Scan timing: clone 13.3s · analysis 27.67s · 36.1 MB · GitHub API rate-limit (preflight)
https://github.com/facebook/react
· scanned 2026-06-05 04:28 UTC (4 hours, 36 minutes ago)
· 10 languages
2383 findings (123 legacy + 2260 scanner) 11/13 scanners ran 89th percentile · Javascript · large (100-500K LoC) Scanner says 41 (higher by 50)
Last scanned 4 hours, 36 minutes ago · v2 · 1253 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
99.0 | 0.15 | 14.85 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 90.8 |
Showing 571 of 1253 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/react-client/src/ReactClientDebugConfigNode.js:20
qualitylegacy
packages/react-client/src/ReactClientDebugConfigBrowser.js:20
qualitylegacy
compiler/packages/snap/src/sprout/evaluator.ts:255
qualitylegacy
compiler/packages/react-mcp-server/src/utils/algolia.ts:14
secrets
packages/react-server/src/ReactServerStreamConfigNode.js:239
qualitylegacy
compiler/packages/babel-plugin-react-compiler/src/SSA/EnterSSA.ts:159
qualitylegacy
compiler/packages/babel-plugin-react-compiler/src/ReactiveScopes/PruneHoistedContexts.ts:66
qualitylegacy
compiler/packages/babel-plugin-react-compiler/src/HIR/FindContextIdentifiers.ts:40
qualitylegacy
fixtures/flight/server/region.js:203
qualitylegacy
fixtures/flight-esm/server/region.js:48
qualitylegacy
.github/workflows/compiler_playground.yml:31
dependencylegacy
.github/workflows/compiler_playground.yml:32
dependencylegacy
.github/workflows/devtools_discord_notify.yml:28
dependencylegacy
.github/workflows/compiler_discord_notify.yml:28
dependencylegacy
fixtures/eslint-v10/package.json:1
dependencylegacy
fixtures/eslint-v8/package.json:1
dependencylegacy
fixtures/eslint-v7/package.json:1
dependencylegacy
fixtures/eslint-v6/package.json:1
dependencylegacy
fixtures/eslint-v9/package.json:1
dependencylegacy
package.json:1
dependencylegacy
scripts/jest/jest-cli.js:383
xsslegacy
scripts/ci/download_devtools_regression_build.js:43
xsslegacy
packages/react-devtools-core/src/standalone.js:193
xsslegacy
packages/react-devtools-shared/src/devtools/views/utils.js:45
qualitylegacy
packages/eslint-plugin-react-hooks/src/shared/Utils.ts:18
qualitylegacy
compiler/scripts/enable-feature-flag.js:69
qualitylegacy
compiler/packages/react-compiler-healthcheck/src/checks/reactCompiler.ts:137
qualitylegacy
compiler/packages/react-compiler-healthcheck/src/checks/libraryCompat.ts:16
qualitylegacy
.github/workflows/compiler_discord_notify.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/devtools_discord_notify.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/runtime_discord_notify.yml:30
supply-chaingithub-actionspinned-dependencies
.github/workflows/compiler_prereleases_nightly.yml:16
supply-chaingithub-actionspinned-dependencies
.github/workflows/compiler_prereleases_manual.yml:32
supply-chaingithub-actionspinned-dependencies
.github/workflows/shared_label_core_team_prs.yml:29
supply-chaingithub-actionspinned-dependencies
compiler/packages/snap/src/sprout/evaluator.ts:255
owaspeval_used
fixtures/fiber-debugger/src/App.js:122
owaspeval_used
packages/react-devtools-extensions/src/evalScripts.js:20
owaspeval_used
packages/react-devtools-extensions/deploy.js:43
owaspexec_used
scripts/bench/build.js:18
owaspexec_used
scripts/ci/download_devtools_regression_build.js:40
owaspexec_used
scripts/devtools/prepare-release.js:85
owaspexec_used
scripts/devtools/publish-release.js:107
owaspexec_used
scripts/devtools/utils.js:90
owaspexec_used
scripts/release/build-release-locally-commands/build-artifacts.js:15
owaspexec_used
scripts/release/build-release-locally-commands/copy-repo-to-temp-directory.js:19
owaspexec_used
scripts/release/build-release-locally-commands/npm-pack-and-unpack.js:13
owaspexec_used
scripts/release/shared-commands/download-build-artifacts.js:26
owaspexec_used
scripts/release/utils.js:45
owaspexec_used
scripts/rollup/utils.js:31
owaspexec_used
scripts/shared/listChangedFiles.js:40
owaspexec_used
packages/react-devtools-shared/src/devtools/views/Components/Components.js:194
error_handlinglegacy
packages/react-devtools-shared/src/backend/shared/DevToolsComponentStackFrame.js:176
error_handlinglegacy
packages/react-devtools-shared/src/devtools/views/UnsupportedBridgeProtocolDialog.js:137
securitylegacy
packages/react-devtools-shared/src/devtools/views/Editor/OpenInEditorButton.js:66
securitylegacy
packages/react-devtools-shared/src/devtools/views/Components/OpenInEditorButton.js:41
securitylegacy
packages/react-dom-bindings/src/client/ReactDOMSelection.js:38
qualitylegacy
packages/react-devtools-shared/src/symbolicateSource.js:89
qualitylegacy
packages/react-devtools-shared/src/storage.js:13
qualitylegacy
.github/workflows/runtime_commit_artifacts.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/shared_close_direct_sync_branch_prs.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/runtime_release_from_ci.yml
supply-chaingithub-actionsleast-privilege
fixtures/attribute-behavior/src/attributes.js:398
owaspdangerous_innerhtml
fixtures/fizz/src/Html.js:21
