← Back to scan
File as GitHub Issue repo: sharkdp/bat

Push this scan report to sharkdp/bat

Click the green button below to open GitHub’s new-issue form, pre-filled with the report title, summary table, top findings, and an embedded score-card image. No authentication needed — you review on GitHub before submitting. Repobility is credited as the scanner.

Embedded score card image

This image will render at the top of the issue body. Hosted on Repobility, refreshes automatically after re-scans.

Repobility score card

Issue title

Rust Unwrap In Prod

Curate findings to include

Pick exactly which findings appear in the issue body. By default the top 5 are included. Uncheck noise, check what matters.

Top 5 (default)
Severity Rule Title File:line
CRIT MINED107 Missing import: `array` used but not imported tests/benchmarks/highlighting-speed-src…:7397
CRIT MINED116 Workflow uses `secrets.WINGET_TOKEN` on a `pull_request` trigger .github/workflows/CICD.yml:464
CRIT GHSA-pr76-5cm5-w9cj gitpython: GHSA-pr76-5cm5-w9cj assets/syntaxes/02_Extra/syntax_test_re…
CRIT GHSA-hcpj-qp55-gfph gitpython: GHSA-hcpj-qp55-gfph assets/syntaxes/02_Extra/syntax_test_re…
HIGH MINED003 [MINED003] Rust Unwrap In Prod: .unwrap() panics if None/Err. Acceptable in tests; risky … examples/cat.rs:12
HIGH MINED003 [MINED003] Rust Unwrap In Prod: .unwrap() panics if None/Err. Acceptable in tests; risky … examples/buffer.rs:19
HIGH MINED003 [MINED003] Rust Unwrap In Prod: .unwrap() panics if None/Err. Acceptable in tests; risky … examples/advanced.rs:17
HIGH MINED108 `self.three` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:274
HIGH MINED108 `self.three` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:268
HIGH MINED108 `self.two` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:267
HIGH MINED108 `self.one` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:266
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:225
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:224
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:222
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:228
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:227
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:226
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:220
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:219
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:218
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:217
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:216
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:215
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:214
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:213
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:212
HIGH MINED108 `self.arr` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:107
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:84
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:81
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:86
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:85
HIGH MINED108 `self.a` used but never assigned in __init__ tests/benchmarks/highlighting-speed-src…:77
HIGH MINED106 Phantom test coverage: test_dtypeattr tests/benchmarks/highlighting-speed-src…:291
HIGH MINED106 Phantom test coverage: test_attributes tests/benchmarks/highlighting-speed-src…:270
HIGH MINED106 Phantom test coverage: test_int tests/benchmarks/highlighting-speed-src…:244
HIGH MINED106 Phantom test coverage: test_void_align tests/benchmarks/highlighting-speed-src…:237
HIGH MINED106 Phantom test coverage: test_string_align tests/benchmarks/highlighting-speed-src…:230
HIGH MINED106 Phantom test coverage: test_otherflags tests/benchmarks/highlighting-speed-src…:211
HIGH MINED106 Phantom test coverage: test_warnonwrite tests/benchmarks/highlighting-speed-src…:201
HIGH MINED106 Phantom test coverage: test_writeable_pickle tests/benchmarks/highlighting-speed-src…:150
HIGH MINED106 Phantom test coverage: test_writeable_from_buffer tests/benchmarks/highlighting-speed-src…:132
HIGH MINED106 Phantom test coverage: test_writeable_from_readonly tests/benchmarks/highlighting-speed-src…:121
