https://github.com/microsoft/vscode
· scanned 2026-06-05 04:35 UTC (4 hours, 27 minutes ago)
· 10 languages
5328 findings (184 legacy + 5144 scanner) 11/13 scanners ran 85th percentile · Typescript · huge (>500K LoC) Scanner says 44 (higher by 46)
Last scanned 4 hours, 27 minutes ago · v2 · 2756 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
81.0 | 0.15 | 12.15 |
practices_score |
91.0 | 0.15 | 13.65 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 90.5 |
Showing 1245 of 2756 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
extensions/copilot/src/extension/intents/node/promptOverride.ts:107
qualitylegacy
extensions/php-language-features/src/features/phpGlobals.ts:183
qualitylegacy
extensions/copilot/src/extension/intents/node/promptOverride.ts:107
qualitylegacy
extensions/copilot/src/extension/intents/node/promptOverride.ts:107
deserializationlegacy
extensions/copilot/src/extension/prompts/node/inline/pythonCookbookData.ts:56
secrets
extensions/copilot/src/extension/prompts/node/inline/pythonCookbookData.ts:57
secrets
src/vs/platform/agentHost/common/sshRemoteAgentHost.ts:27
secrets
extensions/copilot/src/util/vs/base/common/hash.ts:98
qualitylegacy
extensions/copilot/src/extension/chatSessions/vscode-node/copilotCLIShim.ts:109
qualitylegacy
extensions/copilot/src/platform/inlineEdits/common/responseProcessor.ts:89
qualitylegacy
extensions/copilot/src/extension/prompts/node/panel/symbolAtCursor.tsx:191
qualitylegacy
extensions/tunnel-forwarding/src/extension.ts:259
qualitylegacy
extensions/copilot/.github/workflows/pr.yml:101
dependencylegacy
extensions/copilot/.github/workflows/pr.yml:31
dependencylegacy
extensions/copilot/.github/workflows/copilot-setup-steps.yml:44
dependencylegacy
extensions/copilot/.github/workflows/ensure-node-modules-cache.yml:67
dependencylegacy
extensions/copilot/.github/workflows/ensure-node-modules-cache.yml:27
dependencylegacy
extensions/copilot/.github/workflows/pr.yml:167
dependencylegacy
extensions/copilot/.github/workflows/pr.yml:77
dependencylegacy
extensions/copilot/.github/workflows/pr.yml:61
dependencylegacy
extensions/copilot/.github/workflows/pr.yml:22
dependencylegacy
extensions/copilot/.github/workflows/copilot-setup-steps.yml:20
dependencylegacy
extensions/copilot/.github/workflows/ensure-node-modules-cache.yml:51
dependencylegacy
extensions/copilot/.github/workflows/ensure-node-modules-cache.yml:17
dependencylegacy
extensions/copilot/.github/workflows/pr.yml:93
dependencylegacy
extensions/copilot/.github/workflows/copilot-setup-steps.yml:36
dependencylegacy
extensions/copilot/.github/workflows/pr.yml:172
dependencylegacy
extensions/copilot/.github/workflows/pr.yml:82
dependencylegacy
extensions/copilot/.github/workflows/pr.yml:64
dependencylegacy
extensions/copilot/.github/workflows/pr.yml:25
dependencylegacy
extensions/copilot/.github/workflows/copilot-setup-steps.yml:25
dependencylegacy
extensions/copilot/.github/workflows/ensure-node-modules-cache.yml:56
dependencylegacy
extensions/copilot/.github/workflows/ensure-node-modules-cache.yml:22
dependencylegacy
extensions/copilot/.github/workflows/pr.yml:87
dependencylegacy
extensions/copilot/.github/workflows/copilot-setup-steps.yml:30
dependencylegacy
extensions/copilot/.github/workflows/ensure-node-modules-cache.yml:61
dependencylegacy
extensions/copilot/.github/workflows/pr.yml:157
dependencylegacy
.devcontainer/Dockerfile:1
dependencylegacy
extensions/microsoft-authentication/package.json:1
dependencylegacy
src/vs/workbench/contrib/terminal/common/scripts/psreadline/Microsoft.PowerShell.Pager.dll:1
