← Back to scan
File as GitHub Issue repo: Azim-Ahmed/Automation-workflow

Push this scan report to Azim-Ahmed/Automation-workflow

Click the green button below to open GitHub’s new-issue form, pre-filled with the report title, summary table, top findings, and an embedded score-card image. No authentication needed — you review on GitHub before submitting. Repobility is credited as the scanner.

Embedded score card image

This image will render at the top of the issue body. Hosted on Repobility, refreshes automatically after re-scans.

Repobility score card

Issue title

semver: GHSA-c2qf-rxjj-qqgw

Curate findings to include

Pick exactly which findings appear in the issue body. By default the top 5 are included. Uncheck noise, check what matters.

Top 5 (default)
Severity Rule Title File:line
HIGH GHSA-3h5v-q93c-6h6q ws: GHSA-3h5v-q93c-6h6q yarn.lock
HIGH GHSA-wr3j-pwj9-hqq6 webpack-dev-middleware: GHSA-wr3j-pwj9-hqq6 yarn.lock
HIGH GHSA-xpqw-6gx7-v673 svgo: GHSA-xpqw-6gx7-v673 yarn.lock
HIGH GHSA-5c6j-r48x-rmvq serialize-javascript: GHSA-5c6j-r48x-rmvq yarn.lock
HIGH GHSA-c2qf-rxjj-qqgw semver: GHSA-c2qf-rxjj-qqgw yarn.lock
HIGH GHSA-mw96-cpmx-2vgc rollup: GHSA-mw96-cpmx-2vgc yarn.lock
HIGH GHSA-gcx4-mw62-g8wm rollup: GHSA-gcx4-mw62-g8wm yarn.lock
HIGH GHSA-c2c7-rcm5-vvqj picomatch: GHSA-c2c7-rcm5-vvqj yarn.lock
HIGH GHSA-rhx6-c78j-4q9w path-to-regexp: GHSA-rhx6-c78j-4q9w yarn.lock
HIGH GHSA-9wv6-86v2-598j path-to-regexp: GHSA-9wv6-86v2-598j yarn.lock
HIGH GHSA-37ch-88jc-xwx2 path-to-regexp: GHSA-37ch-88jc-xwx2 yarn.lock
HIGH GHSA-rp65-9cf3-cjxr nth-check: GHSA-rp65-9cf3-cjxr yarn.lock
HIGH GHSA-q67f-28xg-22rw node-forge: GHSA-q67f-28xg-22rw yarn.lock
HIGH GHSA-ppp5-5v6c-4jwp node-forge: GHSA-ppp5-5v6c-4jwp yarn.lock
HIGH GHSA-5m6q-g25r-mvwx node-forge: GHSA-5m6q-g25r-mvwx yarn.lock
HIGH GHSA-5gfm-wpxj-wjgq node-forge: GHSA-5gfm-wpxj-wjgq yarn.lock
HIGH GHSA-554w-wpv2-vw27 node-forge: GHSA-554w-wpv2-vw27 yarn.lock
HIGH GHSA-2328-f5f3-gj25 node-forge: GHSA-2328-f5f3-gj25 yarn.lock
HIGH GHSA-f8q6-p94x-37v3 minimatch: GHSA-f8q6-p94x-37v3 yarn.lock
HIGH GHSA-7r86-cg39-jmmj minimatch: GHSA-7r86-cg39-jmmj yarn.lock
HIGH GHSA-3ppc-4f35-3m26 minimatch: GHSA-3ppc-4f35-3m26 yarn.lock
HIGH GHSA-23c5-xmqv-rm74 minimatch: GHSA-23c5-xmqv-rm74 yarn.lock
HIGH GHSA-r5fr-rjxr-66jc lodash: GHSA-r5fr-rjxr-66jc yarn.lock
HIGH GHSA-hhq3-ff78-jv3g loader-utils: GHSA-hhq3-ff78-jv3g yarn.lock
HIGH GHSA-3rfm-jhwj-7488 loader-utils: GHSA-3rfm-jhwj-7488 yarn.lock
HIGH GHSA-9c47-m6qq-7p4h json5: GHSA-9c47-m6qq-7p4h yarn.lock
HIGH GHSA-wf6x-7x77-mvgw immutable: GHSA-wf6x-7x77-mvgw yarn.lock
