https://github.com/nodejs/node
· scanned 2026-06-05 05:18 UTC (8 hours, 33 minutes ago)
· 10 languages
11114 findings (246 legacy + 10868 scanner) 11/13 scanners ran 60th percentile · Javascript · huge (>500K LoC) Scanner says 66 (higher by 22)
Last scanned 8 hours, 33 minutes ago · v2 · 5680 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
92.0 | 0.20 | 18.40 |
documentation_score |
88.0 | 0.15 | 13.20 |
practices_score |
87.0 | 0.15 | 13.05 |
code_quality |
56.0 | 0.10 | 5.60 |
| Overall | 1.00 | 88.0 |
Showing 135 of 5680 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
benchmark/process/handled-rejections.js:34
error_handlinglegacy
deps/v8/tools/dev/gm.py:539
qualitylegacy
deps/v8/tools/dev/gm.py:428
qualitylegacy
tools/gyp/pylib/gyp/MSVSUserFile.py:79
qualitylegacy
tools/gyp/pylib/gyp/xcode_emulation.py:1236
qualitylegacy
deps/v8/tools/run-clang-tidy.py:221
qualitylegacy
tools/gyp/pylib/gyp/common.py:526
qualitylegacy
deps/v8/tools/dev/gm.py:435
qualitylegacy
tools/gyp/pylib/gyp/generator/ninja.py:2885
qualitylegacy
tools/gyp/pylib/gyp/__init__.py:71
qualitylegacy
tools/gyp/pylib/gyp/__init__.py:71
qualitylegacy
deps/uv/docs/src/sphinx-plugins/manpage.py:30
qualitylegacy
deps/uv/docs/src/sphinx-plugins/manpage.py:30
qualitylegacy
deps/v8/tools/lldb_commands.py:46
qualitylegacy
benchmark/process/bench-env.js:32
qualitylegacy
deps/LIEF/include/LIEF/PE/Builder.hpp:83
qualitylegacy
.dockerignore
dockerlegacy
.dockerignore
dockerlegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
manifest.json
qualitylegacy
deps/openssl/openssl/crypto/asn1/tasn_new.c:1
qualitylegacy
deps/LIEF/third-party/mbedtls/library/ecp_internal_alt.h:1
qualitylegacy
deps/LIEF/third-party/mbedtls/library/ecp_curves_new.c:1
qualitylegacy
.github/workflows/create-release-proposal.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/scorecard.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/license-builder.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/timezone-update.yml
supply-chaingithub-actionsleast-privilege
deps/v8/third_party/ittapi/buildall.py:90
owaspsubprocess_shell_true
deps/v8/tools/android-run.py:57
owaspsubprocess_shell_true
deps/v8/tools/clusterfuzz/js_fuzzer/tools/fuzz_one.py:39
owaspsubprocess_shell_true
deps/v8/tools/clusterfuzz/js_fuzzer/tools/run_one.py:58
owaspsubprocess_shell_true
deps/v8/tools/dev/gen-tags.py:37
owaspsubprocess_shell_true
deps/v8/tools/dev/gm.py:324
owaspsubprocess_shell_true
deps/v8/tools/dev/setup-reclient.py:39
owaspsubprocess_shell_true
deps/v8/tools/dev/update-compile-commands.py:43
owaspsubprocess_shell_true
deps/v8/tools/disasm.py:79
owaspsubprocess_shell_true
deps/v8/tools/locs.py:142
owaspsubprocess_shell_true
deps/v8/tools/memory/rss.py:56
owaspsubprocess_shell_true
deps/v8/tools/profiling/linux-perf-chrome.py:314
owaspsubprocess_shell_true
deps/v8/tools/profiling/linux-perf-d8.py:292
owaspsubprocess_shell_true
deps/v8/tools/profiling/ll_prof.py:707
owaspsubprocess_shell_true
deps/v8/tools/release/common_includes.py:104
owaspsubprocess_shell_true
deps/v8/tools/run_perf.py:956
owaspsubprocess_shell_true
deps/v8/tools/sanitizers/sancov_formatter.py:181
owaspsubprocess_shell_true
deps/v8/tools/torque/format-torque.py:168
owaspsubprocess_shell_true
deps/v8/tools/try_perf.py:101
owaspsubprocess_shell_true
deps/v8/tools/v8_presubmit.py:550
owaspsubprocess_shell_true
tools/gyp/pylib/gyp/common.py:449
owaspsubprocess_shell_true
tools/gyp/pylib/gyp/input.py:900
owaspsubprocess_shell_true
tools/gyp/pylib/gyp/msvs_emulation.py:1190
owaspsubprocess_shell_true
tools/gyp/pylib/gyp/win_tool.py:251
owaspsubprocess_shell_true
tools/v8/fetch_deps.py:62
owaspsubprocess_shell_true
tools/v8/node_common.py:33
owaspsubprocess_shell_true
benchmark/crypto/rsa-sign-verify-throughput.js:21
owaspweak_hash
typings/internalBinding/constants.d.ts:244
owaspweak_hash
This page is publicly accessible at:
https://repobility.com/scan/f9fcf18e-aacd-473f-8572-887b663f1bea/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/f9fcf18e-aacd-473f-8572-887b663f1bea/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.