq9-p65f flatted: GHSA-25h7-pfq9-p65f package-lock.json
HIGH GHSA-wm7h-9275-46v2 dicer: GHSA-wm7h-9275-46v2 package-lock.json
HIGH GHSA-3xgq-45jj-v275 cross-spawn: GHSA-3xgq-45jj-v275 package-lock.json
HIGH GHSA-x9w5-v3q2-3rhw browserify-sign: GHSA-x9w5-v3q2-3rhw package-lock.json
HIGH GHSA-grv7-fg5c-xmjg braces: GHSA-grv7-fg5c-xmjg package-lock.json
HIGH GHSA-rpmf-866q-6p89 basic-ftp: GHSA-rpmf-866q-6p89 package-lock.json
HIGH GHSA-rp42-5vxx-qpwr basic-ftp: GHSA-rp42-5vxx-qpwr package-lock.json
HIGH GHSA-6v7q-wjvx-w8wg basic-ftp: GHSA-6v7q-wjvx-w8wg package-lock.json
HIGH GHSA-fv7c-fp4j-7gwp @babel/plugin-transform-modules-systemjs: GHSA-fv7c-fp4j-7gwp package-lock.json
HIGH MINED113 Express POST / has no auth test/unit/adapters/http.js:1789
HIGH MINED113 Express POST / has no auth test/unit/adapters/http.js:1730
MED AUC001 [AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks…
MED DEPCUR-NPM npm package `gulp` is 1 major version(s) behind (4.0.2 -> 5.0.1) package.json
MED DEPCUR-NPM npm package `get-stream` is 3 major version(s) behind (6.0.1 -> 9.0.1) package.json
MED DEPCUR-NPM npm package `formidable` is 1 major version(s) behind (2.1.2 -> 3.5.4) package.json
MED DEPCUR-NPM npm package `formdata-node` is 1 major version(s) behind (5.0.1 -> 6.0.3) package.json
MED DEPCUR-NPM npm package `express` is 1 major version(s) behind (4.21.1 -> 5.2.1) package.json
MED DEPCUR-NPM npm package `cross-env` is 3 major version(s) behind (7.0.3 -> 10.1.0) package.json
MED DEPCUR-NPM npm package `chalk` is 3 major version(s) behind (2.4.2 -> 5.6.2) package.json
MED DEPCUR-NPM npm package `c8` is 1 major version(s) behind (10.1.3 -> 11.0.0) package.json
MED DEPCUR-NPM npm package `body-parser` is 1 major version(s) behind (1.20.3 -> 2.2.2) package.json
MED DEPCUR-NPM npm package `@rollup/plugin-node-resolve` is 7 major version(s) behind (9.0.0 -> 16.0.3) package.json
MED DEPCUR-NPM npm package `@rollup/plugin-multi-entry` is 3 major version(s) behind (4.1.0 -> 7.1.0) package.json
MED DEPCUR-NPM npm package `@rollup/plugin-json` is 2 major version(s) behind (4.1.0 -> 6.1.0) package.json
MED DEPCUR-NPM npm package `@rollup/plugin-commonjs` is 14 major version(s) behind (15.1.0 -> 29.0.3) package.json
MED DEPCUR-NPM npm package `@rollup/plugin-babel` is 2 major version(s) behind (5.3.1 -> 7.1.0) package.json
MED DEPCUR-NPM npm package `@rollup/plugin-alias` is 1 major version(s) behind (5.1.0 -> 6.0.0) package.json
MED DEPCUR-NPM npm package `@release-it/conventional-changelog` is 6 major version(s) behind (5.1.1 -> 1… package.json
MED DEPCUR-NPM npm package `@commitlint/config-conventional` is 4 major version(s) behind (17.8.1 -> 21.… package.json
MED DEPCUR-NPM npm package `@commitlint/cli` is 4 major version(s) behind (17.8.1 -> 21.0.2) package.json
MED DEPCUR-NPM npm package `proxy-from-env` is 1 major version(s) behind (1.1.0 -> 2.1.0) package.json
MED GHSA-58qx-3vcg-4xpx ws: GHSA-58qx-3vcg-4xpx package-lock.json
MED GHSA-wp5r-2gw5-m7q7 vm2: GHSA-wp5r-2gw5-m7q7 package-lock.json
MED GHSA-v27g-jcqj-v8rw vm2: GHSA-v27g-jcqj-v8rw package-lock.json
MED GHSA-mpf8-4hx2-7cjg vm2: GHSA-mpf8-4hx2-7cjg package-lock.json
MED GHSA-9g8x-92q2-p28f vm2: GHSA-9g8x-92q2-p28f package-lock.json
MED GHSA-2cm2-m3w5-gp2f vm2: GHSA-2cm2-m3w5-gp2f package-lock.json
MED GHSA-w5hq-g745-h8pq uuid: GHSA-w5hq-g745-h8pq package-lock.json
MED GHSA-72xf-g2v4-qvf3 tough-cookie: GHSA-72xf-g2v4-qvf3 package-lock.json
MED GHSA-f5x3-32g6-xq36 tar: GHSA-f5x3-32g6-xq36 package-lock.json
MED GHSA-qj8w-gfj5-8c6v serialize-javascript: GHSA-qj8w-gfj5-8c6v package-lock.json
MED GHSA-76p7-773f-r4q5 serialize-javascript: GHSA-76p7-773f-r4q5 package-lock.json
MED GHSA-p8p7-x288-28g6 request: GHSA-p8p7-x288-28g6 package-lock.json
MED GHSA-q8mj-m7cp-5q26 qs: GHSA-q8mj-m7cp-5q26 package-lock.json
MED GHSA-6rw7-vpxm-498p qs: GHSA-6rw7-vpxm-498p package-lock.json
MED GHSA-3v7f-55p6-f55p picomatch: GHSA-3v7f-55p6-f55p package-lock.json