HIGH GHSA-c7qv-q95q-8v27 http-proxy-middleware: GHSA-c7qv-q95q-8v27 yarn.lock
HIGH GHSA-rf6f-7fwh-wjgh flatted: GHSA-rf6f-7fwh-wjgh yarn.lock
HIGH GHSA-25h7-pfq9-p65f flatted: GHSA-25h7-pfq9-p65f yarn.lock
HIGH GHSA-3xgq-45jj-v275 cross-spawn: GHSA-3xgq-45jj-v275 yarn.lock
HIGH GHSA-grv7-fg5c-xmjg braces: GHSA-grv7-fg5c-xmjg yarn.lock
MED DEPCUR-NPM npm package `web-vitals` is 3 major version(s) behind (2.1.4 -> 5.3.0) package.json
MED DEPCUR-NPM npm package `@tisoap/react-flow-smart-edge` is 2 major version(s) behind (2.0.0 -> 4.3.0) package.json
MED DEPCUR-NPM npm package `@testing-library/user-event` is 1 major version(s) behind (13.5.0 -> 14.6.1) package.json
MED DEPCUR-NPM npm package `@testing-library/react` is 3 major version(s) behind (13.3.0 -> 16.3.2) package.json
MED DEPCUR-NPM npm package `@testing-library/jest-dom` is 1 major version(s) behind (5.16.5 -> 6.9.1) package.json
MED DEPCUR-NPM npm package `@ant-design/icons` is 2 major version(s) behind (4.7.0 -> 6.2.5) package.json
MED GHSA-48c2-rrv3-qjmp yaml: GHSA-48c2-rrv3-qjmp yarn.lock
MED GHSA-58qx-3vcg-4xpx ws: GHSA-58qx-3vcg-4xpx yarn.lock
MED GHSA-j8xg-fqg3-53r7 word-wrap: GHSA-j8xg-fqg3-53r7 yarn.lock
MED GHSA-9jgg-88mc-972h webpack-dev-server: GHSA-9jgg-88mc-972h yarn.lock
MED GHSA-79cf-xcqc-c78w webpack-dev-server: GHSA-79cf-xcqc-c78w yarn.lock
MED GHSA-4v9v-hfq4-rm2v webpack-dev-server: GHSA-4v9v-hfq4-rm2v yarn.lock
MED GHSA-4vvj-4cpr-p986 webpack: GHSA-4vvj-4cpr-p986 yarn.lock
MED GHSA-w5hq-g745-h8pq uuid: GHSA-w5hq-g745-h8pq yarn.lock
MED GHSA-72xf-g2v4-qvf3 tough-cookie: GHSA-72xf-g2v4-qvf3 yarn.lock
MED GHSA-qj8w-gfj5-8c6v serialize-javascript: GHSA-qj8w-gfj5-8c6v yarn.lock
MED GHSA-76p7-773f-r4q5 serialize-javascript: GHSA-76p7-773f-r4q5 yarn.lock
MED GHSA-6rw7-vpxm-498p qs: GHSA-6rw7-vpxm-498p yarn.lock
MED GHSA-qx2v-qp2m-jg93 postcss: GHSA-qx2v-qp2m-jg93 yarn.lock
MED GHSA-7fh5-64p2-3v2j postcss: GHSA-7fh5-64p2-3v2j yarn.lock
MED GHSA-3v7f-55p6-f55p picomatch: GHSA-3v7f-55p6-f55p yarn.lock
MED GHSA-65ch-62r8-g69g node-forge: GHSA-65ch-62r8-g69g yarn.lock
MED GHSA-mwcw-c2x4-8c55 nanoid: GHSA-mwcw-c2x4-8c55 yarn.lock
MED GHSA-v78c-4p63-2j6c moment-timezone: GHSA-v78c-4p63-2j6c yarn.lock
MED GHSA-952p-6rrq-rcjv micromatch: GHSA-952p-6rrq-rcjv yarn.lock
MED GHSA-xxjr-mmjv-4gpg lodash: GHSA-xxjr-mmjv-4gpg yarn.lock
MED GHSA-f23m-r3pf-42rh lodash: GHSA-f23m-r3pf-42rh yarn.lock
MED GHSA-mh29-5h37-fv8m js-yaml: GHSA-mh29-5h37-fv8m yarn.lock
MED GHSA-9gqv-wp59-fq42 http-proxy-middleware: GHSA-9gqv-wp59-fq42 yarn.lock
