https://github.com/tauri-apps/tauri
· scanned 2026-06-05 05:49 UTC (1 week, 1 day ago)
· 10 languages
322 raw signals (82 security + 240 graph) 11/13 scanners ran 32nd percentile · Rust · medium (20-100K LoC) System graph score 66 (lower by 2)
Last scanned 1 week, 1 day ago · v2 · 92 actionable findings from 2 signal sources. 110 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
16.0 | 0.20 | 3.20 |
documentation_score |
65.0 | 0.15 | 9.75 |
practices_score |
69.0 | 0.15 | 10.35 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 64.3 |
Showing 68 of 92 actionable findings. 202 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/bench.yml:78
CI/CD securityworkflow secretsGitHub Actions
packages/api/src/core.ts:241
crates/tauri/mobile/android/src/main/java/app/tauri/AppPlugin.kt:32crates/tauri/mobile/android/src/main/java/app/tauri/FsUtils.kt:141crates/tauri/mobile/android/src/main/java/app/tauri/plugin/PluginManager.kt:68crates/tauri-cli/templates/plugin/__example-api/tauri-app/package.json:1
.github/workflows/publish-cli-js.yml:285
.github/workflows/bench.yml:41
CI/CD securitySupply chainGithub actions
crates/tauri/src/ipc/channel.rs:158
Eval used
crates/tauri/src/ipc/protocol.rs:334
Eval used
crates/tauri/src/manager/webview.rs:672
Eval used
crates/tauri-cli/src/mobile/init.rs:36
Exec used
.github/workflows/publish-cli-js.yml:172
.github/workflows/docker.yml:23, 65, 88, 91, 94, 101, 125 (9 hits).github/workflows/publish-cli-rs.yml:52, 55, 69 (5 hits).github/workflows/fmt.yml:18, 44, 47 (3 hits).github/workflows/covector-version-or-publish.yml:33, 94 (2 hits).github/workflows/publish-cli-js.yml:119, 135 (2 hits).github/workflows/test-android.yml:37, 59 (2 hits).github/workflows/udeps.yml:80, 131 (2 hits).github/workflows/audit.yml:38.github/workflows/publish-cli-js.yml
CI/CD securitySupply chainGithub actions
.github/workflows/covector-version-or-publish.yml
CI/CD securitySupply chainGithub actions
crates/tauri-cli/config.schema.json:2678
Weak hash
crates/tauri-cli/schema.json:2071
Weak hash
crates/tauri-cli/tauri.config.schema.json:2076
Weak hash
crates/tauri-schema-generator/schemas/config.schema.json:2678
Weak hash
crates/tauri-cli/src/mobile/ios/dev.rs:42, 155 (2 hits)crates/tauri-cli/src/mobile/ios/run.rs:14, 27 (2 hits)crates/tauri-bundler/src/utils/fs_utils.rs:73crates/tauri-cli/src/error.rs:28crates/tauri-cli/src/mobile/ios/build.rs:93crates/tauri-cli/src/mobile/ios/xcode_script.rs:62crates/tauri-cli/src/plugin/ios.rs:15crates/tauri-runtime/build.rs:1.devcontainer/Dockerfile:4
containersPinned dependencies
.github/workflows/docker.yml:20, 34, 44, 62, 71, 76, 82 (13 hits).github/workflows/publish-cli-js.yml:112, 148, 222, 229, 253, 260, 290, 297, +4 more (12 hits).github/workflows/publish-cli-rs.yml:48, 90, 102, 105 (7 hits).github/workflows/lint-js.yml:21, 23, 33, 35 (4 hits).github/workflows/bench.yml:48, 76 (2 hits).github/workflows/udeps.yml:86, 141 (2 hits).github/workflows/check-license-header.yml:18.github/workflows/covector-status.yml:13
This page is publicly accessible at:
https://repobility.com/scan/6a9bdf8b-9ece-4780-bdf2-3db6f0001b42/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/6a9bdf8b-9ece-4780-bdf2-3db6f0001b42/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.