HIGH MINED106 Phantom test coverage: test_writeable_any_base tests/benchmarks/highlighting-speed-src…:88
HIGH MINED106 Phantom test coverage: test_writeable tests/benchmarks/highlighting-speed-src…:79
HIGH MINED106 Phantom test coverage: test_getfield tests/benchmarks/highlighting-speed-src…:8457
HIGH MINED106 Phantom test coverage: test_uintalignment_and_alignment tests/benchmarks/highlighting-speed-src…:8350
HIGH MINED106 Phantom test coverage: test_npymath_real tests/benchmarks/highlighting-speed-src…:8329
HIGH MINED106 Phantom test coverage: test_npymath_complex tests/benchmarks/highlighting-speed-src…:8310
HIGH MINED106 Phantom test coverage: test_equal_override tests/benchmarks/highlighting-speed-src…:8284
HIGH MINED106 Phantom test coverage: test_orderconverter_with_nonASCII_unicode_ordering tests/benchmarks/highlighting-speed-src…:8278
HIGH MINED106 Phantom test coverage: test_scalar_element_deletion tests/benchmarks/highlighting-speed-src…:7461
HIGH MINED106 Phantom test coverage: test_flat_element_deletion tests/benchmarks/highlighting-speed-src…:7450
HIGH MINED106 Phantom test coverage: test_array_interface_offset tests/benchmarks/highlighting-speed-src…:7436
HIGH MINED106 Phantom test coverage: test_array_interface_empty_shape tests/benchmarks/highlighting-speed-src…:7411
HIGH MINED106 Phantom test coverage: test_array_interface_itemsize tests/benchmarks/highlighting-speed-src…:7401
HIGH MINED106 Phantom test coverage: test_interface_no_shape tests/benchmarks/highlighting-speed-src…:7394
HIGH MINED106 Phantom test coverage: test_matmul_inplace tests/benchmarks/highlighting-speed-src…:6329
HIGH MINED115 Action `softprops/action-gh-release` pinned to mutable ref `@v2` .github/workflows/CICD.yml:445
HIGH MINED115 Action `actions/upload-artifact` pinned to mutable ref `@master` .github/workflows/CICD.yml:431
HIGH MINED115 Action `actions/upload-artifact` pinned to mutable ref `@master` .github/workflows/CICD.yml:425
HIGH MINED115 Action `dtolnay/rust-toolchain` pinned to mutable ref `@stable` .github/workflows/CICD.yml:192
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/CICD.yml:181
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/CICD.yml:153
HIGH MINED115 Action `dtolnay/rust-toolchain` pinned to mutable ref `@stable` .github/workflows/CICD.yml:140
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/CICD.yml:138
HIGH MINED115 Action `dtolnay/rust-toolchain` pinned to mutable ref `@stable` .github/workflows/CICD.yml:127
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/CICD.yml:122
HIGH MINED115 Action `dtolnay/rust-toolchain` pinned to mutable ref `@stable` .github/workflows/CICD.yml:97
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/CICD.yml:93
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/CICD.yml:83
HIGH MINED115 Action `dtolnay/rust-toolchain` pinned to mutable ref `@master` .github/workflows/CICD.yml:73
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/CICD.yml:71
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/CICD.yml:61
HIGH MINED115 Action `dtolnay/rust-toolchain` pinned to mutable ref `@stable` .github/workflows/CICD.yml:58
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/CICD.yml:38
HIGH MINED115 Action `actions/checkout` pinned to mutable ref `@v6` .github/workflows/require-changelog-for…:16
HIGH MINED121 requirements.txt installs from `https://github.com/pallets/click/archive/7.0.zip#e...` (g… tests/syntax-tests/source/Requirements.…:40
HIGH MINED121 requirements.txt installs from `-e bzr+https://bzr.myproject.org/MyProject/trunk@2...` (g… tests/syntax-tests/source/Requirements.…:37
HIGH MINED121 requirements.txt installs from `-e bzr+ssh://[email protected]/MyProject/trunk#eg...` (g… tests/syntax-tests/source/Requirements.…:36
HIGH MINED121 requirements.txt installs from `-e svn+http://svn.myproject.org/svn/MyProject/trun...` (g… tests/syntax-tests/source/Requirements.…:35
HIGH MINED121 requirements.txt installs from `-e hg+http://hg.myproject.org/MyProject@da39a3ee5e...` (g… tests/syntax-tests/source/Requirements.…:34
HIGH MINED121 requirements.txt installs from `-e hg+https://hg.myproject.org/MyProject#egg=MyPro...` (g… tests/syntax-tests/source/Requirements.…:33