MED GHSA-4www-5p9h-95mh http-proxy-middleware: GHSA-4www-5p9h-95mh yarn.lock
MED GHSA-r4q5-vmmm-2653 follow-redirects: GHSA-r4q5-vmmm-2653 yarn.lock
MED GHSA-jchw-25xp-jwwc follow-redirects: GHSA-jchw-25xp-jwwc yarn.lock
MED GHSA-cxjh-pqwp-8mfp follow-redirects: GHSA-cxjh-pqwp-8mfp yarn.lock
MED GHSA-rv95-896h-c2vc express: GHSA-rv95-896h-c2vc yarn.lock
MED GHSA-ghr5-ch3p-vcr6 ejs: GHSA-ghr5-ch3p-vcr6 yarn.lock
MED GHSA-f886-m6hf-6m8v brace-expansion: GHSA-f886-m6hf-6m8v yarn.lock
MED GHSA-2g4f-4pwh-qvx6 ajv: GHSA-2g4f-4pwh-qvx6 yarn.lock
MED GHSA-968p-4wvh-cqc8 @babel/runtime-corejs3: GHSA-968p-4wvh-cqc8 yarn.lock
MED GHSA-968p-4wvh-cqc8 @babel/runtime: GHSA-968p-4wvh-cqc8 yarn.lock
MED GHSA-968p-4wvh-cqc8 @babel/helpers: GHSA-968p-4wvh-cqc8 yarn.lock
MED GHSA-prr3-c3m5-p7q2 @adobe/css-tools: GHSA-prr3-c3m5-p7q2 yarn.lock
MED GHSA-hpx4-r86g-5jrg @adobe/css-tools: GHSA-hpx4-r86g-5jrg yarn.lock
MED GHSA-48c2-rrv3-qjmp yaml: GHSA-48c2-rrv3-qjmp pnpm-lock.yaml
MED GHSA-58qx-3vcg-4xpx ws: GHSA-58qx-3vcg-4xpx pnpm-lock.yaml
MED GHSA-j8xg-fqg3-53r7 word-wrap: GHSA-j8xg-fqg3-53r7 pnpm-lock.yaml
MED GHSA-9jgg-88mc-972h webpack-dev-server: GHSA-9jgg-88mc-972h pnpm-lock.yaml
MED GHSA-79cf-xcqc-c78w webpack-dev-server: GHSA-79cf-xcqc-c78w pnpm-lock.yaml
MED GHSA-4v9v-hfq4-rm2v webpack-dev-server: GHSA-4v9v-hfq4-rm2v pnpm-lock.yaml
MED GHSA-4vvj-4cpr-p986 webpack: GHSA-4vvj-4cpr-p986 pnpm-lock.yaml
MED GHSA-w5hq-g745-h8pq uuid: GHSA-w5hq-g745-h8pq pnpm-lock.yaml
MED GHSA-72xf-g2v4-qvf3 tough-cookie: GHSA-72xf-g2v4-qvf3 pnpm-lock.yaml
MED GHSA-qj8w-gfj5-8c6v serialize-javascript: GHSA-qj8w-gfj5-8c6v pnpm-lock.yaml
MED GHSA-76p7-773f-r4q5 serialize-javascript: GHSA-76p7-773f-r4q5 pnpm-lock.yaml
MED GHSA-6rw7-vpxm-498p qs: GHSA-6rw7-vpxm-498p pnpm-lock.yaml
MED GHSA-qx2v-qp2m-jg93 postcss: GHSA-qx2v-qp2m-jg93 pnpm-lock.yaml
MED GHSA-7fh5-64p2-3v2j postcss: GHSA-7fh5-64p2-3v2j pnpm-lock.yaml
MED GHSA-3v7f-55p6-f55p picomatch: GHSA-3v7f-55p6-f55p pnpm-lock.yaml
MED GHSA-65ch-62r8-g69g node-forge: GHSA-65ch-62r8-g69g pnpm-lock.yaml
MED GHSA-mwcw-c2x4-8c55 nanoid: GHSA-mwcw-c2x4-8c55 pnpm-lock.yaml
MED GHSA-v78c-4p63-2j6c moment-timezone: GHSA-v78c-4p63-2j6c pnpm-lock.yaml
MED GHSA-952p-6rrq-rcjv micromatch: GHSA-952p-6rrq-rcjv pnpm-lock.yaml
MED GHSA-xxjr-mmjv-4gpg lodash: GHSA-xxjr-mmjv-4gpg pnpm-lock.yaml
MED GHSA-f23m-r3pf-42rh lodash: GHSA-f23m-r3pf-42rh pnpm-lock.yaml
MED GHSA-mh29-5h37-fv8m js-yaml: GHSA-mh29-5h37-fv8m pnpm-lock.yaml
MED GHSA-9gqv-wp59-fq42 http-proxy-middleware: GHSA-9gqv-wp59-fq42 pnpm-lock.yaml
MED GHSA-4www-5p9h-95mh http-proxy-middleware: GHSA-4www-5p9h-95mh pnpm-lock.yaml
