← Back to scan
File as GitHub Issue repo: kzahel/yepanywhere

Push this scan report to kzahel/yepanywhere

Click the green button below to open GitHub’s new-issue form, pre-filled with the report title, summary table, top findings, and an embedded score-card image. No authentication needed — you review on GitHub before submitting. Repobility is credited as the scanner.

Embedded score card image

This image will render at the top of the issue body. Hosted on Repobility, refreshes automatically after re-scans.

Repobility score card

Issue title

h3: GHSA-22cc-p3c6-wpvm

Curate findings to include

Pick exactly which findings appear in the issue body. By default the top 5 are included. Uncheck noise, check what matters.

Top 5 (default)
Severity Rule Title File:line
HIGH GHSA-p9ff-h696-f583 vite: GHSA-p9ff-h696-f583 site/package-lock.json
HIGH GHSA-xpqw-6gx7-v673 svgo: GHSA-xpqw-6gx7-v673 site/package-lock.json
HIGH GHSA-c2c7-rcm5-vvqj picomatch: GHSA-c2c7-rcm5-vvqj site/package-lock.json
HIGH GHSA-r5fr-rjxr-66jc lodash: GHSA-r5fr-rjxr-66jc site/package-lock.json
HIGH GHSA-22cc-p3c6-wpvm h3: GHSA-22cc-p3c6-wpvm site/package-lock.json
HIGH GHSA-v39h-62p7-jpjc fast-uri: GHSA-v39h-62p7-jpjc site/package-lock.json
HIGH GHSA-q3j6-qgpj-74h6 fast-uri: GHSA-q3j6-qgpj-74h6 site/package-lock.json
HIGH GHSA-77vg-94rm-hx3p devalue: GHSA-77vg-94rm-hx3p site/package-lock.json
HIGH GHSA-737v-mqg7-c878 defu: GHSA-737v-mqg7-c878 site/package-lock.json
HIGH GHSA-vrm6-8vpv-qv8q undici: GHSA-vrm6-8vpv-qv8q sharing-worker/package-lock.json
HIGH GHSA-v9p9-hfj2-hcw8 undici: GHSA-v9p9-hfj2-hcw8 sharing-worker/package-lock.json
HIGH GHSA-f269-vfmq-vjvj undici: GHSA-f269-vfmq-vjvj sharing-worker/package-lock.json
HIGH GHSA-v2wj-q39q-566r vite: GHSA-v2wj-q39q-566r pnpm-lock.yaml
HIGH GHSA-p9ff-h696-f583 vite: GHSA-p9ff-h696-f583 pnpm-lock.yaml
HIGH GHSA-rxv8-25v2-qmq8 react-router: GHSA-rxv8-25v2-qmq8 pnpm-lock.yaml
HIGH GHSA-8x6r-g9mw-2r78 react-router: GHSA-8x6r-g9mw-2r78 pnpm-lock.yaml
HIGH GHSA-8646-j5j9-6r62 react-router: GHSA-8646-j5j9-6r62 pnpm-lock.yaml
HIGH GHSA-49rj-9fvp-4h2h react-router: GHSA-49rj-9fvp-4h2h pnpm-lock.yaml
HIGH GHSA-c2c7-rcm5-vvqj picomatch: GHSA-c2c7-rcm5-vvqj pnpm-lock.yaml
HIGH GHSA-v39h-62p7-jpjc fast-uri: GHSA-v39h-62p7-jpjc pnpm-lock.yaml
HIGH GHSA-q3j6-qgpj-74h6 fast-uri: GHSA-q3j6-qgpj-74h6 pnpm-lock.yaml
HIGH RUSTSEC-2025-0098 unic-ucd-version: RUSTSEC-2025-0098 packages/mobile/src-tauri/Cargo.lock
HIGH RUSTSEC-2025-0100 unic-ucd-ident: RUSTSEC-2025-0100 packages/mobile/src-tauri/Cargo.lock
HIGH RUSTSEC-2025-0080 unic-common: RUSTSEC-2025-0080 packages/mobile/src-tauri/Cargo.lock
HIGH RUSTSEC-2025-0075 unic-char-range: RUSTSEC-2025-0075 packages/mobile/src-tauri/Cargo.lock
HIGH RUSTSEC-2025-0081 unic-char-property: RUSTSEC-2025-0081 packages/mobile/src-tauri/Cargo.lock
HIGH RUSTSEC-2024-0370 proc-macro-error: RUSTSEC-2024-0370 packages/mobile/src-tauri/Cargo.lock
HIGH JRN009 Secret-like setting is echoed into a password input value packages/client/src/pages/LoginPage.tsx:105
HIGH JRN009 Secret-like setting is echoed into a password input value packages/client/src/pages/DirectLoginPa…:173
HIGH JRN009 Secret-like setting is echoed into a password input value packages/client/src/components/RemoteAc…:535
MED SEC091 [SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read… packages/device-bridge/cmd/bridge/main.…:93
MED SEC046 [SEC046] Client-side open redirect — window.location = server-supplied URL: Assigning win… packages/desktop/src/main/MainLayout.tsx:74
MED ERR002 [ERR002] Empty Catch Block: Empty catch blocks hide errors. packages/client/src/pages/settings/Abou…:67
MED SEC045 [SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even … packages/relay/src/client-ip.ts:93
MED SEC045 [SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even … packages/client/src/contexts/PublicShar…:178
MED SEC045 [SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even … packages/client/src/components/Thinking…:20