HIGH MINED121 requirements.txt installs from `-e git+git://git.myproject.org/MyProject#egg=MyPro...` (g… tests/syntax-tests/source/Requirements.…:31
HIGH MINED121 requirements.txt installs from `pip @ https://github.com/pypa/pip/archive/1.3.1.zi...` (g… tests/syntax-tests/source/Requirements.…:26
HIGH GO-2026-5039 stdlib: GO-2026-5039 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-5038 stdlib: GO-2026-5038 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-5037 stdlib: GO-2026-5037 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4986 stdlib: GO-2026-4986 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4982 stdlib: GO-2026-4982 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4981 stdlib: GO-2026-4981 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4980 stdlib: GO-2026-4980 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4977 stdlib: GO-2026-4977 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4976 stdlib: GO-2026-4976 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4971 stdlib: GO-2026-4971 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4947 stdlib: GO-2026-4947 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4946 stdlib: GO-2026-4946 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4918 stdlib: GO-2026-4918 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4870 stdlib: GO-2026-4870 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4869 stdlib: GO-2026-4869 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4865 stdlib: GO-2026-4865 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4864 stdlib: GO-2026-4864 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4603 stdlib: GO-2026-4603 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4602 stdlib: GO-2026-4602 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4601 stdlib: GO-2026-4601 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4342 stdlib: GO-2026-4342 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4341 stdlib: GO-2026-4341 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4340 stdlib: GO-2026-4340 tests/syntax-tests/source/Go/go.mod
HIGH GO-2026-4337 stdlib: GO-2026-4337 tests/syntax-tests/source/Go/go.mod
HIGH GO-2025-4175 stdlib: GO-2025-4175 tests/syntax-tests/source/Go/go.mod
HIGH GO-2025-4155 stdlib: GO-2025-4155 tests/syntax-tests/source/Go/go.mod
HIGH GO-2025-4015 stdlib: GO-2025-4015 tests/syntax-tests/source/Go/go.mod
HIGH GO-2025-4014 stdlib: GO-2025-4014 tests/syntax-tests/source/Go/go.mod
HIGH GO-2025-4013 stdlib: GO-2025-4013 tests/syntax-tests/source/Go/go.mod
HIGH GO-2025-4012 stdlib: GO-2025-4012 tests/syntax-tests/source/Go/go.mod
HIGH GO-2025-4011 stdlib: GO-2025-4011 tests/syntax-tests/source/Go/go.mod
HIGH GO-2025-4010 stdlib: GO-2025-4010 tests/syntax-tests/source/Go/go.mod
HIGH GO-2025-4009 stdlib: GO-2025-4009 tests/syntax-tests/source/Go/go.mod
HIGH GO-2025-4008 stdlib: GO-2025-4008 tests/syntax-tests/source/Go/go.mod
HIGH GO-2025-4007 stdlib: GO-2025-4007 tests/syntax-tests/source/Go/go.mod
HIGH GO-2025-4006 stdlib: GO-2025-4006 tests/syntax-tests/source/Go/go.mod
HIGH GHSA-x2qx-6953-8485 gitpython: GHSA-x2qx-6953-8485 assets/syntaxes/02_Extra/syntax_test_re…
HIGH GHSA-v87r-6q3f-2j67 gitpython: GHSA-v87r-6q3f-2j67 assets/syntaxes/02_Extra/syntax_test_re…
HIGH GHSA-mv93-w799-cj2w gitpython: GHSA-mv93-w799-cj2w assets/syntaxes/02_Extra/syntax_test_re…
HIGH GHSA-7545-fcxq-7j24 gitpython: GHSA-7545-fcxq-7j24 assets/syntaxes/02_Extra/syntax_test_re…
HIGH GHSA-2mqj-m65w-jghx gitpython: GHSA-2mqj-m65w-jghx assets/syntaxes/02_Extra/syntax_test_re…
HIGH PYSEC-2023-165 gitpython: PYSEC-2023-165 assets/syntaxes/02_Extra/syntax_test_re…
HIGH PYSEC-2023-161 gitpython: PYSEC-2023-161 assets/syntaxes/02_Extra/syntax_test_re…
HIGH PYSEC-2023-117 pygments: PYSEC-2023-117 assets/syntaxes/02_Extra/syntax_test_re…
HIGH PYSEC-2021-66 jinja2: PYSEC-2021-66 assets/syntaxes/02_Extra/syntax_test_re…
HIGH PYSEC-2019-217 jinja2: PYSEC-2019-217 assets/syntaxes/02_Extra/syntax_test_re…
HIGH RUSTSEC-2024-0320 yaml-rust: RUSTSEC-2024-0320 Cargo.lock
HIGH RUSTSEC-2025-0141 bincode: RUSTSEC-2025-0141 Cargo.lock
MED DKR007 Docker build context has no .dockerignore .dockerignore
