← Back to scan
File as GitHub Issue repo: neurons-me/all.this

Push this scan report to neurons-me/all.this

Click the green button below to open GitHub’s new-issue form, pre-filled with the report title, summary table, top findings, and an embedded score-card image. No authentication needed — you review on GitHub before submitting. Repobility is credited as the scanner.

Embedded score card image

This image will render at the top of the issue body. Hosted on Repobility, refreshes automatically after re-scans.

Repobility score card

Issue title

fast-uri: GHSA-q3j6-qgpj-74h6

Curate findings to include

Pick exactly which findings appear in the issue body. By default the top 5 are included. Uncheck noise, check what matters.

Top 5 (default)
Severity Rule Title File:line
CRIT GHSA-2h32-95rg-cppp @vitest/browser: GHSA-2h32-95rg-cppp pnpm-lock.yaml
HIGH GHSA-hvx9-hwr7-wjj9 systeminformation: GHSA-hvx9-hwr7-wjj9 pnpm-lock.yaml
HIGH GHSA-qjx8-664m-686j js-cookie: GHSA-qjx8-664m-686j pnpm-lock.yaml
HIGH GHSA-v39h-62p7-jpjc fast-uri: GHSA-v39h-62p7-jpjc pnpm-lock.yaml
HIGH GHSA-q3j6-qgpj-74h6 fast-uri: GHSA-q3j6-qgpj-74h6 pnpm-lock.yaml
HIGH GHSA-pjwm-pj3p-43mv axios: GHSA-pjwm-pj3p-43mv pnpm-lock.yaml
HIGH GHSA-p92q-9vqr-4j8v axios: GHSA-p92q-9vqr-4j8v pnpm-lock.yaml
HIGH GHSA-j5f8-grm9-p9fc axios: GHSA-j5f8-grm9-p9fc pnpm-lock.yaml
HIGH GHSA-hfxv-24rg-xrqf axios: GHSA-hfxv-24rg-xrqf pnpm-lock.yaml
HIGH GHSA-777c-7fjr-54vf axios: GHSA-777c-7fjr-54vf pnpm-lock.yaml
HIGH GHSA-35jp-ww65-95wh axios: GHSA-35jp-ww65-95wh pnpm-lock.yaml
HIGH CORE_NO_TESTS No test files found
MED GHSA-58qx-3vcg-4xpx ws: GHSA-58qx-3vcg-4xpx pnpm-lock.yaml
MED GHSA-4w7w-66w2-5vf9 vite: GHSA-4w7w-66w2-5vf9 pnpm-lock.yaml
MED GHSA-hcf7-66rw-9f5r turbo: GHSA-hcf7-66rw-9f5r pnpm-lock.yaml
MED GHSA-2j2x-hqr9-3h42 react-router: GHSA-2j2x-hqr9-3h42 pnpm-lock.yaml
MED GHSA-q8mj-m7cp-5q26 qs: GHSA-q8mj-m7cp-5q26 pnpm-lock.yaml
MED GHSA-67mh-4wv8-2f99 esbuild: GHSA-67mh-4wv8-2f99 pnpm-lock.yaml
MED GHSA-jxxr-4gwj-5jf2 brace-expansion: GHSA-jxxr-4gwj-5jf2 pnpm-lock.yaml
MED GHSA-898c-q2cr-xwhg axios: GHSA-898c-q2cr-xwhg pnpm-lock.yaml
MED AGT007 localStorage write failures are swallowed silently src/npm/src/boot/browser-global.js:114
MED CORE_NO_CI No CI/CD configuration found
LOW GHSA-3qcw-2rhx-2726 turbo: GHSA-3qcw-2rhx-2726 pnpm-lock.yaml
LOW GHSA-x5gf-qvw8-r2rm pm2: GHSA-x5gf-qvw8-r2rm pnpm-lock.yaml
LOW GHSA-654m-c8p4-x5fp axios: GHSA-654m-c8p4-x5fp pnpm-lock.yaml
LOW CORE_NO_LICENSE No LICENSE file
INFO MINED077 [MINED077] Python Open No Context: fp = open(path) outside with-block leaks file handles. src/pip/setup.py:8
Reset to top 5 27 findings available (after auto-suppression of test files + won't-fix)

Issue body (markdown)

## Code-quality scan: `neurons-me/all.this`

**Score: 82/100 (D+)**  ·  27 findings  ·  scanned 2026-06-05 17:10 UTC  ·  4,009 LOC

| Severity | Count |
|---|---|
| CRITICAL | 1 |
| HIGH | 11 |
| MEDIUM | 10 |
| LOW | 4 |

📊 [Full filterable report](https://repobility.com/scan/f43550d6-be9b-4cca-930d-1e237a032f03/)  ·  ![scorecard](https://repobility.com/scan/f43550d6-be9b-4cca-930d-1e237a032f03/report.png?v=1780679405-s2)

### Top findings

1. **CRITICAL** `GHSA-2h32-95rg-cppp` — @vitest/browser: GHSA-2h32-95rg-cppp
   `pnpm-lock.yaml`
2. **HIGH** `GHSA-hvx9-hwr7-wjj9` — systeminformation: GHSA-hvx9-hwr7-wjj9
   `pnpm-lock.yaml`
3. **HIGH** `GHSA-qjx8-664m-686j` — js-cookie: GHSA-qjx8-664m-686j
   `pnpm-lock.yaml`
4. **HIGH** `GHSA-v39h-62p7-jpjc` — fast-uri: GHSA-v39h-62p7-jpjc
   `pnpm-lock.yaml`
5. **HIGH** `GHSA-q3j6-qgpj-74h6` — fast-uri: GHSA-q3j6-qgpj-74h6
   `pnpm-lock.yaml`

---

_Filed automatically. Close this issue if not useful — we won't refile. Full report: https://repobility.com/scan/f43550d6-be9b-4cca-930d-1e237a032f03/_
Megaproject â high spam risk
Could not determine 'neurons-me/all.this' star count (GitHub API rate-limited or unreachable). When in doubt about repo size, prefer opening a focused PR or a discussion rather than an issue.

The button opens GitHubâs new-issue page in a new tab. You will see the title + body pre-filled â review, edit if you want, then click GitHubâs "Submit new issue" button. Repobility never posts anything on your behalf.

For real security findings on big repos: use the project's SECURITY.md or private advisory flow instead of a public issue.