MED MINED111 Bare except continues silently packages/server/src/services/voice/whis…:87
MED MINED111 Bare except continues silently packages/server/src/services/voice/whis…:45
MED COMP001 [COMP001] High cognitive complexity: Function `main` has cognitive complexity 15 (SonarSo… packages/server/src/services/voice/whis…:32
MED DKR002 Compose service `yep-sandbox` image has no explicit tag docker/docker-compose.yml:14
MED DKR007 Docker build context has no .dockerignore .dockerignore
MED DEPCUR-NPM npm package `shiki` is 1 major version(s) behind (3.23.0 -> 4.2.0) packages/server/package.json
MED DEPCUR-NPM npm package `marked` is 1 major version(s) behind (^17.0.1 -> 18.0.5) packages/server/package.json
MED DEPCUR-NPM npm package `diff` is 1 major version(s) behind (8.0.3 -> 9.0.0) packages/server/package.json
MED DEPCUR-NPM npm package `@hono/node-server` is 1 major version(s) behind (^1.19.9 -> 2.0.4) packages/server/package.json
MED GHSA-48c2-rrv3-qjmp yaml: GHSA-48c2-rrv3-qjmp site/package-lock.json
MED GHSA-4w7w-66w2-5vf9 vite: GHSA-4w7w-66w2-5vf9 site/package-lock.json
MED GHSA-v3rj-xjv7-4jmq smol-toml: GHSA-v3rj-xjv7-4jmq site/package-lock.json
MED GHSA-qx2v-qp2m-jg93 postcss: GHSA-qx2v-qp2m-jg93 site/package-lock.json
MED GHSA-3v7f-55p6-f55p picomatch: GHSA-3v7f-55p6-f55p site/package-lock.json
MED GHSA-xxjr-mmjv-4gpg lodash: GHSA-xxjr-mmjv-4gpg site/package-lock.json
MED GHSA-f23m-r3pf-42rh lodash: GHSA-f23m-r3pf-42rh site/package-lock.json
MED GHSA-wr4h-v87w-p3r7 h3: GHSA-wr4h-v87w-p3r7 site/package-lock.json
MED GHSA-72gr-qfp7-vwhw h3: GHSA-72gr-qfp7-vwhw site/package-lock.json
MED GHSA-4hxc-9384-m385 h3: GHSA-4hxc-9384-m385 site/package-lock.json
MED GHSA-cfw5-2vxh-hr84 devalue: GHSA-cfw5-2vxh-hr84 site/package-lock.json
MED GHSA-j687-52p2-xcff astro: GHSA-j687-52p2-xcff site/package-lock.json
MED GHSA-58qx-3vcg-4xpx ws: GHSA-58qx-3vcg-4xpx sharing-worker/package-lock.json
MED GHSA-phc3-fgpg-7m6h undici: GHSA-phc3-fgpg-7m6h sharing-worker/package-lock.json
MED GHSA-4992-7rv2-5pvq undici: GHSA-4992-7rv2-5pvq sharing-worker/package-lock.json
MED GHSA-2mjp-6q6p-2qxm undici: GHSA-2mjp-6q6p-2qxm sharing-worker/package-lock.json
MED GHSA-58qx-3vcg-4xpx ws: GHSA-58qx-3vcg-4xpx pnpm-lock.yaml
MED GHSA-4w7w-66w2-5vf9 vite: GHSA-4w7w-66w2-5vf9 pnpm-lock.yaml
MED GHSA-f22v-gfqf-p8f3 react-router: GHSA-f22v-gfqf-p8f3 pnpm-lock.yaml
MED GHSA-2j2x-hqr9-3h42 react-router: GHSA-2j2x-hqr9-3h42 pnpm-lock.yaml
MED GHSA-q8mj-m7cp-5q26 qs: GHSA-q8mj-m7cp-5q26 pnpm-lock.yaml
MED GHSA-qx2v-qp2m-jg93 postcss: GHSA-qx2v-qp2m-jg93 pnpm-lock.yaml
MED GHSA-3v7f-55p6-f55p picomatch: GHSA-3v7f-55p6-f55p pnpm-lock.yaml
MED GHSA-v2v4-37r5-5v8g ip-address: GHSA-v2v4-37r5-5v8g pnpm-lock.yaml
MED GHSA-xrhx-7g5j-rcj5 hono: GHSA-xrhx-7g5j-rcj5 pnpm-lock.yaml
MED GHSA-xpcf-pg52-r92g hono: GHSA-xpcf-pg52-r92g pnpm-lock.yaml
MED GHSA-xf4j-xp2r-rqqx hono: GHSA-xf4j-xp2r-rqqx pnpm-lock.yaml
MED GHSA-wmmm-f939-6g9c hono: GHSA-wmmm-f939-6g9c pnpm-lock.yaml
MED GHSA-r5rp-j6wh-rvv4 hono: GHSA-r5rp-j6wh-rvv4 pnpm-lock.yaml
MED GHSA-qp7p-654g-cw7p hono: GHSA-qp7p-654g-cw7p pnpm-lock.yaml
MED GHSA-p77w-8qqv-26rm hono: GHSA-p77w-8qqv-26rm pnpm-lock.yaml
MED GHSA-f577-qrjj-4474 hono: GHSA-f577-qrjj-4474 pnpm-lock.yaml
MED GHSA-9vqf-7f2p-gf9v hono: GHSA-9vqf-7f2p-gf9v pnpm-lock.yaml
MED GHSA-69xw-7hcm-h432 hono: GHSA-69xw-7hcm-h432 pnpm-lock.yaml
MED GHSA-458j-xx4x-4375 hono: GHSA-458j-xx4x-4375 pnpm-lock.yaml
MED GHSA-3hrh-pfw6-9m5x hono: GHSA-3hrh-pfw6-9m5x pnpm-lock.yaml
MED GHSA-2gcr-mfcq-wcc3 hono: GHSA-2gcr-mfcq-wcc3 pnpm-lock.yaml
MED GHSA-26pp-8wgv-hjvm hono: GHSA-26pp-8wgv-hjvm pnpm-lock.yaml
MED GHSA-r4q5-vmmm-2653 follow-redirects: GHSA-r4q5-vmmm-2653 pnpm-lock.yaml
MED GHSA-67mh-4wv8-2f99 esbuild: GHSA-67mh-4wv8-2f99 pnpm-lock.yaml
MED GHSA-92pp-h63x-v22m @hono/node-server: GHSA-92pp-h63x-v22m pnpm-lock.yaml
MED GHSA-7gmj-67g7-phm9 tauri: GHSA-7gmj-67g7-phm9 packages/desktop/src-tauri/Cargo.lock
