Scan timing: clone 2.91s · analysis 99.57s · 8.8 MB · GitHub API rate-limit (preflight)
https://github.com/graphql/graphiql
· scanned 2026-06-05 19:14 UTC (4 days, 16 hours ago)
· 10 languages
469 raw signals (189 security + 280 graph) 62nd percentile · Typescript · medium (20-100K LoC) System graph score 70 (higher by 5)
Last scanned 4 days, 16 hours ago · v2 · 271 actionable findings from 2 signal sources. 58 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
53.9 | 0.25 | 13.47 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
98.6 | 0.15 | 14.79 |
practices_score |
84.0 | 0.15 | 12.60 |
code_quality |
74.2 | 0.10 | 7.42 |
| Overall | 1.00 | 74.3 |
Showing 207 of 271 actionable findings. 329 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
yarn.lock
yarn.lock
yarn.lock
yarn.lock
examples/graphiql-vite-react-router/public/robots.txt
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
yarn.lock
.github/workflows/update-cdn-example.yml:43 (2 hits).github/workflows/pr.yml:136.github/workflows/release.yml:53.github/workflows/update-cdn-example.yml
CI/CD securitySupply chainGithub actions
.github/workflows/release.yml
CI/CD securitySupply chainGithub actions
packages/graphiql-react/src/components/markdown-content/index.tsx:24
Dangerous innerhtml
yarn.lock
yarn.lock
yarn.lock
packages/graphiql-plugin-doc-explorer/src/schema-reference.ts:36packages/graphiql-react/src/components/variables-editor.tsx:36packages/graphiql-react/src/types.ts:4packages/graphql-language-service-server/src/GraphQLLanguageService.ts:104packages/graphql-language-service/src/interface/autocompleteUtils.ts:74packages/graphql-language-service/src/interface/getDiagnostics.ts:64packages/graphql-language-service/src/parser/Rules.ts:122packages/vscode-graphql-execution/src/helpers/source.ts:205yarn.lock
package.json
package.json
package.json
package.json (4 hits)package.json
package.json
package.json
package.json
package.json
package.json (2 hits)package.json
yarn.lock
examples/graphiql-vite-react-router/public/robots.txt
yarn.lock
yarn.lock
yarn.lock
yarn.lock
.github/workflows/pr.yml:15, 16, 22, 31, 32, 43, 44, 56, +14 more (22 hits).github/workflows/pr-graphql-compat-check.yml:34, 41 (2 hits).github/workflows/release.yml:40, 79 (2 hits).github/workflows/update-cdn-example.yml:21, 22 (2 hits)package.json
CI/CD securitySupply chainNpm
packages/cm6-graphql/package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/a584bcf6-918b-4edb-a5d7-ebcb192249d3/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/a584bcf6-918b-4edb-a5d7-ebcb192249d3/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.