Scan timing: clone 6.17s · analysis 78.44s · 16.3 MB · GitHub API rate-limit (preflight)
https://github.com/open-telemetry/opentelemetry-js
· scanned 2026-06-05 21:05 UTC (4 days, 11 hours ago)
· 10 languages
585 raw signals (165 security + 420 graph) 30th percentile · Typescript · large (100-500K LoC) System graph score 59 (higher by 10)
Last scanned 4 days, 11 hours ago · v2 · 281 actionable findings from 2 signal sources. 94 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
28.9 | 0.25 | 7.22 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
92.0 | 0.15 | 13.80 |
practices_score |
91.0 | 0.15 | 13.65 |
code_quality |
69.9 | 0.10 | 6.99 |
| Overall | 1.00 | 69.7 |
Showing 232 of 281 actionable findings. 375 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
examples/https/server-key.pem:1
semantic-conventions/src/experimental_attributes.ts:594, 676, 769, 796, 895, 931 (6 hits)packages/sdk-metrics/src/MeterProvider.ts:58
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
bundler-tests/node/webpack-5/package.json:1 (11 hits)bundler-tests/browser/nextjs-16-edge/package.json:1 (10 hits)package-lock.json
package-lock.json
packages/sdk-metrics/src/exemplar/SimpleFixedSizeExemplarReservoir.ts:23
scripts/update-ts-configs.js:236
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
examples/opentelemetry-web/docker/docker-compose.yaml:2, 15, 21 (3 hits)examples/basic-tracer-node/docker/ot/docker-compose.yaml:4, 17 (2 hits)examples/otlp-exporter-node/docker/docker-compose.yaml:17, 23 (2 hits)examples/https/docker/docker-compose.yml:10package-lock.json
package-lock.json
api/package.jsonsemantic-conventions/package.jsonpackage.json
package.json
package.json
api/package.json
semantic-conventions/package.json
api/package.jsonsemantic-conventions/package.jsonpackage.json
package.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
.github/workflows/benchmark.yml.github/workflows/docs.yaml.github/workflows/ossf-scorecard.yml.github/workflows/publish-to-npm.yml.github/workflows/sbom.ymlpackage-lock.json
examples/opentelemetry-web/docker/docker-compose.yaml:2, 15, 21 (3 hits)examples/otlp-exporter-node/docker/docker-compose.yaml:3, 17, 23 (3 hits)examples/basic-tracer-node/docker/ot/docker-compose.yaml:4, 17 (2 hits)examples/https/docker/docker-compose.yml:3, 10 (2 hits)experimental/examples/prometheus/docker-compose.yaml:3examples/opentelemetry-web/docker/docker-compose.yaml:2, 15, 21 (3 hits)examples/otlp-exporter-node/docker/docker-compose.yaml:3, 17, 23 (3 hits)examples/basic-tracer-node/docker/ot/docker-compose.yaml:4, 17 (2 hits)examples/https/docker/docker-compose.yml:3, 10 (2 hits)experimental/examples/prometheus/docker-compose.yaml:3package-lock.json
bundler-tests/browser/webpack-5/src/index.js:12bundler-tests/node/webpack-5/src/index.js:26experimental/packages/opentelemetry-instrumentation-xml-http-request/src/utils.ts:8experimental/packages/opentelemetry-instrumentation-xml-http-request/src/xhr.ts:225experimental/packages/otlp-grpc-exporter-base/src/configuration/otlp-grpc-env-configuration.ts:30experimental/packages/otlp-transformer/src/metrics/protobuf/response-deserializer.ts:17experimental/packages/otlp-transformer/src/trace/protobuf/response-deserializer.ts:17packages/opentelemetry-core/src/internal/validators.ts:1e2e-tests/package.jsonintegration-tests/propagation-validation-server/package.jsonapi/package.json
api/package.json
api/package.jsonpackage.jsonpackage.json
package.json
package.json
api/package.json
package.json
api/package.json
scripts/version-update.js:1
package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/890f7b57-f0a7-4c37-b302-d02b01bb4096/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/890f7b57-f0a7-4c37-b302-d02b01bb4096/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.