MED GHSA-3pv8-6f4r-ffg2 tar: GHSA-3pv8-6f4r-ffg2 packages/desktop/src-tauri/Cargo.lock
MED GHSA-xv59-967r-8726 openssl: GHSA-xv59-967r-8726 packages/desktop/src-tauri/Cargo.lock
MED GHSA-phqj-4mhp-q6mq openssl: GHSA-phqj-4mhp-q6mq packages/desktop/src-tauri/Cargo.lock
MED AGT007 localStorage write failures are swallowed silently packages/client/src/lib/hostStorage.ts:59
MED AGT007 localStorage write failures are swallowed silently packages/client/src/hooks/useSession.ts:338
MED AGT007 localStorage write failures are swallowed silently packages/client/src/hooks/useRemoteComp…:27
MED AGT007 localStorage write failures are swallowed silently packages/client/src/hooks/useDrafts.ts:163
MED AGT007 localStorage write failures are swallowed silently packages/client/src/hooks/useDraftPersi…:27
MED AGT007 localStorage write failures are swallowed silently packages/client/src/contexts/RemoteConn…:169
MED AGT007 localStorage write failures are swallowed silently packages/client/src/components/CodexUpd…:19
MED WEB003 Public web service has no security.txt .well-known/security.txt
MED AGT016 Codex session log reader may expose prompts or tool-call content packages/server/src/projects/scanner.ts:19
MED AGT016 Codex session log reader may expose prompts or tool-call content packages/server/src/projects/paths.ts:26
MED AGT016 Codex session log reader may expose prompts or tool-call content packages/server/src/indexes/SessionInde…:84
MED AGT016 Codex session log reader may expose prompts or tool-call content packages/client/e2e/global-setup.ts:30
MED AGT012 Agent control bridge may listen on a network interface without visible auth packages/server/src/routes/server-info.…:17
MED AGT012 Agent control bridge may listen on a network interface without visible auth packages/server/src/cli.ts:85
MED WEB015 Public web app has no Content Security Policy index.html
MED AGT015 Remote install command pipes network code directly to a shell packages/server/src/index.ts:212
MED AGT015 Remote install command pipes network code directly to a shell docs/archive/claude-anywhere-vision.md:299
MED AGT013 Agent auto-approve or skip-permissions mode is easy to enable docs/research/subscription-access-appro…:44
MED AGT013 Agent auto-approve or skip-permissions mode is easy to enable docs/competitive/emdash.md:42
LOW ERR003 [ERR003] Ignored Error (Go): Ignoring error return values. packages/device-bridge/internal/device/…:60
LOW ERR003 [ERR003] Ignored Error (Go): Ignoring error return values. packages/device-bridge/cmd/bridge/main.…:81
LOW DEPCUR-NPM npm package `@tauri-apps/cli` is minor version(s) behind (^2 -> 2.11.2) packages/desktop/package.json
LOW DEPCUR-NPM npm package `@xterm/addon-fit` is minor version(s) behind (^0.10.0 -> 0.11.0) packages/desktop/package.json
LOW DEPCUR-NPM npm package `@tauri-apps/plugin-updater` is minor version(s) behind (^2 -> 2.10.1) packages/desktop/package.json
LOW DEPCUR-NPM npm package `@tauri-apps/plugin-shell` is minor version(s) behind (^2 -> 2.3.5) packages/desktop/package.json
LOW DEPCUR-NPM npm package `@tauri-apps/plugin-process` is minor version(s) behind (^2 -> 2.3.1) packages/desktop/package.json
LOW DEPCUR-NPM npm package `@tauri-apps/plugin-opener` is minor version(s) behind (^2 -> 2.5.4) packages/desktop/package.json
LOW DEPCUR-NPM npm package `@tauri-apps/api` is minor version(s) behind (^2 -> 2.11.0) packages/desktop/package.json
LOW DEPCUR-NPM npm package `@tauri-apps/cli` is minor version(s) behind (^2 -> 2.11.2) packages/mobile/package.json
LOW DEPCUR-NPM npm package `tsx` is minor version(s) behind (^4.19.2 -> 4.22.4) packages/server/package.json
LOW DEPCUR-NPM npm package `ws` is minor version(s) behind (8.18.0 -> 8.21.0) packages/server/package.json
LOW DEPCUR-NPM npm package `pino` is minor version(s) behind (^10.1.0 -> 10.3.1) packages/server/package.json
LOW DEPCUR-NPM npm package `katex` is minor version(s) behind (^0.16.45 -> 0.17.0) packages/server/package.json
