https://github.com/dubinc/dub
· scanned 2026-05-16 12:50 UTC (1 day, 6 hours ago)
· 10 languages
831 findings (12 legacy + 819 scanner) 2/10 scanners ran 16th percentile · Typescript · large (100-500K LoC)
Last scanned 3 days ago · v1 · 823 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Showing 823 of 823 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/playwright.yaml:36
secrets
.github/workflows/playwright.yaml:58
secrets
apps/web/playwright/partners/auth.setup.ts:6
secrets
apps/web/playwright/seed.ts:11
secrets
apps/web/playwright/workspaces/auth.setup.ts:6
secrets
apps/web/ui/support/code-block.tsx:146
ssrflegacy
apps/web/ui/domains/domain-card-title-column.tsx:75
ssrflegacy
apps/web/middleware.ts:85
ssrflegacy
apps/web/ui/links/link-builder/use-metatags.ts:60
error_handlinglegacy
.github/workflows/deploy-embed-script.yml:20
supply-chaingithub-actionspinned-dependencies
.github/workflows/prettier.yaml:20
supply-chaingithub-actionspinned-dependencies
.github/workflows/playwright.yaml:128
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e.yaml:16
supply-chaingithub-actionspinned-dependencies
apps/web/app/app.dub.co/(auth)/oauth/authorize/scopes-requested.tsx:44
owaspdangerous_innerhtml
apps/web/app/app.dub.co/(dashboard)/[slug]/(ee)/settings/logs/[logId]/page-client.tsx:222
owaspdangerous_innerhtml
apps/web/ui/domains/domain-configuration.tsx:129
owaspdangerous_innerhtml
apps/web/ui/guides/markdown.tsx:105
owaspdangerous_innerhtml
apps/web/ui/postbacks/postback-event-details-sheet.tsx:99
owaspdangerous_innerhtml
apps/web/ui/support/code-block.tsx:198
owaspdangerous_innerhtml
apps/web/ui/webhooks/webhook-event-details-sheet.tsx:99
owaspdangerous_innerhtml
packages/ui/src/form.tsx:69
owaspdangerous_innerhtml
.github/workflows/deploy-embed-script.yml:17
supply-chaingithub-actionspinned-dependencies
.github/workflows/prettier.yaml:17
supply-chaingithub-actionspinned-dependencies
.github/workflows/playwright.yaml:114
supply-chaingithub-actionspinned-dependencies
.github/workflows/playwright.yaml:131
supply-chaingithub-actionspinned-dependencies
.github/workflows/playwright.yaml:141
supply-chaingithub-actionspinned-dependencies
.github/workflows/apply-issue-labels-to-pr.yml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e.yaml:13
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e.yaml:19
supply-chaingithub-actionspinned-dependencies
Showing first 300 of 823. Refine filters or use the legacy findings page for deep search.
{# ── 2026-05-17 Round 14: AI-agent bridge footer ────────────────────── Discoverability: the /agents/voting/ guide + MCP manifest exist but aren't linked from anywhere users actually land. Small, opt-in footer. #}
This page is publicly accessible at:
https://repobility.com/scan/e8971222-160d-42f1-967c-5e0c4aa69c35/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/e8971222-160d-42f1-967c-5e0c4aa69c35/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.