MED GHSA-r4q5-vmmm-2653 follow-redirects: GHSA-r4q5-vmmm-2653 pnpm-lock.yaml
MED GHSA-jchw-25xp-jwwc follow-redirects: GHSA-jchw-25xp-jwwc pnpm-lock.yaml
MED GHSA-cxjh-pqwp-8mfp follow-redirects: GHSA-cxjh-pqwp-8mfp pnpm-lock.yaml
MED GHSA-rv95-896h-c2vc express: GHSA-rv95-896h-c2vc pnpm-lock.yaml
MED GHSA-ghr5-ch3p-vcr6 ejs: GHSA-ghr5-ch3p-vcr6 pnpm-lock.yaml
MED GHSA-f886-m6hf-6m8v brace-expansion: GHSA-f886-m6hf-6m8v pnpm-lock.yaml
MED GHSA-2g4f-4pwh-qvx6 ajv: GHSA-2g4f-4pwh-qvx6 pnpm-lock.yaml
MED GHSA-968p-4wvh-cqc8 @babel/runtime-corejs3: GHSA-968p-4wvh-cqc8 pnpm-lock.yaml
MED GHSA-968p-4wvh-cqc8 @babel/runtime: GHSA-968p-4wvh-cqc8 pnpm-lock.yaml
MED GHSA-968p-4wvh-cqc8 @babel/helpers: GHSA-968p-4wvh-cqc8 pnpm-lock.yaml
MED GHSA-prr3-c3m5-p7q2 @adobe/css-tools: GHSA-prr3-c3m5-p7q2 pnpm-lock.yaml
MED GHSA-hpx4-r86g-5jrg @adobe/css-tools: GHSA-hpx4-r86g-5jrg pnpm-lock.yaml
MED GHSA-48c2-rrv3-qjmp yaml: GHSA-48c2-rrv3-qjmp package-lock.json
MED GHSA-58qx-3vcg-4xpx ws: GHSA-58qx-3vcg-4xpx package-lock.json
MED GHSA-j8xg-fqg3-53r7 word-wrap: GHSA-j8xg-fqg3-53r7 package-lock.json
MED GHSA-9jgg-88mc-972h webpack-dev-server: GHSA-9jgg-88mc-972h package-lock.json
MED GHSA-79cf-xcqc-c78w webpack-dev-server: GHSA-79cf-xcqc-c78w package-lock.json
MED GHSA-4v9v-hfq4-rm2v webpack-dev-server: GHSA-4v9v-hfq4-rm2v package-lock.json
MED GHSA-4vvj-4cpr-p986 webpack: GHSA-4vvj-4cpr-p986 package-lock.json
MED GHSA-w5hq-g745-h8pq uuid: GHSA-w5hq-g745-h8pq package-lock.json
MED GHSA-72xf-g2v4-qvf3 tough-cookie: GHSA-72xf-g2v4-qvf3 package-lock.json
MED GHSA-qj8w-gfj5-8c6v serialize-javascript: GHSA-qj8w-gfj5-8c6v package-lock.json
MED GHSA-76p7-773f-r4q5 serialize-javascript: GHSA-76p7-773f-r4q5 package-lock.json
MED GHSA-6rw7-vpxm-498p qs: GHSA-6rw7-vpxm-498p package-lock.json
MED GHSA-qx2v-qp2m-jg93 postcss: GHSA-qx2v-qp2m-jg93 package-lock.json
MED GHSA-7fh5-64p2-3v2j postcss: GHSA-7fh5-64p2-3v2j package-lock.json
MED GHSA-3v7f-55p6-f55p picomatch: GHSA-3v7f-55p6-f55p package-lock.json
MED GHSA-65ch-62r8-g69g node-forge: GHSA-65ch-62r8-g69g package-lock.json
MED GHSA-mwcw-c2x4-8c55 nanoid: GHSA-mwcw-c2x4-8c55 package-lock.json
MED GHSA-v78c-4p63-2j6c moment-timezone: GHSA-v78c-4p63-2j6c package-lock.json
MED GHSA-952p-6rrq-rcjv micromatch: GHSA-952p-6rrq-rcjv package-lock.json
MED GHSA-xxjr-mmjv-4gpg lodash: GHSA-xxjr-mmjv-4gpg package-lock.json
MED GHSA-f23m-r3pf-42rh lodash: GHSA-f23m-r3pf-42rh package-lock.json
MED GHSA-mh29-5h37-fv8m js-yaml: GHSA-mh29-5h37-fv8m package-lock.json
MED GHSA-9gqv-wp59-fq42 http-proxy-middleware: GHSA-9gqv-wp59-fq42 package-lock.json
