https://github.com/vm0-ai/vm0
· scanned 2026-05-31 01:27 UTC (5 days, 6 hours ago)
· 10 languages
1670 findings (261 legacy + 1409 scanner) 11/13 scanners ran 42nd percentile · Typescript · huge (>500K LoC) Scanner says 59 (higher by 24)
Last scanned 5 days, 6 hours ago · v2 · last Δ -4.4 (diff) · 950 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
98.0 | 0.15 | 14.70 |
practices_score |
82.0 | 0.15 | 12.30 |
code_quality |
51.0 | 0.10 | 5.10 |
| Overall | 1.00 | 83.1 |
Showing 688 of 950 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
turbo/apps/api/src/signals/services/zero-custom-connector.service.ts:211
qualitylegacy
.github/workflows/crates.yml:295
dependencylegacy
.github/workflows/crates.yml:438
dependencylegacy
.github/workflows/crates.yml:181
dependencylegacy
.github/workflows/crates.yml:1075
dependencylegacy
.github/workflows/crates.yml:884
dependencylegacy
.github/workflows/crates.yml:772
dependencylegacy
.github/workflows/crates.yml:510
dependencylegacy
.github/workflows/crates.yml:454
dependencylegacy
.github/workflows/crates.yml:395
dependencylegacy
.github/workflows/crates.yml:1076
dependencylegacy
.github/workflows/crates.yml:885
dependencylegacy
.github/workflows/crates.yml:773
dependencylegacy
.github/workflows/crates.yml:511
dependencylegacy
.github/workflows/crates.yml:455
dependencylegacy
.github/workflows/crates.yml:396
dependencylegacy
.github/workflows/crates.yml:886
dependencylegacy
.github/workflows/crates.yml:774
dependencylegacy
.github/workflows/crates.yml:512
dependencylegacy
.github/workflows/crates.yml:456
dependencylegacy
.github/workflows/crates.yml:397
dependencylegacy
.github/workflows/crates.yml:286
dependencylegacy
.github/workflows/crates.yml:891
dependencylegacy
.github/workflows/crates.yml:779
dependencylegacy
.github/workflows/crates.yml:517
dependencylegacy
.github/workflows/crates.yml:461
dependencylegacy
turbo/packages/firewalls-generator/src/sendgrid.ts:17
credential_exposurelegacy
turbo/packages/firewalls-generator/src/clerk.ts:42
secretlegacy
turbo/packages/firewalls-generator/src/gitlab.ts:14
secretlegacy
crates/api-contracts/src/generated/model_providers.rs:23
secrets
crates/vsock-guest/src/user.rs:261
secrets
crates/vsock-guest/src/user.rs:274
secrets
turbo/packages/api-contracts/src/contracts/model-providers.ts:979
secrets
turbo/packages/api-contracts/src/contracts/model-providers.ts:969
secrets
turbo/packages/api-contracts/src/contracts/model-providers.ts:982
secrets
turbo/packages/connectors/src/connectors/servicenow.ts:40
secrets
turbo/packages/firewalls-generator/src/bland.ts:12
secrets
turbo/packages/firewalls-generator/src/cronlytic.ts:4
secrets
turbo/packages/firewalls-generator/src/deepseek.ts:14
secrets
turbo/packages/firewalls-generator/src/stability-ai.ts:14
secrets
turbo/apps/web/app/f/[userId]/[id]/[filename]/route.ts:45
authlegacy
turbo/apps/web/proxy.cors.ts:99
qualitylegacy
turbo/apps/web/app/f/[userId]/[id]/[filename]/route.ts:38
qualitylegacy
.github/workflows/release-please.yml:90
dependencylegacy
.github/workflows/crates.yml:1444
dependencylegacy
.github/workflows/crates.yml:1304
dependencylegacy
.github/workflows/crates.yml:1070
dependencylegacy
.github/workflows/crates.yml:879
dependencylegacy
.github/workflows/crates.yml:767
dependencylegacy
.github/workflows/crates.yml:505
dependencylegacy
.github/workflows/crates.yml:449
dependencylegacy
.github/workflows/crates.yml:429
dependencylegacy
.github/workflows/crates.yml:375
dependencylegacy
.github/workflows/crates.yml:325
dependencylegacy
.github/workflows/crates.yml:309
dependencylegacy
.github/workflows/crates.yml:251
dependencylegacy
.github/workflows/crates.yml:84
dependencylegacy
.github/workflows/crates.yml:339
dependencylegacy
.github/workflows/crates.yml:326
dependencylegacy
.github/workflows/crates.yml:284
dependencylegacy
.github/workflows/crates.yml:336
dependencylegacy
.github/workflows/release-please.yml:263
dependencylegacy
.github/workflows/release-please.yml:240