LOW DEPCUR-NPM npm package `@hono/node-ws` is minor version(s) behind (^1.2.0 -> 1.3.1) packages/server/package.json
LOW DEPCUR-NPM npm package `@agentclientprotocol/sdk` is minor version(s) behind (^0.12.0 -> 0.25.0) packages/server/package.json
LOW DEPCUR-NPM npm package `@cloudflare/workers-types` is minor version(s) behind (4.20260302.0 -> 4.202… sharing-worker/package.json
LOW DEPCUR-NPM npm package `tsx` is minor version(s) behind (^4.19.2 -> 4.22.4) package.json
LOW GHSA-mwv9-gp5h-frr4 devalue: GHSA-mwv9-gp5h-frr4 site/package-lock.json
LOW GHSA-xr5h-phrj-8vxv astro: GHSA-xr5h-phrj-8vxv site/package-lock.json
LOW GHSA-g735-7g2w-hh3f astro: GHSA-g735-7g2w-hh3f site/package-lock.json
LOW GHSA-hm8q-7f3q-5f36 hono: GHSA-hm8q-7f3q-5f36 pnpm-lock.yaml
LOW GHSA-xmgf-hq76-4vx2 openssl: GHSA-xmgf-hq76-4vx2 packages/desktop/src-tauri/Cargo.lock
LOW AIC003 Duplicated implementation block across source files packages/client/vite.config.ts:11
LOW AIC003 Duplicated implementation block across source files packages/client/src/pages/RemoteLoginMo…:17
LOW AIC003 Duplicated implementation block across source files packages/client/src/pages/RelayLoginPag…:108
LOW AIC003 Duplicated implementation block across source files packages/client/src/pages/PublicSharePa…:225
LOW AIC003 Duplicated implementation block across source files packages/client/src/pages/ProjectsPage.…:171
LOW AIC003 Duplicated implementation block across source files packages/client/src/pages/ProjectsPage.…:117
LOW AIC003 Duplicated implementation block across source files packages/client/src/pages/ProjectsPage.…:116
LOW AIC003 Duplicated implementation block across source files packages/client/src/pages/HostPickerPag…:170
LOW AIC003 Duplicated implementation block across source files packages/client/src/pages/GitStatusPage…:104
LOW AIC003 Duplicated implementation block across source files packages/client/src/lib/connection/Dire…:13
LOW AIC003 Duplicated implementation block across source files packages/client/src/hooks/useToast.ts:16
LOW AIC003 Duplicated implementation block across source files packages/client/src/hooks/useSessionWat…:57
LOW AIC003 Duplicated implementation block across source files packages/client/src/hooks/useModelSetti…:119
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/ui/Modal…:37
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/ui/CopyT…:70
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/renderer…:242
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/renderer…:62
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/renderer…:104
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/renderer…:212
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/renderer…:113
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/renderer…:29
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/YepAnywh…:37
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/ToolAppr…:192
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/SidebarN…:132
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/Sidebar.…:436
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/RestartS…:638
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/ProjectS…:47
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/ProjectC…:69
LOW AIC003 Duplicated implementation block across source files packages/client/src/components/ModeSele…:44
LOW AIC003 Duplicated implementation block across source files packages/client/src/RemoteApp.tsx:49
LOW WEB001 Public web app has no robots.txt robots.txt
LOW WEB002 Public web app has no sitemap sitemap.xml
LOW DKR011 Dockerfile installs recommended OS packages docker/Dockerfile:8
LOW AIC009 Multiple AI-agent scaffold marker files are present .cursorrules:1
LOW WEB008 Public docs site has no llms.txt llms.txt
LOW AIC002 Source file name looks like an AI patch artifact site/public/branding/yepanywhere-final.…:1
