https://github.com/nodejs/node
· scanned 2026-06-05 05:18 UTC (2 hours, 31 minutes ago)
· 10 languages
11114 findings (246 legacy + 10868 scanner) 11/13 scanners ran Scanner says 66 (higher by 22)
Last scanned 2 hours, 31 minutes ago · v2 · 5680 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
92.0 | 0.20 | 18.40 |
documentation_score |
88.0 | 0.15 | 13.20 |
practices_score |
87.0 | 0.15 | 13.05 |
code_quality |
56.0 | 0.10 | 5.60 |
| Overall | 1.00 | 88.0 |
Showing 1573 of 5680 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
benchmark/scatter.R:44
qualitylegacy
benchmark/compare.R:50
qualitylegacy
benchmark/source_map/source-map-cache.js:47
qualitylegacy
benchmark/es/eval.js:28
qualitylegacy
benchmark/buffers/buffer-swap.js:74
qualitylegacy
benchmark/buffers/buffer-fill.js:24
qualitylegacy
deps/v8/tools/grokdump.py:1612
qualitylegacy
tools/gyp/pylib/gyp/generator/cmake.py:505
qualitylegacy
deps/v8/tools/release/merge_to_branch.py:42
qualitylegacy
deps/v8/tools/release/roll_merge.py:41
qualitylegacy
deps/v8/tools/run_perf.py:1334
qualitylegacy
deps/libffi/generate-darwin-source-and-headers.py:176
qualitylegacy
deps/v8/tools/release/merge_to_branch.py:135
qualitylegacy
deps/v8/tools/release/create_release.py:121
qualitylegacy
deps/v8/tools/release/roll_merge.py:124
qualitylegacy
tools/gyp/pylib/gyp/generator/ninja.py:2101
qualitylegacy
deps/v8/tools/run-clang-tidy.py:216
qualitylegacy
deps/v8/tools/grokdump.py:1089
qualitylegacy
tools/gyp/pylib/gyp/generator/make.py:739
qualitylegacy
tools/gyp/pylib/gyp/ninja_syntax.py:174
qualitylegacy
tools/gyp/pylib/gyp/msvs_emulation.py:1096
qualitylegacy
tools/gyp/pylib/gyp/input.py:708
qualitylegacy
tools/gyp/pylib/gyp/xcode_emulation.py:1840
qualitylegacy
tools/gyp/pylib/gyp/__init__.py:32
qualitylegacy
tools/gyp/pylib/packaging/tags.py:124
qualitylegacy
deps/v8/tools/run-clang-tidy.py:163
qualitylegacy
.github/workflows/linters.yml:282
dependencylegacy
deps/npm/lib/commands/profile.js:168
secrets
deps/npm/lib/commands/profile.js:195
secrets
deps/npm/lib/utils/auth.js:53
secrets
deps/npm/lib/utils/auth.js:89
secrets
deps/npm/lib/utils/read-user-info.js:10
secrets
benchmark/crypto/hash-stream-throughput.js:9
qualitylegacy
benchmark/crypto/hash-stream-creation.js:9
qualitylegacy
benchmark/crypto/create-hash.js:18
qualitylegacy
deps/LIEF/include/LIEF/PE/CodePage.hpp:125
qualitylegacy
android_configure.py:10
qualitylegacy
tools/cpplint.py:1034
qualitylegacy
tools/cpplint.py:1038
qualitylegacy
tools/cpplint.py:1044
qualitylegacy
tools/cpplint.py:3566
qualitylegacy
tools/cpplint.py:3643
qualitylegacy
tools/cpplint.py:3645
qualitylegacy
tools/cpplint.py:3571
qualitylegacy
tools/cpplint.py:1493
qualitylegacy
tools/cpplint.py:1854
qualitylegacy
tools/cpplint.py:1771
qualitylegacy
tools/cpplint.py:3596
qualitylegacy
tools/cpplint.py:1034
qualitylegacy
tools/cpplint.py:1038
qualitylegacy
tools/cpplint.py:1043
qualitylegacy
tools/cpplint.py:1539
qualitylegacy
tools/cpplint.py:1537
qualitylegacy
tools/cpplint.py:1836
qualitylegacy
tools/cpplint.py:3672
qualitylegacy
tools/cpplint.py:3606
qualitylegacy
tools/cpplint.py:1842
qualitylegacy
tools/cpplint.py:1846
