Scan timing: clone 3.15s · analysis 6.4s · 1.3 MB · GitHub preflight 478ms
https://github.com/nvm-sh/nvm
· scanned 2026-06-05 06:51 UTC (6 days ago)
· 10 languages
116 raw signals (60 security + 56 graph) 95th percentile · Javascript · tiny (<2K LoC)
Last scanned 6 days ago · v2 · 28 actionable findings from 2 signal sources. 60 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
97.5 | 0.25 | 24.38 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
75.0 | 0.15 | 11.25 |
practices_score |
91.0 | 0.15 | 13.65 |
code_quality |
75.8 | 0.10 | 7.58 |
| Overall | 1.00 | 83.6 |
Showing 24 of 28 actionable findings. 88 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
Dockerfile:8
.github/workflows/lint.yml:20, 39, 56 (3 hits).github/workflows/rebase.yml:15.github/workflows/lint.yml:19, 38, 55, 70 (4 hits).github/workflows/codeql-analysis.yml:24 (2 hits).github/workflows/nvm-install-test.yml:24, 65 (2 hits).github/workflows/toc.yml:24, 32 (2 hits).github/workflows/rebase.yml:14.github/workflows/codeql-analysis.yml:30, 38, 52 (6 hits).github/workflows/windows-npm.yml:139, 147, 217 (5 hits).github/workflows/lint.yml:12, 29, 48, 65 (4 hits).github/workflows/toc.yml:18, 38 (3 hits).github/workflows/latest-npm.yml:15, 58 (2 hits).github/workflows/nodejs-org.yml:26.github/workflows/release.yml:13.github/workflows/shellcheck.yml:31.github/workflows/shellcheck.yml:40
CI/CD securitySupply chainGithub actions
Dockerfile:85
CI/CD securitycontainers
Dockerfile:106
CI/CD securitycontainers
.github/workflows/windows-npm.yml:139
.github/workflows/windows-npm.yml:45
.github/workflows/toc.yml
CI/CD securitySupply chainGithub actions
.dockerignore
CI/CD securitycontainers
Dockerfile:32
CI/CD securitycontainers
Dockerfile:32
CI/CD securitycontainers
.github/workflows/release.yml:25
.github/workflows/toc.yml:32
.github/workflows/latest-npm.yml:15.github/workflows/lint.yml:12.github/workflows/release.yml:13.github/workflows/shellcheck.yml:31.github/workflows/tests-fast.yml:34.github/workflows/tests-installation-iojs.yml:31.github/workflows/tests-installation-node.yml:31.github/workflows/tests-xenial.yml:28package.json
package.json
Dockerfile:8
containersPinned dependencies
.github/workflows/codeql-analysis.yml:24.github/workflows/latest-npm.yml:66.github/workflows/lint.yml:19.github/workflows/nvm-install-test.yml:24.github/workflows/rebase.yml:14.github/workflows/release.yml:22.github/workflows/shellcheck.yml:38.github/workflows/tests-installation-iojs.yml:41
This page is publicly accessible at:
https://repobility.com/scan/851ae72c-90e8-4115-88e4-0abc61006b90/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/851ae72c-90e8-4115-88e4-0abc61006b90/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.