Scan timing: clone 2.85s · analysis 3.01s · 9.4 MB · GitHub API rate-limit (preflight)
https://github.com/evanw/esbuild
· scanned 2026-05-24 01:23 UTC (1 week, 5 days ago)
· 10 languages
278 findings (60 legacy + 218 scanner) 45th percentile · Go · large (100-500K LoC) Scanner says 67 (higher by 13)
Last scanned 1 week, 5 days ago · v2 · 169 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
96.0 | 0.25 | 24.00 |
testing_score |
76.0 | 0.20 | 15.20 |
documentation_score |
72.0 | 0.15 | 10.80 |
practices_score |
84.0 | 0.15 | 12.60 |
code_quality |
45.5 | 0.10 | 4.55 |
| Overall | 1.00 | 79.9 |
Showing 130 of 169 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
scripts/destructuring-fuzzer.js:121
qualitylegacy
internal/js_parser/json_parser.go:192
qualitylegacy
internal/js_parser/global_name_parser.go:12
qualitylegacy
compat-table/src/js_table.ts:15
xsslegacy
compat-table/src/css_table.ts:15
xsslegacy
.github/workflows/publish.yml:19
dependencylegacy
.github/workflows/validate.yml:16
dependencylegacy
.github/workflows/e2e.yml:16
dependencylegacy
.github/workflows/ci.yml:294
dependencylegacy
.github/workflows/ci.yml:233
dependencylegacy
.github/workflows/ci.yml:95
dependencylegacy
.github/workflows/ci.yml:49
dependencylegacy
.github/workflows/ci.yml:21
dependencylegacy
.github/workflows/publish.yml:80
dependencylegacy
.github/workflows/publish.yml:45
dependencylegacy
.github/workflows/validate.yml:23
dependencylegacy
.github/workflows/ci.yml:307
dependencylegacy
.github/workflows/ci.yml:236
dependencylegacy
.github/workflows/ci.yml:108
dependencylegacy
.github/workflows/ci.yml:56
dependencylegacy
.github/workflows/ci.yml:28
dependencylegacy
.github/workflows/publish.yml:50
dependencylegacy
.github/workflows/e2e.yml:19
dependencylegacy
.github/workflows/ci.yml:320
dependencylegacy
.github/workflows/ci.yml:114
dependencylegacy
.github/workflows/ci.yml:62
dependencylegacy
.github/workflows/ci.yml:34
dependencylegacy
.github/workflows/e2e.yml:26
dependencylegacy
.github/workflows/ci.yml:315
dependencylegacy
.github/workflows/ci.yml:119
dependencylegacy
.github/workflows/ci.yml:119
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:315
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e.yml:26
supply-chaingithub-actionspinned-dependencies
scripts/parse-ts-files.js:53
error_handlinglegacy
scripts/destructuring-fuzzer.js:139
error_handlinglegacy
.github/workflows/publish.yml
supply-chaingithub-actionsleast-privilege
pkg/api/api.go:52
qualitylegacy
lib/npm/browser.ts:32
qualitylegacy
lib/deno/wasm.ts:10
qualitylegacy
internal/logger/logger_linux.go:10
qualitylegacy
compat-table/src/mdn.ts:108
qualitylegacy
compat-table/src/js_table.ts:5
qualitylegacy
.github/workflows/ci.yml:21
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:34
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:49
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:56
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:62
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:95
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:108
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:114
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:233
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:236
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:294
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:307
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:320
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e.yml:16
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e.yml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/validate.yml:16
supply-chaingithub-actionspinned-dependencies
.github/workflows/validate.yml:23
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:45
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:50
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:80
supply-chaingithub-actionspinned-dependencies
npm/esbuild/package.json
supply-chainnpminstall-scripts
compat-table/src/js_table.ts:36
qualitylegacy
compat-table/src/css_table.ts:29
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/8da981ac-3685-4c52-b871-6094005ae9e9/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/8da981ac-3685-4c52-b871-6094005ae9e9/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.