MED GHSA-4www-5p9h-95mh http-proxy-middleware: GHSA-4www-5p9h-95mh package-lock.json
MED GHSA-r4q5-vmmm-2653 follow-redirects: GHSA-r4q5-vmmm-2653 package-lock.json
MED GHSA-jchw-25xp-jwwc follow-redirects: GHSA-jchw-25xp-jwwc package-lock.json
MED GHSA-cxjh-pqwp-8mfp follow-redirects: GHSA-cxjh-pqwp-8mfp package-lock.json
MED GHSA-rv95-896h-c2vc express: GHSA-rv95-896h-c2vc package-lock.json
MED GHSA-ghr5-ch3p-vcr6 ejs: GHSA-ghr5-ch3p-vcr6 package-lock.json
MED GHSA-f886-m6hf-6m8v brace-expansion: GHSA-f886-m6hf-6m8v package-lock.json
MED GHSA-2g4f-4pwh-qvx6 ajv: GHSA-2g4f-4pwh-qvx6 package-lock.json
MED GHSA-968p-4wvh-cqc8 @babel/runtime-corejs3: GHSA-968p-4wvh-cqc8 package-lock.json
MED GHSA-968p-4wvh-cqc8 @babel/runtime: GHSA-968p-4wvh-cqc8 package-lock.json
MED GHSA-968p-4wvh-cqc8 @babel/helpers: GHSA-968p-4wvh-cqc8 package-lock.json
MED GHSA-prr3-c3m5-p7q2 @adobe/css-tools: GHSA-prr3-c3m5-p7q2 package-lock.json
MED GHSA-hpx4-r86g-5jrg @adobe/css-tools: GHSA-hpx4-r86g-5jrg package-lock.json
MED WEB003 Public web service has no security.txt .well-known/security.txt
MED WEB015 Public web app has no Content Security Policy index.html
MED CORE_NO_CI No CI/CD configuration found
LOW DEPCUR-NPM npm package `sass` is minor version(s) behind (1.54.3 -> 1.100.0) package.json
LOW DEPCUR-NPM npm package `moment-timezone` is minor version(s) behind (0.5.34 -> 0.6.2) package.json
LOW DEPCUR-NPM npm package `fp-ts` is minor version(s) behind (2.11.7 -> 2.16.11) package.json
LOW DEPCUR-NPM npm package `@xyflow/react` is minor version(s) behind (12.1.1 -> 12.11.0) package.json
LOW DEPCUR-NPM npm package `@emotion/css` is minor version(s) behind (11.7.1 -> 11.13.5) package.json
LOW DEPCUR-NPM npm package `@contactlab/ds-tokens` is minor version(s) behind (3.3.0 -> 3.6.0) package.json
LOW GHSA-8fgc-7cc6-rx7x webpack: GHSA-8fgc-7cc6-rx7x yarn.lock
LOW GHSA-38r7-794h-5758 webpack: GHSA-38r7-794h-5758 yarn.lock
LOW GHSA-cm22-4g7w-348p serve-static: GHSA-cm22-4g7w-348p yarn.lock
LOW GHSA-m6fv-jmcg-4jfg send: GHSA-m6fv-jmcg-4jfg yarn.lock
LOW GHSA-w7fw-mjwx-w883 qs: GHSA-w7fw-mjwx-w883 yarn.lock
LOW GHSA-76c9-3jph-rj3q on-headers: GHSA-76c9-3jph-rj3q yarn.lock
LOW GHSA-56x4-j7p9-fcf9 moment-timezone: GHSA-56x4-j7p9-fcf9 yarn.lock
LOW GHSA-qw6h-vgh9-j6wx express: GHSA-qw6h-vgh9-j6wx yarn.lock
LOW GHSA-pxg6-pf52-xh8x cookie: GHSA-pxg6-pf52-xh8x yarn.lock
LOW GHSA-v6h2-p8h4-qcjw brace-expansion: GHSA-v6h2-p8h4-qcjw yarn.lock
LOW GHSA-vpq2-c234-7xj6 @tootallnate/once: GHSA-vpq2-c234-7xj6 yarn.lock
