Scan timing: clone 4.63s · analysis 10.16s · 27.9 MB · GitHub API rate-limit (preflight)
https://github.com/astral-sh/uv
· scanned 2026-05-31 01:25 UTC (5 days, 7 hours ago)
· 10 languages
493 findings (142 legacy + 351 scanner) 11/13 scanners ran 60th percentile · Rust · huge (>500K LoC) Scanner says 73 (higher by 11)
Last scanned 5 days, 7 hours ago · v2 · 320 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
84.0 | 0.20 | 16.80 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
35.0 | 0.10 | 3.50 |
| Overall | 1.00 | 84.3 |
Showing 272 of 320 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
crates/uv-configuration/src/proxy_url.rs:169
qualitylegacy
.github/workflows/ci.yml:353
dependencylegacy
.github/workflows/ci.yml:352
dependencylegacy
.github/workflows/ci.yml:407
dependencylegacy
.github/workflows/ci.yml:406
dependencylegacy
.github/workflows/ci.yml:405
dependencylegacy
.github/workflows/ci.yml:390
dependencylegacy
.github/workflows/ci.yml:404
dependencylegacy
.github/workflows/ci.yml:408
dependencylegacy
.github/workflows/ci.yml:396
dependencylegacy
.github/workflows/ci.yml:403
dependencylegacy
crates/uv-auth/src/middleware.rs:1048
secrets
crates/uv-auth/src/middleware.rs:1094
secrets
crates/uv-auth/src/middleware.rs:1208
secrets
crates/uv-auth/src/middleware.rs:1249
secrets
crates/uv-auth/src/middleware.rs:1297
secrets
crates/uv-auth/src/middleware.rs:1337
secrets
crates/uv-auth/src/middleware.rs:1380
secrets
crates/uv-auth/src/middleware.rs:1445
secrets
crates/uv-auth/src/middleware.rs:1510
secrets
crates/uv-auth/src/middleware.rs:1541
secrets
crates/uv-auth/src/middleware.rs:2231
secrets
crates/uv-auth/src/middleware.rs:2326
secrets
crates/uv-auth/src/middleware.rs:2422
secrets
crates/uv-auth/src/middleware.rs:2536
secrets
crates/uv-auth/src/middleware.rs:2568
secrets
crates/uv-auth/src/middleware.rs:2591
secrets
crates/uv-auth/src/store.rs:493
secrets
crates/uv-client/src/registry_client.rs:1739
secrets
crates/uv-client/src/registry_client.rs:1795
secrets
crates/uv-client/src/registry_client.rs:1845
secrets
crates/uv-keyring/src/mock.rs:286
secrets
crates/uv-keyring/src/secret_service.rs:64
secrets
crates/uv-keyring/src/secret_service.rs:801
secrets
crates/uv-keyring/src/windows.rs:759
secrets
crates/uv/src/commands/auth/login.rs:142
secrets
crates/uv/src/commands/publish.rs:598
secrets
crates/uv-virtualenv/src/_virtualenv.py:80
qualitylegacy
.claude/hooks/post-edit-format.py:22
qualitylegacy
crates/uv-platform/src/cpuinfo.rs:71
qualitylegacy
crates/uv-extract/src/hash.rs:11
qualitylegacy
python/uv/__main__.py:43
qualitylegacy
crates/uv/src/commands/build_backend.rs:56
qualitylegacy
crates/uv-resolver/src/dependency_provider.rs:30
qualitylegacy
crates/uv-macros/src/lib.rs:32
qualitylegacy
scripts/scenarios/generate.py:84
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:102
qualitylegacy
scripts/benchmark/src/benchmark/tools.py:36
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:104
qualitylegacy
scripts/benchmark/src/benchmark/tools.py:38
qualitylegacy
scripts/scenarios/generate.py:82
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:94
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:98
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:100
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:96
qualitylegacy
scripts/benchmark/src/benchmark/tools.py:40
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:775
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:536
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:810
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:581
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:661
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:389
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:1058
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:700
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:443
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:745
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:499
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:678
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:416
qualitylegacy
scripts/benchmark/src/benchmark/resolver.py:1079
qualitylegacy
scripts/scenarios/generate.py:85
qualitylegacy