MED GHSA-952p-6rrq-rcjv micromatch: GHSA-952p-6rrq-rcjv package-lock.json
MED GHSA-xxjr-mmjv-4gpg lodash: GHSA-xxjr-mmjv-4gpg package-lock.json
MED GHSA-f23m-r3pf-42rh lodash: GHSA-f23m-r3pf-42rh package-lock.json
MED GHSA-mh29-5h37-fv8m js-yaml: GHSA-mh29-5h37-fv8m package-lock.json
MED GHSA-v2v4-37r5-5v8g ip-address: GHSA-v2v4-37r5-5v8g package-lock.json
MED GHSA-7rx3-28cr-v5wh handlebars: GHSA-7rx3-28cr-v5wh package-lock.json
MED GHSA-2qvq-rjwj-gvw9 handlebars: GHSA-2qvq-rjwj-gvw9 package-lock.json
MED GHSA-pfrx-2q88-qq97 got: GHSA-pfrx-2q88-qq97 package-lock.json
MED GHSA-r4q5-vmmm-2653 follow-redirects: GHSA-r4q5-vmmm-2653 package-lock.json
MED GHSA-f886-m6hf-6m8v brace-expansion: GHSA-f886-m6hf-6m8v package-lock.json
MED GHSA-378v-28hj-76wf bn.js: GHSA-378v-28hj-76wf package-lock.json
MED GHSA-v88g-cgmw-v5xw ajv: GHSA-v88g-cgmw-v5xw package-lock.json
MED GHSA-2g4f-4pwh-qvx6 ajv: GHSA-2g4f-4pwh-qvx6 package-lock.json
MED GHSA-xx4v-prfh-6cgc @octokit/request-error: GHSA-xx4v-prfh-6cgc package-lock.json
MED GHSA-rmvr-2pp2-xj38 @octokit/request: GHSA-rmvr-2pp2-xj38 package-lock.json
MED GHSA-h5c3-5r3r-rr8q @octokit/plugin-paginate-rest: GHSA-h5c3-5r3r-rr8q package-lock.json
MED GHSA-968p-4wvh-cqc8 @babel/runtime: GHSA-968p-4wvh-cqc8 package-lock.json
MED GHSA-968p-4wvh-cqc8 @babel/helpers: GHSA-968p-4wvh-cqc8 package-lock.json
MED WEB003 Public web service has no security.txt .well-known/security.txt
LOW DEPCUR-NPM npm package `fs-extra` is minor version(s) behind (11.2.0 -> 11.3.5) package.json
LOW DEPCUR-NPM npm package `auto-changelog` is minor version(s) behind (2.4.0 -> 2.6.0) package.json
LOW DEPCUR-NPM npm package `@babel/preset-env` is minor version(s) behind (7.23.9 -> 7.29.7) package.json
LOW DEPCUR-NPM npm package `@babel/core` is minor version(s) behind (7.23.9 -> 7.29.7) package.json
LOW DEPCUR-NPM npm package `follow-redirects` is minor version(s) behind (1.15.11 -> 1.16.0) package.json
LOW GHSA-q3fm-4wcw-g57x vm2: GHSA-q3fm-4wcw-g57x package-lock.json
LOW GHSA-52f5-9888-hmc6 tmp: GHSA-52f5-9888-hmc6 package-lock.json
LOW GHSA-4x5v-gmq8-25ch semver-regex: GHSA-4x5v-gmq8-25ch package-lock.json
LOW GHSA-w7fw-mjwx-w883 qs: GHSA-w7fw-mjwx-w883 package-lock.json
LOW GHSA-78xj-cgh5-2h22 ip: GHSA-78xj-cgh5-2h22 package-lock.json
LOW GHSA-442j-39wm-28r2 handlebars: GHSA-442j-39wm-28r2 package-lock.json
LOW GHSA-75v8-2h7p-7m2m formidable: GHSA-75v8-2h7p-7m2m package-lock.json
LOW GHSA-4gmj-3p3h-gm8h es5-ext: GHSA-4gmj-3p3h-gm8h package-lock.json
LOW GHSA-848j-6mx2-7j84 elliptic: GHSA-848j-6mx2-7j84 package-lock.json
LOW GHSA-73rr-hh4g-fpgx diff: GHSA-73rr-hh4g-fpgx package-lock.json
LOW GHSA-v6h2-p8h4-qcjw brace-expansion: GHSA-v6h2-p8h4-qcjw package-lock.json
LOW AIC003 Duplicated implementation block across source files test/module/typings/esm/index.ts:76
LOW AIC003 Duplicated implementation block across source files test/module/ts/index.ts:3
LOW AIC003 Duplicated implementation block across source files test/module/ts-require/index.ts:4
LOW AIC003 Duplicated implementation block across source files test/module/ts-require/index.ts:3
LOW AIC003 Duplicated implementation block across source files test/module/ts-require/index.js:4
LOW AIC003 Duplicated implementation block across source files test/module/ts-require-default/index.ts:4
LOW WEB005 robots.txt does not advertise a sitemap README.md
INFO MINED044 [MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger … examples/server.js:101
INFO MINED044 [MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger … examples/postMultipartFormData/server.js:7
INFO MINED044 [MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger … examples/post/server.js:9
INFO DEPCUR-NPM npm package `abortcontroller-polyfill` is patch version(s) behind (1.7.5 -> 1.7.8) package.json
Reset to top 5 191 findings available (after auto-suppression of test files + won't-fix)

