https://github.com/astral-sh/uv.git
· scanned 2026-05-16 09:40 UTC (2 weeks, 6 days ago)
· 10 languages
202 findings (29 legacy + 173 scanner) 73rd percentile · Rust · large (100-500K LoC) Scanner says 73 (higher by 3)
Last scanned 2 weeks, 6 days ago · v1 · 25 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Bug-class explainers. Each card groups findings of the same shape — these are the patterns most likely to ship to prod and reappear in future scans unless you systematically fix the cause, not just the instance.
crates/uv-keyring/src/windows.rs:490
crates/uv-keyring/src/secret_service.rs:438
crates/uv-keyring/src/mock.rs:154
crates/uv-installer/src/satisfies.rs:322
crates/uv-install-wheel/src/uninstall.rs:312
crates/uv-distribution/src/metadata/requires_dist…:190
crates/uv-distribution/src/metadata/requires_dist…:152
crates/uv-dev/src/generate_sysconfig_mappings.rs:50
crates/uv-dev/src/generate_sysconfig_mappings.rs:28
crates/uv-dev/src/generate_options_reference.rs:25
crates/uv-dev/src/generate_options_reference.rs:11
crates/uv-configuration/src/sources.rs:30
This page is publicly accessible at:
https://repobility.com/scan/9d80afe6-b891-4d50-b2cd-9006567d3dc2/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/9d80afe6-b891-4d50-b2cd-9006567d3dc2/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.