LOW GHSA-8fgc-7cc6-rx7x webpack: GHSA-8fgc-7cc6-rx7x pnpm-lock.yaml
LOW GHSA-38r7-794h-5758 webpack: GHSA-38r7-794h-5758 pnpm-lock.yaml
LOW GHSA-cm22-4g7w-348p serve-static: GHSA-cm22-4g7w-348p pnpm-lock.yaml
LOW GHSA-m6fv-jmcg-4jfg send: GHSA-m6fv-jmcg-4jfg pnpm-lock.yaml
LOW GHSA-w7fw-mjwx-w883 qs: GHSA-w7fw-mjwx-w883 pnpm-lock.yaml
LOW GHSA-76c9-3jph-rj3q on-headers: GHSA-76c9-3jph-rj3q pnpm-lock.yaml
LOW GHSA-56x4-j7p9-fcf9 moment-timezone: GHSA-56x4-j7p9-fcf9 pnpm-lock.yaml
LOW GHSA-qw6h-vgh9-j6wx express: GHSA-qw6h-vgh9-j6wx pnpm-lock.yaml
LOW GHSA-pxg6-pf52-xh8x cookie: GHSA-pxg6-pf52-xh8x pnpm-lock.yaml
LOW GHSA-v6h2-p8h4-qcjw brace-expansion: GHSA-v6h2-p8h4-qcjw pnpm-lock.yaml
LOW GHSA-vpq2-c234-7xj6 @tootallnate/once: GHSA-vpq2-c234-7xj6 pnpm-lock.yaml
LOW GHSA-8fgc-7cc6-rx7x webpack: GHSA-8fgc-7cc6-rx7x package-lock.json
LOW GHSA-38r7-794h-5758 webpack: GHSA-38r7-794h-5758 package-lock.json
LOW GHSA-cm22-4g7w-348p serve-static: GHSA-cm22-4g7w-348p package-lock.json
LOW GHSA-m6fv-jmcg-4jfg send: GHSA-m6fv-jmcg-4jfg package-lock.json
LOW GHSA-w7fw-mjwx-w883 qs: GHSA-w7fw-mjwx-w883 package-lock.json
LOW GHSA-76c9-3jph-rj3q on-headers: GHSA-76c9-3jph-rj3q package-lock.json
LOW GHSA-56x4-j7p9-fcf9 moment-timezone: GHSA-56x4-j7p9-fcf9 package-lock.json
LOW GHSA-qw6h-vgh9-j6wx express: GHSA-qw6h-vgh9-j6wx package-lock.json
LOW GHSA-pxg6-pf52-xh8x cookie: GHSA-pxg6-pf52-xh8x package-lock.json
LOW GHSA-v6h2-p8h4-qcjw brace-expansion: GHSA-v6h2-p8h4-qcjw package-lock.json
LOW GHSA-vpq2-c234-7xj6 @tootallnate/once: GHSA-vpq2-c234-7xj6 package-lock.json
LOW AIC003 Duplicated implementation block across source files src/Data/Elements2.jsx:23
LOW AIC003 Duplicated implementation block across source files src/Data/Elements1.jsx:103
LOW WEB005 robots.txt does not advertise a sitemap public/robots.txt
LOW WEB002 Public web app has no sitemap sitemap.xml
LOW WEB008 Public docs site has no llms.txt llms.txt
LOW WEB011 Public web app has no humans.txt humans.txt
LOW CORE_NO_LICENSE No LICENSE file
INFO MINED043 [MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr… src/Edges/Edges.jsx:59
INFO MINED044 [MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger … src/Utils/WorkflowElementUtils.js:128
INFO MINED044 [MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger … src/App.js:51
INFO DEPCUR-NPM npm package `react-flow-renderer` is patch version(s) behind (10.3.12 -> 10.3.17) package.json
INFO DEPCUR-NPM npm package `io-ts` is patch version(s) behind (2.2.16 -> 2.2.22) package.json
Reset to top 5 200 findings available (after auto-suppression of test files + won't-fix)