MED DEPCUR-GHA GitHub Action `softprops/action-gh-release@v2` is 1 major version(s) behind (latest v3.0.… .github/workflows/CICD.yml:445
MED DEPCUR-PY Python package `zope.interface` is 4 major version(s) behind (4.2.0 -> 8.5) tests/syntax-tests/source/Requirements.…:21
MED DEPCUR-PY Python package `sphinx-rtd-theme` is 3 major version(s) behind (0.1.9 -> 3.1.0) tests/syntax-tests/source/Requirements.…:19
MED DEPCUR-PY Python package `Sphinx` is 8 major version(s) behind (1.3.3 -> 9.1.0) tests/syntax-tests/source/Requirements.…:18
MED DEPCUR-PY Python package `snowballstemmer` is 2 major version(s) behind (1.2.0 -> 3.1.1) tests/syntax-tests/source/Requirements.…:17
MED DEPCUR-PY Python package `pytz` is 11 major version(s) behind (2015.7 -> 2026.2) tests/syntax-tests/source/Requirements.…:15
MED DEPCUR-PY Python package `MarkupSafe` is 3 major version(s) behind (0.23 -> 3.0.3) tests/syntax-tests/source/Requirements.…:13
MED DEPCUR-PY Python package `alabaster` is 1 major version(s) behind (0.7.6 -> 1.0.0) tests/syntax-tests/source/Requirements.…:6
MED MINED124 requirements.txt: `https://github.com/pallets/click/archive/7.0.zip#e… tests/syntax-tests/highlighted/Requirem…:40
MED MINED124 requirements.txt: `# Project or archive URL` … tests/syntax-tests/highlighted/Requirem…:39
MED MINED124 requirements.txt: `-e hg… tests/syntax-tests/highlighted/Requirem…:33
MED MINED124 requirements.txt: `-e gi… tests/syntax-tests/highlighted/Requirem…:31
MED MINED124 requirements.txt: `# VCS repositories` has no… tests/syntax-tests/highlighted/Requirem…:30
MED MINED124 requirements.txt: `# c.f. https://www.python.org/… tests/syntax-tests/highlighted/Requirem…:24
MED MINED124 requirements.txt: `# Examples from PEP508` ha… tests/syntax-tests/highlighted/Requirem…:23
MED MINED124 requirements.txt: `# Freeze packages` has no … tests/syntax-tests/highlighted/Requirem…:5
MED MINED124 requirements.txt: `--allow-unverified` has no version pin tests/syntax-tests/highlighted/Requirem…:3
MED MINED124 requirements.txt: `--allow-external` has no version pin tests/syntax-tests/highlighted/Requirem…:2
MED MINED124 requirements.txt: `# Options` has no version … tests/syntax-tests/highlighted/Requirem…:1
MED GHSA-q2x7-8rv6-6q7h jinja2: GHSA-q2x7-8rv6-6q7h assets/syntaxes/02_Extra/syntax_test_re…
MED GHSA-h75v-3vvj-5mfj jinja2: GHSA-h75v-3vvj-5mfj assets/syntaxes/02_Extra/syntax_test_re…
MED GHSA-h5c8-rqwp-cp95 jinja2: GHSA-h5c8-rqwp-cp95 assets/syntaxes/02_Extra/syntax_test_re…
MED GHSA-cpwx-vrp4-4pq7 jinja2: GHSA-cpwx-vrp4-4pq7 assets/syntaxes/02_Extra/syntax_test_re…
MED DKR001 Docker final stage has no non-root USER tests/syntax-tests/source/Dockerfile/Do…:2
LOW DEPCUR-PY Python package `six` is minor version(s) behind (1.10.0 -> 1.17.0) tests/syntax-tests/source/Requirements.…:16
LOW DEPCUR-PY Python package `Pygments` is minor version(s) behind (2.7.4 -> 2.20.0) tests/syntax-tests/source/Requirements.…:14
LOW DEPCUR-PY Python package `gitpython` is minor version(s) behind (3.0.7 -> 3.1.50) tests/syntax-tests/source/Requirements.…:10
LOW DEPCUR-PY Python package `docutils` is minor version(s) behind (0.12 -> 0.23) tests/syntax-tests/source/Requirements.…:8
LOW GHSA-5239-wwwm-4pmq pygments: GHSA-5239-wwwm-4pmq assets/syntaxes/02_Extra/syntax_test_re…
LOW AIC007 Generated build artifact directory is present at repository root build:1
INFO MINED043 [MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr… src/less.rs:48
INFO MINED043 [MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr… src/assets/build_assets/acknowledgement…:96
INFO MINED059 [MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message. src/output.rs:36
INFO MINED059 [MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message. src/assets/build_assets/acknowledgement…:137
INFO MINED059 [MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message. src/assets/assets_metadata.rs:69
INFO DEPCUR-GHA GitHub Action `actions/checkout@v6` is patch version(s) behind (latest v6.0.3) .github/workflows/CICD.yml:38
INFO DEPCUR-GHA GitHub Action `actions/checkout@v6` is patch version(s) behind (latest v6.0.3) .github/workflows/require-changelog-for…:16
Reset to top 5 170 findings available (after auto-suppression of test files + won't-fix)