Issue body (markdown)

## Code-quality scan: `axios/axios`

**Score: 78/100 (B+)**  ·  191 findings  ·  scanned 2026-06-05 04:17 UTC  ·  17,901 LOC

| Severity | Count |
|---|---|
| CRITICAL | 29 |
| HIGH | 81 |
| MEDIUM | 54 |
| LOW | 23 |

📊 [Full filterable report](https://repobility.com/scan/638bbbc9-da12-4b15-a037-c1489534a330/)  ·  ![scorecard](https://repobility.com/scan/638bbbc9-da12-4b15-a037-c1489534a330/report.png?v=1780633050-s2)

### Top findings

1. **CRITICAL** `private-key` — Identified a Private Key, which may compromise cryptographic security and sensitive data e
   `test/unit/adapters/key.pem:1`
2. **CRITICAL** `MINED127` — Cryptominer signature: `stratum+tcp://`
   `test/unit/helpers/parseProtocol.js:15` · ✓ Repobility
3. **CRITICAL** `GHSA-vwrp-x96c-mhwq` — vm2: GHSA-vwrp-x96c-mhwq
   `package-lock.json`
4. **CRITICAL** `GHSA-v6mx-mf47-r5wg` — vm2: GHSA-v6mx-mf47-r5wg
   `package-lock.json`
5. **CRITICAL** `GHSA-v37h-5mfm-c47c` — vm2: GHSA-v37h-5mfm-c47c
   `package-lock.json`

---

_Filed automatically. Close this issue if not useful — we won't refile. Full report: https://repobility.com/scan/638bbbc9-da12-4b15-a037-c1489534a330/_
Already filed
This repo publishes a SECURITY.md policy and the scan contains 1 Critical/High security finding(s). Public issue filing would violate coordinated disclosure. Submit privately via the project's security reporting channel.
Megaproject â high spam risk
Could not determine 'axios/axios' star count (GitHub API rate-limited or unreachable). When in doubt about repo size, prefer opening a focused PR or a discussion rather than an issue.

The button opens GitHubâs new-issue page in a new tab. You will see the title + body pre-filled â review, edit if you want, then click GitHubâs "Submit new issue" button. Repobility never posts anything on your behalf.

For real security findings on big repos: use the project's SECURITY.md or private advisory flow instead of a public issue.