LOW DKC006 Compose service does not declare a runtime user docker/docker-compose.yml:14
LOW WEB011 Public web app has no humans.txt humans.txt
LOW CORE_NO_LICENSE No LICENSE file
INFO MINED055 [MINED055] Npm Install No Lockfile: Production image runs npm install (resolves new versi… scripts/build-bundle.ts:319
INFO MINED065 [MINED065] Cors Wildcard: Access-Control-Allow-Origin: * exposes the API to any browser o… packages/relay/src/server.ts:23
INFO MINED065 [MINED065] Cors Wildcard: Access-Control-Allow-Origin: * exposes the API to any browser o… packages/relay/src/origin-policy.ts:212
INFO MINED065 [MINED065] Cors Wildcard: Access-Control-Allow-Origin: * exposes the API to any browser o… packages/relay/src/index.ts:13
INFO MINED060 [MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g… packages/device-bridge/internal/emulato…:46
INFO MINED060 [MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g… packages/device-bridge/internal/device/…:29
INFO MINED060 [MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g… packages/device-bridge/cmd/validate/mai…:50
INFO MINED068 [MINED068] Rust Unsafe Block: unsafe { ... } block. Compiler safety guarantees disabled i… packages/desktop/src-tauri/src/server.rs:31
INFO MINED059 [MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message. packages/mobile/src-tauri/src/lib.rs:51
INFO MINED059 [MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message. packages/desktop/src-tauri/src/lib.rs:107
INFO MINED059 [MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message. packages/desktop/src-tauri/src/config.rs:27
INFO MINED043 [MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr… packages/shared/src/ya-client-url.ts:32
INFO MINED043 [MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr… packages/client/src/pages/DirectLoginPa…:78
INFO MINED045 [MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError … packages/client/vite-plugin-csp.ts:27
INFO MINED045 [MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError … packages/client/src/hooks/useSpeechReco…:137
INFO MINED045 [MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError … packages/client/src/hooks/useNotifyInAp…:19
INFO MINED056 [MINED056] React Key As Index: key={index} in map() — re-renders the wrong elements on re… packages/desktop/src/wizard/WizardLayou…:91
INFO MINED056 [MINED056] React Key As Index: key={index} in map() — re-renders the wrong elements on re… packages/client/src/components/Thinking…:196
INFO MINED058 [MINED058] React Dangerously Set Html: dangerouslySetInnerHTML bypasses Reacts JSX escapi… packages/client/src/components/renderer…:38
INFO MINED058 [MINED058] React Dangerously Set Html: dangerouslySetInnerHTML bypasses Reacts JSX escapi… packages/client/src/components/blocks/T…:199
INFO MINED058 [MINED058] React Dangerously Set Html: dangerouslySetInnerHTML bypasses Reacts JSX escapi… packages/client/src/components/Markdown…:161
INFO MINED044 [MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger … packages/client/src/components/ErrorBou…:43
INFO MINED044 [MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger … packages/client/src/api/upload.ts:139
INFO MINED044 [MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger … docs/tasks/archive/analyze-claude-messa…:372
INFO DEPCUR-NPM npm package `@types/sanitize-html` is patch version(s) behind (^2.16.0 -> 2.16.1) packages/server/package.json
INFO DEPCUR-NPM npm package `sanitize-html` is patch version(s) behind (^2.17.1 -> 2.17.4) packages/server/package.json
INFO DEPCUR-NPM npm package `@anthropic-ai/claude-agent-sdk` is patch version(s) behind (^0.3.158 -> 0.3.… packages/server/package.json
INFO DEPCUR-NPM npm package `@astrojs/sitemap` is patch version(s) behind (3.7.0 -> 3.7.3) site/package.json
INFO DEPCUR-NPM npm package `@astrojs/check` is patch version(s) behind (0.9.6 -> 0.9.9) site/package.json
Reset to top 5 200 findings available (after auto-suppression of test files + won't-fix)