dependencylegacy
src/vs/workbench/contrib/terminal/common/scripts/psreadline/Microsoft.PowerShell.PSReadLine.dll:1
dependencylegacy
src/vs/workbench/contrib/terminal/common/scripts/psreadline/net6plus/Microsoft.PowerShell.PSReadLine.Polyfiller.dll:1
dependencylegacy
src/vs/workbench/contrib/terminal/common/scripts/psreadline/netstd/Microsoft.PowerShell.PSReadLine.Polyfiller.dll:1
dependencylegacy
extensions/github-authentication/src/node/authServer.ts:24
injectionlegacy
extensions/copilot/src/extension/intents/node/hookResultProcessor.ts:131
xsslegacy
extensions/copilot/src/extension/completions-core/vscode-node/extension/src/copilotPanel/webView/suggestionsPanelWebview.ts:101
xsslegacy
extensions/copilot/script/setup/getEnv.mts:82
xsslegacy
extensions/copilot/src/extension/linkify/common/linkifier.ts:164
qualitylegacy
extensions/copilot/src/extension/conversation/vscode-node/logWorkspaceState.ts:51
qualitylegacy
.eslint-plugin-local/vscode-dts-event-naming.ts:72
qualitylegacy
.eslint-plugin-local/vscode-dts-vscode-in-comments.ts:36
qualitylegacy
.eslint-plugin-local/vscode-dts-event-naming.ts:52
qualitylegacy
extensions/copilot/src/platform/endpoint/node/responsesApiDebugDump.ts:63
path_traversallegacy
.devcontainer/Dockerfile:13
dockerlegacy
extensions/copilot/src/extension/prompts/node/inline/pythonCookbookData.ts:52
owaspeval_used
extensions/php-language-features/src/features/phpGlobals.ts:183
owaspeval_used
extensions/copilot/src/extension/prompts/node/inline/pythonCookbookData.ts:52
owaspexec_used
extensions/copilot/src/platform/git/common/gitService.ts:87
owaspexec_used
extensions/copilot/src/platform/git/vscode-node/gitServiceImpl.ts:381
owaspexec_used
extensions/php/syntaxes/php.tmLanguage.json:3727
owaspexec_used
extensions/terminal-suggest/src/completions/git.ts:4103
owaspexec_used
extensions/terminal-suggest/src/fig/autocomplete-parser/parseArguments.ts:1122
owaspexec_used
extensions/terminal-suggest/src/shell/common.ts:60
owaspexec_used
src/vs/base/node/terminalEncoding.ts:62
owaspexec_used
src/vs/platform/agentHost/node/sshRemoteAgentHostHelpers.ts:334
owaspexec_used
src/vs/platform/agentHost/node/sshRemoteAgentHostService.ts:70
owaspexec_used
src/vs/platform/terminal/node/ptyService.ts:206
owaspexec_used
src/vs/platform/terminal/node/terminalProcess.ts:617
owaspexec_used
extensions/copilot/src/extension/prompts/node/inline/pythonCookbookData.ts:100
owasptls_verify_false
extensions/copilot/src/extension/inlineEdits/vscode-node/components/logContextRecorder.ts:56
error_handlinglegacy
extensions/copilot/src/extension/conversation/vscode-node/feedbackReporter.ts:120
error_handlinglegacy
extensions/copilot/src/extension/chat/vscode-node/sessionTranscriptService.ts:140
error_handlinglegacy
extensions/copilot/src/extension/intents/node/promptOverride.ts:107
deserializationlegacy
extensions/notebook-renderers/src/linkify.ts:9
redoslegacy
extensions/copilot/src/extension/completions-core/vscode-node/extension/src/copilotPanel/webView/suggestionsPanelWebview.ts:60
securitylegacy
extensions/copilot/src/platform/survey/vscode/surveyServiceImpl.ts:51
qualitylegacy
extensions/copilot/src/extension/agents/node/langModelServer.ts:54
qualitylegacy
extensions/copilot/src/extension/prompts/node/panel/workspace/visualFileTree.ts:135
qualitylegacy
extensions/copilot/src/extension/prompts/node/panel/referencesAtPosition.tsx:118
qualitylegacy
extensions/copilot/src/extension/context/node/resolvers/vscodeContext.ts:32
qualitylegacy
