Scan timing: clone 13.3s · analysis 27.67s · 36.1 MB · GitHub API rate-limit (preflight)
https://github.com/facebook/react
· scanned 2026-06-05 04:28 UTC (11 hours, 50 minutes ago)
· 10 languages
2383 findings (123 legacy + 2260 scanner) 11/13 scanners ran 88th percentile · Javascript · large (100-500K LoC) Scanner says 41 (higher by 50)
Last scanned 11 hours, 50 minutes ago · v2 · 1253 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
99.0 | 0.15 | 14.85 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 90.8 |
Bug-class explainers. Each card groups findings of the same shape — these are the patterns most likely to ship to prod and reappear in future scans unless you systematically fix the cause, not just the instance.
packages/react-dom-bindings/src/client/ReactDOMSe…:38
packages/react-devtools-shared/src/symbolicateSou…:89
packages/react-devtools-shared/src/storage.js:13
packages/react-devtools-shared/src/devtools/views…:194
packages/react-devtools-shared/src/backend/shared…:176
packages/internal-test-utils/internalAct.js:273
packages/react-devtools-shared/src/devtools/views…:45
packages/react-devtools-shared/src/devtools/views…:45
packages/react-devtools-inline/webpack.config.js:77
packages/react-devtools-inline/webpack.config.js:13
packages/react-devtools-inline/webpack.config.js:1
packages/react-devtools-fusebox/webpack.config.fr…:85
This page is publicly accessible at:
https://repobility.com/scan/71490123-d37f-4659-ac2a-5b9a11374c25/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/71490123-d37f-4659-ac2a-5b9a11374c25/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.