dependencylegacy
.github/workflows/release-please.yml:215
dependencylegacy
.github/workflows/release-please.yml:100
dependencylegacy
.github/workflows/crates.yml:376
dependencylegacy
.github/workflows/crates.yml:252
dependencylegacy
.github/workflows/release-please.yml:39
dependencylegacy
docker/toolchain/Dockerfile:2
dependencylegacy
.github/workflows/runner-image.yml:202
dependencylegacy
.github/workflows/rollback-runner.yml:53
dependencylegacy
.github/workflows/release-please.yml:1883
dependencylegacy
.github/workflows/release-please.yml:1647
dependencylegacy
.github/workflows/crates.yml:364
dependencylegacy
.github/workflows/crates.yml:247
dependencylegacy
.github/workflows/crates.yml:61
dependencylegacy
.github/workflows/turbo.yml:393
dependencylegacy
.github/workflows/turbo.yml:380
dependencylegacy
.github/workflows/turbo.yml:356
dependencylegacy
.github/workflows/turbo.yml:108
dependencylegacy
.github/workflows/cleanup-stale.yml:20
dependencylegacy
.github/workflows/cleanup.yml:85
dependencylegacy
.github/workflows/release-please.yml:2074
dependencylegacy
.github/workflows/release-please.yml:2050
dependencylegacy
.github/workflows/release-please.yml:1110
dependencylegacy
.github/workflows/release-please.yml:994
dependencylegacy
.github/workflows/release-please.yml:876
dependencylegacy
.github/workflows/release-please.yml:749
dependencylegacy
.github/workflows/release-please.yml:603
dependencylegacy
.github/workflows/release-please.yml:414
dependencylegacy
.github/workflows/release-please.yml:283
dependencylegacy
.github/workflows/release-please.yml:85
dependencylegacy
.github/workflows/crates.yml:303
dependencylegacy
.github/workflows/security.yml:63
dependencylegacy
crates/runner/mitm-addon/scripts/update-x-tlds.py:48
path_traversallegacy
turbo/apps/platform/src/signals/zero-page/clipboard.ts:191
xxelegacy
turbo/packages/firewalls-generator/src/docusign.ts:44
xsslegacy
turbo/packages/firewalls-generator/src/browserless.ts:21
xsslegacy
turbo/packages/firewalls-generator/src/atlassian.ts:26
xsslegacy
turbo/apps/cli/src/commands/volume/pull.ts:97
qualitylegacy
turbo/apps/cli/src/commands/artifact/pull.ts:104
qualitylegacy
turbo/apps/cli/src/commands/zero/connector/connected-as.ts:33
qualitylegacy
turbo/apps/platform/src/signals/usage-page/usage-insight-signals.ts:153
qualitylegacy
turbo/apps/platform/custom-eslint/rules/no-raw-msw-http.ts:109
qualitylegacy
crates/runner/src/main.rs:68
qualitylegacy
scripts/cf-ssh.sh:116
cryptolegacy
turbo/apps/desktop/src/desktop-renderer-url.ts:29
path_traversallegacy
turbo/apps/api/src/signals/services/zero-runs-create.service.ts:224
authlegacy
docker/toolchain/Dockerfile:49
dockerlegacy
docker/toolchain/Dockerfile:19
dockerlegacy
turbo/apps/platform/src/views/device-bb0/bb0-device-page.tsx:246
authlegacy
docker/toolchain/Dockerfile:19
supply-chaindockerremote-installer
docker/toolchain/Dockerfile:49
supply-chaindockerremote-installer
turbo/apps/web/app/f/[userId]/[id]/[filename]/route.ts:45
authlegacy
turbo/apps/web/app/monday-app-association.json/route.ts:4
authlegacy
turbo/apps/platform/custom-eslint/rules/no-empty-promise-catch.ts:46
error_handlinglegacy
turbo/apps/platform/src/views/router/link.tsx:55
securitylegacy
turbo/apps/platform/src/signals/zero-page/zero-github.ts:203
securitylegacy
turbo/apps/platform/src/signals/zero-page/telegram-login-popup.ts:27
securitylegacy
turbo/apps/web/app/desktop-auth/consume/DesktopAuthConsumeClient.tsx:61
open_redirectlegacy
turbo/apps/web/app/desktop-auth/callback/DesktopAuthCallbackClient.tsx:87
open_redirectlegacy
crates/ably-subscriber/src/connection/endpoint.rs:331
qualitylegacy
.dockerignore
dockerlegacy
docker/toolchain/Dockerfile:123
dockerlegacy
turbo/apps/api/src/signals/services/built-in-generation-provider-webhooks.service.ts:56
qualitylegacy
turbo/apps/api/src/signals/services/agent-webhook-events.service.ts:67
qualitylegacy
turbo/apps/api/src/signals/services/agent-webhook-events.service.ts:62
qualitylegacy