extensions/copilot/src/extension/chatSessions/copilotcli/node/permissionHelpers.ts:51
qualitylegacy
extensions/copilot/docs/monitoring/docker-compose.yaml:31
dockerlegacy
extensions/copilot/docs/monitoring/docker-compose.yaml:19
dockerlegacy
.dockerignore
dockerlegacy
.dockerignore
dockerlegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
extensions/copilot/src/extension/chatSessions/vscode-node/copilotCLIShim.ts:109
dependencylegacy
.github/workflows/component-fixtures.yml
supply-chaingithub-actionsleast-privilege
extensions/copilot/src/extension/prompts/node/inline/pythonCookbookData.ts:110
owaspsubprocess_shell_true
extensions/copilot/src/extension/prompts/node/inline/pythonCookbookData.ts:66
owaspweak_hash
extensions/cpp/syntaxes/platform.tmLanguage.json:105
owaspweak_hash
extensions/php/syntaxes/php.tmLanguage.json:1549
owaspweak_hash
extensions/terminal-suggest/src/completions/git.ts:2500
owaspweak_hash
extensions/terminal-suggest/src/completions/upstream/curl.ts:450
owaspweak_hash
src/vs/base/parts/ipc/node/ipc.net.ts:39
owaspweak_hash
src/vs/platform/backup/electron-main/backupMainService.ts:414
owaspweak_hash
src/vs/workbench/contrib/debug/common/debugProtocol.d.ts:2340
owaspweak_hash
extensions/terminal-suggest/src/completions/upstream/docker-compose.ts
securityports
extensions/php-language-features/src/features/phpGlobalFunctions.ts
securityports
extensions/terminal-suggest/src/completions/upstream/docker-compose.ts
securityports
extensions/copilot/docs/monitoring/docker-compose.yaml:31
dockerlegacy
extensions/copilot/docs/monitoring/docker-compose.yaml:19
dockerlegacy
extensions/copilot/docs/monitoring/docker-compose.yaml:31
dockerlegacy
extensions/copilot/docs/monitoring/docker-compose.yaml:19
dockerlegacy
extensions/copilot/src/extension/completions-core/vscode-node/extension/src/panelShared/themes/dark-hc.ts:138
qualitylegacy
extensions/copilot/src/extension/chatSessions/vscode-node/claudeWorkspaceFolderServiceImpl.ts:160
qualitylegacy
extensions/copilot/src/extension/chatSessions/vscode-node/chatSessionWorktreeServiceImpl.ts:589
qualitylegacy
extensions/copilot/src/extension/chatSessions/copilotcli/vscode-node/copilotCLIFolderMru.ts:54
qualitylegacy
extensions/copilot/src/extension/chatSessions/copilotcli/node/ripgrepShim.ts:65
qualitylegacy
extensions/copilot/src/extension/chatSessions/claude/node/claudeLanguageModelServer.ts:110
qualitylegacy
extensions/copilot/src/extension/byok/vscode-node/openRouterProvider.ts:86
qualitylegacy
extensions/copilot/src/extension/byok/vscode-node/geminiNativeProvider.ts:166
qualitylegacy
extensions/copilot/src/extension/byok/vscode-node/customOAIProvider.ts:38
qualitylegacy
extensions/copilot/src/extension/byok/common/geminiMessageConverter.ts:158
qualitylegacy
extensions/copilot/src/extension/agents/vscode-node/exploreAgentProvider.ts:42
qualitylegacy
extensions/copilot/.eslintplugin/no-runtime-import.ts:41
qualitylegacy
.eslint-plugin-local/code-no-runtime-import.ts:10
qualitylegacy
.eslint-plugin-local/code-no-reader-after-await.ts:10
qualitylegacy
build:1
qualitylegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
robots.txt
qualitylegacy
sitemap.xml
qualitylegacy
scripts/xterm-update.js:1
qualitylegacy
cli/src/self_update.rs:1
qualitylegacy
.devcontainer/Dockerfile:1
supply-chaindockerpinned-dependencies
Showing first 300 of 1245. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/962fd338-2a5d-4f18-8b09-1929989ac06a/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/962fd338-2a5d-4f18-8b09-1929989ac06a/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.