qualitylegacy
tools/cpplint.py:1850
qualitylegacy
tools/cpplint.py:3121
qualitylegacy
tools/cpplint.py:3191
qualitylegacy
tools/cpplint.py:3564
qualitylegacy
deps/ngtcp2/ngtcp2/third-party/urlparse/.clusterfuzzlite/Dockerfile:1
dependencylegacy
deps/openssl/config/Dockerfile:1
dependencylegacy
android_configure.py:77
injectionlegacy
benchmark/http/headers.js:34
xsslegacy
benchmark/assert/deepequal-set.js:57
xsslegacy
benchmark/child_process/child-process-exec-stdout.js:20
qualitylegacy
benchmark/_http-benchmarkers.js:186
qualitylegacy
deps/ngtcp2/ngtcp2/third-party/urlparse/.clusterfuzzlite/Dockerfile:3
dockerlegacy
benchmark/es/eval.js:28
owaspeval_used
benchmark/source_map/source-map-cache.js:47
owaspeval_used
deps/v8/tools/clusterfuzz/foozzie/v8_mock.js:302
owaspeval_used
deps/v8/tools/compare-table-gen.js:11
owaspeval_used
deps/v8/tools/grokdump.py:3778
owaspeval_used
deps/v8/tools/lldb_visualizers.py:146
owaspeval_used
lib/internal/modules/esm/loader.js:249
owaspeval_used
lib/internal/process/execution.js:79
owaspeval_used
lib/internal/repl/completion.js:421
owaspeval_used
tools/gyp/pylib/gyp/input.py:237
owaspeval_used
tools/gypi_to_gn.py:223
owaspeval_used
benchmark/child_process/child-process-exec-stdout.js:20
owaspexec_used
deps/npm/lib/base-cmd.js:429
owaspexec_used
deps/npm/lib/commands/access.js:73
owaspexec_used
deps/npm/lib/commands/adduser.js:15
owaspexec_used
deps/npm/lib/commands/audit.js:46
owaspexec_used
deps/npm/lib/commands/cache.js:96
owaspexec_used
deps/npm/lib/commands/ci.js:40
owaspexec_used
deps/npm/lib/commands/completion.js:63
owaspexec_used
deps/npm/lib/commands/config.js:132
owaspexec_used
deps/npm/lib/commands/dedupe.js:28
owaspexec_used
deps/npm/lib/commands/deprecate.js:36
owaspexec_used
deps/npm/lib/commands/diff.js:37
owaspexec_used
deps/npm/lib/commands/dist-tag.js:34
owaspexec_used
deps/npm/lib/commands/doctor.js:106
owaspexec_used
deps/npm/lib/commands/edit.js:41
owaspexec_used
deps/npm/lib/commands/exec.js:31
owaspexec_used
deps/npm/lib/commands/explain.js:25
owaspexec_used
deps/npm/lib/commands/explore.js:21
owaspexec_used
deps/npm/lib/commands/find-dupes.js:21
owaspexec_used
deps/npm/lib/commands/fund.js:42
owaspexec_used
deps/npm/lib/commands/get.js:16
owaspexec_used
deps/npm/lib/commands/help-search.js:15
owaspexec_used
deps/npm/lib/commands/help.js:46
owaspexec_used
deps/npm/lib/commands/init.js:43
owaspexec_used
deps/npm/lib/commands/install.js:104
owaspexec_used
deps/npm/lib/commands/link.js:45
owaspexec_used
deps/npm/lib/commands/ll.js:7
owaspexec_used
deps/npm/lib/commands/login.js:15
owaspexec_used
deps/npm/lib/commands/logout.js:14
owaspexec_used
deps/npm/lib/commands/ls.js:47
owaspexec_used
deps/npm/lib/commands/org.js:34
owaspexec_used
deps/npm/lib/commands/outdated.js:42
owaspexec_used
deps/npm/lib/commands/owner.js:75
owaspexec_used
deps/npm/lib/commands/pack.js:25
owaspexec_used
deps/npm/lib/commands/ping.js:11
owaspexec_used
deps/npm/lib/commands/pkg.js:28
owaspexec_used
deps/npm/lib/commands/prefix.js:9
owaspexec_used
deps/npm/lib/commands/profile.js:75
owaspexec_used
deps/npm/lib/commands/prune.js:19
owaspexec_used
deps/npm/lib/commands/publish.js:43
