https://github.com/astral-sh/uv.git
· scanned 2026-05-16 09:40 UTC (2 weeks, 5 days ago)
· 10 languages
202 findings (29 legacy + 173 scanner) 69th percentile · Rust · large (100-500K LoC) Scanner says 73 (higher by 3)
Last scanned 2 weeks, 5 days ago · v1 · 25 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Showing 25 of 25 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
scripts/update_schemastore.py:38
injectionlegacy
scripts/benchmark/src/benchmark/resolver.py:228
path_traversallegacy
scripts/publish-crates.py:80
path_traversallegacy
crates/uv-trampoline/Dockerfile:38
dockerlegacy
scripts/repair-sdist-cargo-lock.py:32
path_traversallegacy
.dockerignore
dockerlegacy
crates/uv-trampoline/Dockerfile:63
dockerlegacy
crates/uv-keyring/src/windows.rs:490
qualitylegacy
crates/uv-keyring/src/secret_service.rs:438
qualitylegacy
crates/uv-keyring/src/mock.rs:154
qualitylegacy
crates/uv-installer/src/satisfies.rs:322
qualitylegacy
crates/uv-install-wheel/src/uninstall.rs:312
qualitylegacy
crates/uv-distribution/src/metadata/requires_dist.rs:190
qualitylegacy
crates/uv-distribution/src/metadata/requires_dist.rs:152
qualitylegacy
crates/uv-dev/src/generate_sysconfig_mappings.rs:50
qualitylegacy
crates/uv-dev/src/generate_sysconfig_mappings.rs:28
qualitylegacy
crates/uv-dev/src/generate_options_reference.rs:25
qualitylegacy
crates/uv-dev/src/generate_options_reference.rs:11
qualitylegacy
crates/uv-configuration/src/sources.rs:30
qualitylegacy
docs/reference/installer.md:57
dependencylegacy
docs/getting-started/installation.md:16
dependencylegacy
crates/uv-trampoline/Dockerfile:28
dockerlegacy
crates/uv/src/commands/self_update.rs:1
qualitylegacy
crates/uv/src/commands/cache_clean.rs:1
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/9d80afe6-b891-4d50-b2cd-9006567d3dc2/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/9d80afe6-b891-4d50-b2cd-9006567d3dc2/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.