turbo/apps/api/src/signals/routes/zero-integrations-telegram.ts:50
qualitylegacy
turbo/apps/api/src/signals/routes/zero-integrations-slack.ts:51
qualitylegacy
turbo/apps/api/src/signals/routes/zero-integrations-github-download-file.ts:19
qualitylegacy
turbo/apps/api/src/signals/routes/zero-connectors.ts:558
qualitylegacy
turbo/apps/api/src/signals/routes/zero-chat-messages.ts:250
qualitylegacy
turbo/apps/api/src/signals/routes/model-stats.ts:62
qualitylegacy
turbo/apps/api/src/signals/routes/model-stats.ts:32
qualitylegacy
turbo/apps/api/src/signals/routes/internal-event-consumers-telegram-typing.ts:68
qualitylegacy
turbo/apps/api/src/signals/routes/internal-event-consumers-agentphone-typing.ts:92
qualitylegacy
turbo/apps/api/src/signals/routes/internal-callbacks-chat.ts:164
qualitylegacy
turbo/apps/api/src/signals/routes/github-oauth.ts:57
qualitylegacy
turbo/apps/api/src/signals/routes/zero-web-download.ts:20
qualitylegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
.github/workflows/crates.yml:275
supply-chaingithub-actionspinned-dependencies
.github/workflows/crates.yml:284
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:100
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:215
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:240
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:263
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:300
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:328
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:378
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:394
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:431
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:458
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:512
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:528
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:614
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:662
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:678
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:763
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:774
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:809
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:831
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-please.yml:847
supply-chaingithub-actionspinned-dependencies
.github/workflows/rollback-runner.yml:85
supply-chaingithub-actionspinned-dependencies
.github/workflows/rollback-runner.yml:199
supply-chaingithub-actionspinned-dependencies
.github/workflows/rollback-runner.yml:215
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-toolchain-publish.yml:40
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-toolchain-publish.yml:43
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-toolchain-publish.yml:51
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-toolchain-publish.yml:66
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-toolchain-publish.yml:81
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-toolchain-publish.yml:127
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-toolchain-publish.yml:130
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-toolchain.yml:36
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-toolchain.yml:41
supply-chaingithub-actionspinned-dependencies
.github/workflows/security.yml:111
supply-chaingithub-actionspinned-dependencies
.github/workflows/security.yml:127
supply-chaingithub-actionspinned-dependencies
.github/workflows/security.yml:135
supply-chaingithub-actionspinned-dependencies
.github/workflows/turbo.yml:449
supply-chaingithub-actionspinned-dependencies
.github/workflows/turbo.yml:456
supply-chaingithub-actionspinned-dependencies
.github/workflows/turbo.yml:594
supply-chaingithub-actionspinned-dependencies
Showing first 300 of 688. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/c5e1fbe1-170b-4f36-b3c5-d92f53e41551/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/c5e1fbe1-170b-4f36-b3c5-d92f53e41551/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.