Issue body (markdown)

## Code-quality scan: `sharkdp/bat`

**Score: 74/100 (B+)**  ·  170 findings  ·  scanned 2026-06-04 22:46 UTC  ·  37,106 LOC

| Severity | Count |
|---|---|
| CRITICAL | 4 |
| HIGH | 128 |
| MEDIUM | 25 |
| LOW | 6 |

📊 [Full filterable report](https://repobility.com/scan/b504f98d-17fc-4f9d-a9ba-35a8204074a9/)  ·  ![scorecard](https://repobility.com/scan/b504f98d-17fc-4f9d-a9ba-35a8204074a9/report.png?v=1780613174-s2)

### Top findings

1. **CRITICAL** `MINED107` — Missing import: `array` used but not imported
   `tests/benchmarks/highlighting-speed-src/numpy_test_multiarray.py:7397` · ✓ Repobility
2. **CRITICAL** `MINED116` — Workflow uses `secrets.WINGET_TOKEN` on a `pull_request` trigger
   `.github/workflows/CICD.yml:464` · ✓ Repobility
3. **CRITICAL** `GHSA-pr76-5cm5-w9cj` — gitpython: GHSA-pr76-5cm5-w9cj
   `assets/syntaxes/02_Extra/syntax_test_requirements.txt`
4. **CRITICAL** `GHSA-hcpj-qp55-gfph` — gitpython: GHSA-hcpj-qp55-gfph
   `assets/syntaxes/02_Extra/syntax_test_requirements.txt`
5. **HIGH** `MINED003` — Rust Unwrap In Prod
   `examples/cat.rs:12` · CWE-755 · ✓ Repobility

---

_Filed automatically. Close this issue if not useful — we won't refile. Full report: https://repobility.com/scan/b504f98d-17fc-4f9d-a9ba-35a8204074a9/_
Megaproject â high spam risk
Could not determine 'sharkdp/bat' star count (GitHub API rate-limited or unreachable). When in doubt about repo size, prefer opening a focused PR or a discussion rather than an issue.
Already filed
162/173 findings (94%) on this scan are already flagged as test-file, won't-fix, or suppressed. The scan is too noisy to file as a single issue. Curate down to specific actionable findings, or address the FP source first.

The button opens GitHubâs new-issue page in a new tab. You will see the title + body pre-filled â review, edit if you want, then click GitHubâs "Submit new issue" button. Repobility never posts anything on your behalf.

For real security findings on big repos: use the project's SECURITY.md or private advisory flow instead of a public issue.