Issue body (markdown)

## Code-quality scan: `Azim-Ahmed/Automation-workflow`

**Score: 74/100 (C-)**  ·  278 findings  ·  scanned 2026-06-05 16:56 UTC  ·  1,487 LOC

| Severity | Count |
|---|---|
| CRITICAL | 11 |
| HIGH | 99 |
| MEDIUM | 117 |
| LOW | 46 |

📊 [Full filterable report](https://repobility.com/scan/a26233f4-6f06-4682-bf0d-658632a042ab/)  ·  ![scorecard](https://repobility.com/scan/a26233f4-6f06-4682-bf0d-658632a042ab/report.png?v=1780678609-s2)

### Top findings

1. **HIGH** `GHSA-3h5v-q93c-6h6q` — ws: GHSA-3h5v-q93c-6h6q
   `yarn.lock`
2. **HIGH** `GHSA-wr3j-pwj9-hqq6` — webpack-dev-middleware: GHSA-wr3j-pwj9-hqq6
   `yarn.lock`
3. **HIGH** `GHSA-xpqw-6gx7-v673` — svgo: GHSA-xpqw-6gx7-v673
   `yarn.lock`
4. **HIGH** `GHSA-5c6j-r48x-rmvq` — serialize-javascript: GHSA-5c6j-r48x-rmvq
   `yarn.lock`
5. **HIGH** `GHSA-c2qf-rxjj-qqgw` — semver: GHSA-c2qf-rxjj-qqgw
   `yarn.lock`

---

_Filed automatically. Close this issue if not useful — we won't refile. Full report: https://repobility.com/scan/a26233f4-6f06-4682-bf0d-658632a042ab/_
Megaproject â high spam risk
Could not determine 'Azim-Ahmed/Automation-workflow' star count (GitHub API rate-limited or unreachable). When in doubt about repo size, prefer opening a focused PR or a discussion rather than an issue.

The button opens GitHubâs new-issue page in a new tab. You will see the title + body pre-filled â review, edit if you want, then click GitHubâs "Submit new issue" button. Repobility never posts anything on your behalf.

For real security findings on big repos: use the project's SECURITY.md or private advisory flow instead of a public issue.