crates/uv-dev/builder.dockerfile:3
dependencylegacy
.github/workflows/build-release-binaries.yml:361
dependencylegacy
.pre-commit-config.yaml:9
dependencylegacy
.pre-commit-config.yaml:45
dependencylegacy
.pre-commit-config.yaml:13
dependencylegacy
crates/uv-trampoline-builder/trampolines/uv-trampoline-aarch64-console.exe:1
dependencylegacy
crates/uv-trampoline-builder/trampolines/uv-trampoline-aarch64-gui.exe:1
dependencylegacy
crates/uv-trampoline-builder/trampolines/uv-trampoline-i686-console.exe:1
dependencylegacy
crates/uv-trampoline-builder/trampolines/uv-trampoline-i686-gui.exe:1
dependencylegacy
crates/uv-trampoline-builder/trampolines/uv-trampoline-x86_64-console.exe:1
dependencylegacy
crates/uv-trampoline-builder/trampolines/uv-trampoline-x86_64-gui.exe:1
dependencylegacy
scripts/update_schemastore.py:38
injectionlegacy
scripts/publish-crates.py:80
path_traversallegacy
scripts/repair-sdist-cargo-lock.py:32
qualitylegacy
scripts/sync-python-version-constants.py:81
injectionlegacy
crates/uv-trampoline/Dockerfile:38
dockerlegacy
scripts/repair-sdist-cargo-lock.py:32
path_traversallegacy
.dockerignore
dockerlegacy
crates/uv-trampoline/Dockerfile:63
dockerlegacy
docs/reference/installer.md:57
dependencylegacy
docs/getting-started/installation.md:16
dependencylegacy
.github/workflows/publish-crates.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/publish-pypi.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/sync-python-releases.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/build-docker.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/ci.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release-prepare.yml
supply-chaingithub-actionsleast-privilege
crates/uv-trampoline/Dockerfile
securityports
crates/uv-trampoline/Dockerfile:28
dockerlegacy
crates/uv/src/commands/pip/install.rs:226
qualitylegacy
crates/uv/src/commands/pip/install.rs:158
qualitylegacy
crates/uv/src/commands/cache_prune.rs:11
qualitylegacy
crates/uv/src/commands/auth/token.rs:32
qualitylegacy
crates/uv-resolver/src/resolver/reporter.rs:15
qualitylegacy
crates/uv-resolver/src/resolver/environment.rs:412
qualitylegacy
crates/uv-resolver/src/lock/tree.rs:79
qualitylegacy
crates/uv-resolver/src/lock/installable.rs:104
qualitylegacy
crates/uv-requirements/src/unnamed.rs:28
qualitylegacy
crates/uv-requirements/src/source_tree.rs:71
qualitylegacy
crates/uv-requirements/src/lookahead.rs:33
qualitylegacy
crates/uv-pypi-types/src/metadata/requires_dist.rs:37
qualitylegacy
crates/uv-publish/src/trusted_publishing/pyx.rs:35
qualitylegacy
crates/uv-platform-tags/src/platform.rs:110
qualitylegacy
crates/uv-platform-tags/src/language_tag.rs:3
qualitylegacy
crates/uv-normalize/src/package_name.rs:7
qualitylegacy
crates/uv-normalize/src/lib.rs:128
qualitylegacy
crates/uv-keyring/src/windows.rs:498
qualitylegacy
crates/uv-installer/src/satisfies.rs:386
qualitylegacy
crates/uv-keyring/src/windows.rs:490
qualitylegacy
crates/uv-keyring/src/secret_service.rs:438
qualitylegacy
crates/uv-keyring/src/mock.rs:154
qualitylegacy
crates/uv-install-wheel/src/uninstall.rs:312
qualitylegacy
crates/uv-distribution/src/metadata/requires_dist.rs:190
qualitylegacy
crates/uv-distribution/src/metadata/requires_dist.rs:152
qualitylegacy
crates/uv-dev/src/generate_sysconfig_mappings.rs:50
qualitylegacy
crates/uv-dev/src/generate_sysconfig_mappings.rs:28
qualitylegacy
crates/uv-dev/src/generate_options_reference.rs:25
qualitylegacy
crates/uv-dev/src/generate_options_reference.rs:11
qualitylegacy
crates/uv-configuration/src/sources.rs:30
qualitylegacy
crates/uv/src/commands/self_update.rs:1
qualitylegacy
crates/uv/src/commands/cache_clean.rs:1
qualitylegacy
crates/uv-python/fetch-download-metadata.py:722
dead-code
crates/uv-configuration/src/trusted_host.rs:97
qualitylegacy
crates/uv-configuration/src/proxy_url.rs:66
qualitylegacy
crates/uv-auth/src/realm.rs:279
qualitylegacy
crates/uv-requirements/src/lookahead.rs:155
qualitylegacy
crates/uv-keyring/src/error.rs:88
qualitylegacy
crates/uv-extract/src/lib.rs:142
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/bee51646-a8dc-410c-9ffa-753bd32e1390/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/bee51646-a8dc-410c-9ffa-753bd32e1390/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.