owaspexec_used
deps/npm/lib/commands/query.js:59
owaspexec_used
deps/npm/lib/commands/rebuild.js:31
owaspexec_used
deps/npm/lib/commands/root.js:9
owaspexec_used
deps/npm/lib/commands/run.js:42
owaspexec_used
deps/npm/lib/commands/sbom.js:25
owaspexec_used
deps/npm/lib/commands/search.js:26
owaspexec_used
deps/npm/lib/commands/set.js:16
owaspexec_used
deps/npm/lib/commands/shrinkwrap.js:11
owaspexec_used
deps/npm/lib/commands/stage/approve.js:14
owaspexec_used
deps/npm/lib/commands/stage/download.js:17
owaspexec_used
deps/npm/lib/commands/stage/list.js:13
owaspexec_used
deps/npm/lib/commands/stage/reject.js:14
owaspexec_used
deps/npm/lib/commands/stage/view.js:14
owaspexec_used
deps/npm/lib/commands/star.js:19
owaspexec_used
deps/npm/lib/commands/stars.js:13
owaspexec_used
deps/npm/lib/commands/team.js:41
owaspexec_used
deps/npm/lib/commands/token.js:51
owaspexec_used
deps/npm/lib/commands/trust/circleci.js:170
owaspexec_used
deps/npm/lib/commands/trust/github.js:99
owaspexec_used
deps/npm/lib/commands/trust/gitlab.js:100
owaspexec_used
deps/npm/lib/commands/trust/list.js:35
owaspexec_used
deps/npm/lib/commands/trust/revoke.js:28
owaspexec_used
deps/npm/lib/commands/undeprecate.js:8
owaspexec_used
deps/npm/lib/commands/uninstall.js:18
owaspexec_used
deps/npm/lib/commands/unpublish.js:66
owaspexec_used
deps/npm/lib/commands/update.js:43
owaspexec_used
deps/npm/lib/commands/version.js:51
owaspexec_used
deps/npm/lib/commands/view.js:53
owaspexec_used
deps/npm/lib/commands/whoami.js:10
owaspexec_used
deps/npm/lib/lifecycle-cmd.js:11
owaspexec_used
deps/npm/lib/npm.js:189
owaspexec_used
deps/npm/lib/package-url-cmd.js:20
owaspexec_used
deps/npm/lib/utils/allow-scripts-cmd.js:33
owaspexec_used
deps/v8/third_party/jinja2/debug.py:145
owaspexec_used
deps/v8/third_party/jinja2/environment.py:1228
owaspexec_used
deps/v8/tools/dev/gm.py:202
owaspexec_used
deps/v8/tools/dev/setup-reclient.py:100
owaspexec_used
lib/internal/per_context/primordials.js:615
owaspexec_used
typings/internalBinding/url_pattern.d.ts:14
owaspexec_used
benchmark/process/handled-rejections.js:34
error_handlinglegacy
deps/v8/tools/dev/gm.py:539
qualitylegacy
deps/v8/tools/dev/gm.py:428
qualitylegacy
tools/gyp/pylib/gyp/MSVSUserFile.py:79
qualitylegacy
tools/gyp/pylib/gyp/xcode_emulation.py:1236
qualitylegacy
deps/v8/tools/run-clang-tidy.py:221
qualitylegacy
tools/gyp/pylib/gyp/common.py:526
qualitylegacy
deps/v8/tools/dev/gm.py:435
qualitylegacy
tools/gyp/pylib/gyp/generator/ninja.py:2885
qualitylegacy
tools/gyp/pylib/gyp/__init__.py:71
qualitylegacy
tools/gyp/pylib/gyp/__init__.py:71
qualitylegacy
deps/uv/docs/src/sphinx-plugins/manpage.py:30
qualitylegacy
deps/uv/docs/src/sphinx-plugins/manpage.py:30
qualitylegacy
deps/v8/tools/lldb_commands.py:46
qualitylegacy
tools/gyp/pylib/gyp/generator/analyzer.py:804
qualitylegacy
tools/gyp/pylib/gyp/mac_tool.py:161
qualitylegacy
tools/gyp/pylib/gyp/common.py:724
qualitylegacy
tools/gyp/pylib/gyp/input.py:549
qualitylegacy
tools/gyp/gyp_main.py:33
qualitylegacy
tools/gyp/gyp_main.py:20
qualitylegacy
tools/build_addons.py:71
qualitylegacy
tools/search_files.py:21
qualitylegacy
tools/gypi_to_gn.py:332