Issue body (markdown)

## Code-quality scan: `kzahel/yepanywhere`

**Score: 50/100 (C+)**  ·  410 findings  ·  scanned 2026-06-05 19:09 UTC  ·  286,659 LOC

| Severity | Count |
|---|---|
| CRITICAL | 24 |
| HIGH | 214 |
| MEDIUM | 79 |
| LOW | 62 |

📊 [Full filterable report](https://repobility.com/scan/eda2b2c7-9bb0-4fd6-b7c0-98d81de29a7a/)  ·  ![scorecard](https://repobility.com/scan/eda2b2c7-9bb0-4fd6-b7c0-98d81de29a7a/report.png?v=1780686568-s2)

### Top findings

1. **HIGH** `GHSA-p9ff-h696-f583` — vite: GHSA-p9ff-h696-f583
   `site/package-lock.json`
2. **HIGH** `GHSA-xpqw-6gx7-v673` — svgo: GHSA-xpqw-6gx7-v673
   `site/package-lock.json`
3. **HIGH** `GHSA-c2c7-rcm5-vvqj` — picomatch: GHSA-c2c7-rcm5-vvqj
   `site/package-lock.json`
4. **HIGH** `GHSA-r5fr-rjxr-66jc` — lodash: GHSA-r5fr-rjxr-66jc
   `site/package-lock.json`
5. **HIGH** `GHSA-22cc-p3c6-wpvm` — h3: GHSA-22cc-p3c6-wpvm
   `site/package-lock.json`

---

_Filed automatically. Close this issue if not useful — we won't refile. Full report: https://repobility.com/scan/eda2b2c7-9bb0-4fd6-b7c0-98d81de29a7a/_
Already filed
This repo publishes a SECURITY.md policy and the scan contains 20 Critical/High security finding(s). Public issue filing would violate coordinated disclosure. Submit privately via the project's security reporting channel.
Megaproject â high spam risk
Could not determine 'kzahel/yepanywhere' star count (GitHub API rate-limited or unreachable). When in doubt about repo size, prefer opening a focused PR or a discussion rather than an issue.

The button opens GitHubâs new-issue page in a new tab. You will see the title + body pre-filled â review, edit if you want, then click GitHubâs "Submit new issue" button. Repobility never posts anything on your behalf.

For real security findings on big repos: use the project's SECURITY.md or private advisory flow instead of a public issue.