https://github.com/pnpm/pnpm
· scanned 2026-05-15 00:07 UTC (3 weeks ago)
· 10 languages
305 findings (23 legacy + 282 scanner) 56th percentile · Typescript · large (100-500K LoC) Scanner says 61 (higher by 15)
Last scanned 3 weeks ago · v1 · 20 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
87.7 | 0.25 | 21.93 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
75.0 | 0.15 | 11.25 |
practices_score |
75.0 | 0.15 | 11.25 |
code_quality |
64.5 | 0.10 | 6.45 |
| Overall | 1.00 | 75.9 |
authz: 1.2 ·
docker: 5.2 ·
threat: 6.0
Showing 18 of 20 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
releasing/commands/src/pack-app/packApp.ts:238
error_handlinglegacy
cli/default-reporter/src/reporterForClient/reportProgress.ts:112
error_handlinglegacy
building/during-install/src/index.ts:196
error_handlinglegacy
lockfile/fs/src/gitMergeFile.ts:15
deserializationlegacy
lockfile/fs/src/read.ts:114
deserializationlegacy
lockfile/fs/src/envLockfile.ts:33
deserializationlegacy
.dockerignore
dockerlegacy
docker/Dockerfile:5
dockerlegacy
agent/server/Dockerfile:6
dockerlegacy
installing/commands/src/installDeps.ts:196
qualitylegacy
global/commands/src/globalUpdate.ts:84
qualitylegacy
global/commands/src/globalUpdate.ts:78
qualitylegacy
global/commands/src/globalAdd.ts:77
qualitylegacy
engine/runtime/deno-resolver/src/index.ts:1
qualitylegacy
deps/compliance/commands/src/sbom/sbom.ts:26
qualitylegacy
auth/commands/src/logout.ts:7
qualitylegacy
agent/server/src/protocol.ts:8
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/7bb8abe5-b64a-4a6a-a079-91f6049c3769/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/7bb8abe5-b64a-4a6a-a079-91f6049c3769/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.