owaspdangerous_innerhtml
fixtures/ssr/src/components/Chrome.js:24
owaspdangerous_innerhtml
fixtures/ssr2/src/Html.js:21
owaspdangerous_innerhtml
fixtures/view-transition/src/components/Chrome.js:29
owaspdangerous_innerhtml
packages/react-dom-bindings/src/client/ReactDOMComponent.js:637
owaspdangerous_innerhtml
packages/react-dom-bindings/src/client/ReactDOMOption.js:44
owaspdangerous_innerhtml
packages/react-dom-bindings/src/client/ReactFiberConfigDOM.js:164
owaspdangerous_innerhtml
packages/react-dom-bindings/src/server/ReactFizzConfigDOM.js:1623
owaspdangerous_innerhtml
packages/react-dom-bindings/src/shared/possibleStandardNames.js:49
owaspdangerous_innerhtml
packages/react-dom-bindings/src/shared/ReactDOMUnknownPropertyHook.js:104
owaspdangerous_innerhtml
scripts/error-codes/codes.json:61
owaspdangerous_innerhtml
.github/workflows/compiler_prereleases_nightly.yml
securityports
packages/react-markup/src/ReactFizzConfigMarkup.js:126
qualitylegacy
packages/react-flight-server-fb/src/client/ReactFlightClientConfigBundlerFB.js:204
qualitylegacy
packages/react-devtools-extensions/edge/build.js:32
qualitylegacy
packages/react-devtools-inline/webpack.config.js:77
qualitylegacy
packages/react-devtools-inline/webpack.config.js:13
qualitylegacy
packages/react-devtools-inline/webpack.config.js:1
qualitylegacy
packages/react-devtools-fusebox/webpack.config.frontend.js:85
qualitylegacy
packages/react-devtools-fusebox/webpack.config.frontend.js:9
qualitylegacy
packages/react-devtools-extensions/webpack.config.js:80
qualitylegacy
packages/react-devtools-extensions/webpack.config.js:9
qualitylegacy
packages/react-devtools-core/webpack.standalone.js:1
qualitylegacy
packages/react-client/src/forks/ReactFlightClientConfig.noop.js:2
qualitylegacy
packages/react-client/src/ReactFlightClientStreamConfigWeb.js:1
qualitylegacy
packages/react-client/src/ReactClientConsoleConfigServer.js:2
qualitylegacy
packages/react-client/src/ReactClientConsoleConfigPlain.js:2
qualitylegacy
packages/eslint-plugin-react-hooks/src/shared/RunReactCompiler.ts:111
qualitylegacy
packages/eslint-plugin-react-hooks/src/shared/ReactCompiler.ts:13
qualitylegacy
compiler/packages/snap/src/runner.ts:195
qualitylegacy
compiler/packages/react-mcp-server/src/compiler/index.ts:36
qualitylegacy
compiler/packages/react-compiler-healthcheck/tsup.config.ts:12
qualitylegacy
compiler/packages/babel-plugin-react-compiler/src/Validation/ValidateNoSetStateInEffects.ts:227
qualitylegacy
compiler/packages/babel-plugin-react-compiler/src/Validation/ValidateNoDerivedComputationsInEffects_exp.ts:387
qualitylegacy
.github/workflows/compiler_playground.yml:36
supply-chaingithub-actionspinned-dependencies
.github/workflows/compiler_playground.yml:52
supply-chaingithub-actionspinned-dependencies
.github/workflows/compiler_playground.yml:63
supply-chaingithub-actionspinned-dependencies
.github/workflows/runtime_eslint_plugin_e2e.yml:41
supply-chaingithub-actionspinned-dependencies
.github/workflows/runtime_commit_artifacts.yml:41
supply-chaingithub-actionspinned-dependencies
.github/workflows/runtime_commit_artifacts.yml:59
supply-chaingithub-actionspinned-dependencies
.github/workflows/runtime_commit_artifacts.yml:109
supply-chaingithub-actionspinned-dependencies
.github/workflows/runtime_commit_artifacts.yml:363
supply-chaingithub-actionspinned-dependencies
.github/workflows/shared_close_direct_sync_branch_prs.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/compiler_typescript.yml:49
supply-chaingithub-actionspinned-dependencies
.github/workflows/compiler_typescript.yml:69
supply-chaingithub-actionspinned-dependencies
.github/workflows/compiler_typescript.yml:93
supply-chaingithub-actionspinned-dependencies
.github/workflows/runtime_release_from_ci.yml:141
supply-chaingithub-actionspinned-dependencies
.github/workflows/shared_check_maintainer.yml:31
supply-chaingithub-actionspinned-dependencies
.github/workflows/shared_lint.yml:29
supply-chaingithub-actionspinned-dependencies
.github/workflows/shared_lint.yml:50
supply-chaingithub-actionspinned-dependencies
.github/workflows/shared_lint.yml:71
supply-chaingithub-actionspinned-dependencies
.github/workflows/shared_lint.yml:92
supply-chaingithub-actionspinned-dependencies
.github/workflows/compiler_prereleases.yml:51
supply-chaingithub-actionspinned-dependencies
.github/workflows/shared_label_core_team_prs.yml:47
supply-chaingithub-actionspinned-dependencies
packages/react-devtools-shell/src/app/Iframe/index.js:44
owaspdocument_write
package.json
supply-chainnpminstall-scripts
compiler/apps/playground/package.json
supply-chainnpminstall-scripts
compiler/packages/react-forgive/package.json
supply-chainnpminstall-scripts
compiler/packages/snap/package.json
supply-chainnpminstall-scripts
fixtures/nesting/package.json
supply-chainnpminstall-scripts
Showing first 300 of 571. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/71490123-d37f-4659-ac2a-5b9a11374c25/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/71490123-d37f-4659-ac2a-5b9a11374c25/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.