Scan timing: clone 1.61s · analysis 4.66s · 6.7 MB · GitHub API rate-limit (preflight)
https://github.com/openai/openai-node
· scanned 2026-05-24 01:20 UTC (1 week, 5 days ago)
· 10 languages
1400 findings (66 legacy + 1334 scanner) 89th percentile · Typescript · large (100-500K LoC) Scanner says 67 (higher by 19)
Last scanned 1 week, 5 days ago · v7 · 257 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
96.0 | 0.25 | 24.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
89.0 | 0.15 | 13.35 |
practices_score |
69.0 | 0.15 | 10.35 |
code_quality |
50.7 | 0.10 | 5.07 |
| Overall | 1.00 | 85.5 |
Showing 208 of 257 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/ci.yml:149
dependencylegacy
.github/workflows/ci.yml:114
dependencylegacy
src/resources/uploads/uploads.ts:198
qualitylegacy
src/internal/to-file.ts:153
xsslegacy
src/_vendor/zod-to-json-schema/parsers/string.ts:389
qualitylegacy
src/internal/utils/path.ts:56
qualitylegacy
src/internal/detect-platform.ts:143
qualitylegacy
examples/stream-to-client-express.ts:29
qualitylegacy
examples/stream-to-client-raw.ts:31
qualitylegacy
examples/package.json:1
dependencylegacy
package.json:1
dependencylegacy
src/_vendor/partial-json-parser/parser.ts:209
error_handlinglegacy
.github/workflows/publish-jsr.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/create-releases.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/publish-npm.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/ci.yml
supply-chaingithub-actionsleast-privilege
src/resources/admin/organization/projects/users/index.ts:1
qualitylegacy
src/resources/admin/organization/projects/groups/roles.ts:46
qualitylegacy
src/resources/admin/organization/projects/groups/index.ts:10
qualitylegacy
src/resources/admin/organization/projects/groups/groups.ts:2
qualitylegacy
src/resources/admin/organization/projects/certificates.ts:69
qualitylegacy
src/resources/admin/organization/organization.ts:234
qualitylegacy
src/realtime/ws.ts:39
qualitylegacy
src/realtime/ws.ts:4
qualitylegacy
src/realtime/websocket.ts:6
qualitylegacy
src/realtime/internal-base.ts:14
qualitylegacy
src/lib/responses/ResponseStream.ts:246
qualitylegacy
src/lib/parser.ts:105
qualitylegacy
src/lib/EventStream.ts:43
qualitylegacy
src/lib/EventEmitter.ts:1
qualitylegacy
src/lib/ChatCompletionStream.ts:447
qualitylegacy
src/internal/ws-adapter-node.ts:11
qualitylegacy
src/internal/stream-utils.ts:1
qualitylegacy
src/beta/realtime/ws.ts:40
qualitylegacy
src/_vendor/zod-to-json-schema/parsers/number.ts:24
qualitylegacy
package.json
supply-chainnpminstall-scripts
src/auth/subject-token-providers.ts:146
qualitylegacy
examples/function-call-diy.ts:84
qualitylegacy
examples/azure/chat.ts:25
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/e4d4c80f-102b-4c6f-b2fd-1a5fa991e3a4/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/e4d4c80f-102b-4c6f-b2fd-1a5fa991e3a4/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.