qualitylegacy
tools/prepare_lief.py:79
qualitylegacy
benchmark/process/bench-env.js:32
qualitylegacy
deps/LIEF/include/LIEF/PE/Builder.hpp:83
qualitylegacy
.dockerignore
dockerlegacy
.dockerignore
dockerlegacy
deps/openssl/config/Dockerfile:1
dockerlegacy
deps/ngtcp2/ngtcp2/third-party/urlparse/.clusterfuzzlite/Dockerfile:1
dockerlegacy
deps/icu-small/source/common/unicode/utf_old.h:1
qualitylegacy
deps/LIEF/third-party/mbedtls/library/ecp_curves_new.c:1
qualitylegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
deps/npm/README.md:16
dependencylegacy
manifest.json
qualitylegacy
deps/openssl/openssl/crypto/asn1/tasn_new.c:1
qualitylegacy
deps/LIEF/third-party/mbedtls/library/ecp_internal_alt.h:1
qualitylegacy
deps/LIEF/third-party/mbedtls/library/ecp_curves_new.c:1
qualitylegacy
.github/workflows/create-release-proposal.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/scorecard.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/license-builder.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/timezone-update.yml
supply-chaingithub-actionsleast-privilege
deps/v8/third_party/ittapi/buildall.py:90
owaspsubprocess_shell_true
deps/v8/tools/android-run.py:57
owaspsubprocess_shell_true
deps/v8/tools/clusterfuzz/js_fuzzer/tools/fuzz_one.py:39
owaspsubprocess_shell_true
deps/v8/tools/clusterfuzz/js_fuzzer/tools/run_one.py:58
owaspsubprocess_shell_true
deps/v8/tools/dev/gen-tags.py:37
owaspsubprocess_shell_true
deps/v8/tools/dev/gm.py:324
owaspsubprocess_shell_true
deps/v8/tools/dev/setup-reclient.py:39
owaspsubprocess_shell_true
deps/v8/tools/dev/update-compile-commands.py:43
owaspsubprocess_shell_true
deps/v8/tools/disasm.py:79
owaspsubprocess_shell_true
deps/v8/tools/locs.py:142
owaspsubprocess_shell_true
deps/v8/tools/memory/rss.py:56
owaspsubprocess_shell_true
deps/v8/tools/profiling/linux-perf-chrome.py:314
owaspsubprocess_shell_true
deps/v8/tools/profiling/linux-perf-d8.py:292
owaspsubprocess_shell_true
deps/v8/tools/profiling/ll_prof.py:707
owaspsubprocess_shell_true
deps/v8/tools/release/common_includes.py:104
owaspsubprocess_shell_true
deps/v8/tools/run_perf.py:956
owaspsubprocess_shell_true
deps/v8/tools/sanitizers/sancov_formatter.py:181
owaspsubprocess_shell_true
deps/v8/tools/torque/format-torque.py:168
owaspsubprocess_shell_true
deps/v8/tools/try_perf.py:101
owaspsubprocess_shell_true
deps/v8/tools/v8_presubmit.py:550
owaspsubprocess_shell_true
tools/gyp/pylib/gyp/common.py:449
owaspsubprocess_shell_true
tools/gyp/pylib/gyp/input.py:900
owaspsubprocess_shell_true
tools/gyp/pylib/gyp/msvs_emulation.py:1190
owaspsubprocess_shell_true
tools/gyp/pylib/gyp/win_tool.py:251
owaspsubprocess_shell_true
tools/v8/fetch_deps.py:62
owaspsubprocess_shell_true
tools/v8/node_common.py:33
owaspsubprocess_shell_true
benchmark/crypto/rsa-sign-verify-throughput.js:21
owaspweak_hash
typings/internalBinding/constants.d.ts:244
owaspweak_hash
Showing first 300 of 1573. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/f9fcf18e-aacd-473f-8572-887b663f1bea/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/f9fcf18e-aacd-473f-8572-887b663f1bea/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.