Scan timing: clone 22.38s · analysis 33.63s · 54.1 MB · GitHub API rate-limit (preflight)
https://github.com/facebook/react-native
· scanned 2026-06-05 05:06 UTC (2 hours, 42 minutes ago)
· 10 languages
1374 findings (170 legacy + 1204 scanner) 11/13 scanners ran Scanner says 56 (higher by 31)
Last scanned 2 hours, 42 minutes ago · v2 · 772 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
81.0 | 0.20 | 16.20 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
66.0 | 0.10 | 6.60 |
| Overall | 1.00 | 86.8 |
Showing 481 of 772 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/react-native/React/DevSupport/RCTFrameTimingsObserver.mm:180
qualitylegacy
packages/react-native/Libraries/Image/RCTImageStoreManager.mm:159
qualitylegacy
packages/react-native-codegen/src/generators/modules/GenerateModuleObjCpp/header/serializeConstantsStruct.js:181
qualitylegacy
packages/react-native/Libraries/Core/Devtools/loadBundleFromServer.js:190
qualitylegacy
packages/react-native/ReactAndroid/src/main/java/com/facebook/react/views/scroll/generate-nested-scroll-view.js:44
qualitylegacy
packages/react-native-babel-transformer/src/index.js:235
qualitylegacy
packages/react-native-babel-preset/src/index.js:36
qualitylegacy
packages/react-native/React/Fabric/RCTScheduler.mm:203
qualitylegacy
packages/react-native/React/Base/RCTManagedPointer.mm:24
qualitylegacy
packages/react-native-babel-preset/src/plugin-warn-on-deep-imports.js:60
qualitylegacy
scripts/cxx-api/parser/snapshot.py:206
qualitylegacy
scripts/cxx-api/parser/snapshot.py:212
qualitylegacy
scripts/cxx-api/parser/snapshot.py:181
qualitylegacy
scripts/cxx-api/parser/snapshot.py:132
qualitylegacy
scripts/cxx-api/parser/snapshot.py:78
qualitylegacy
scripts/cxx-api/parser/snapshot.py:108
qualitylegacy
scripts/cxx-api/parser/snapshot.py:47
qualitylegacy
.github/workflows/publish-bumped-packages.yml:17
dependencylegacy
.github/workflows/on-issue-labeled.yml:54
dependencylegacy
.github/workflows/on-issue-labeled.yml:19
dependencylegacy
.github/workflows/bump-podfile-lock.yml:11
dependencylegacy
.github/workflows/needs-attention.yml:19
dependencylegacy
.github/workflows/create-draft-release.yml:16
dependencylegacy
.github/workflows/publish-release.yml:74
dependencylegacy
.github/workflows/publish-release.yml:29
dependencylegacy
.github/workflows/generate-changelog.yml:11
dependencylegacy
.github/workflows/create-release.yml:26
dependencylegacy
.github/workflows/on-issue-labeled.yml:55
dependencylegacy
.github/workflows/on-issue-labeled.yml:42
dependencylegacy
.github/workflows/on-issue-labeled.yml:22
dependencylegacy
.github/workflows/create-draft-release.yml:39
dependencylegacy
.github/workflows/create-draft-release.yml:29
dependencylegacy
.github/workflows/publish-release.yml:120
dependencylegacy
.github/workflows/publish-release.yml:111
dependencylegacy
.github/workflows/publish-release.yml:96
dependencylegacy
.github/workflows/publish-release.yml:86
dependencylegacy
.github/workflows/generate-changelog.yml:24
dependencylegacy
.github/workflows/close-pr.yml:14
dependencylegacy
.github/workflows/stale-bot.yml:30
dependencylegacy
.github/workflows/stale-bot.yml:13
dependencylegacy
.github/workflows/needs-attention.yml:21
dependencylegacy
.github/workflows/nightly.yml:76
dependencylegacy
.github/workflows/nightly.yml:45
dependencylegacy
.github/workflows/publish-release.yml:55
dependencylegacy
gradle/wrapper/gradle-wrapper.jar:1
dependencylegacy
packages/gradle-plugin/gradle/wrapper/gradle-wrapper.jar:1
dependencylegacy
private/helloworld/android/gradle/wrapper/gradle-wrapper.jar:1
dependencylegacy
packages/react-native/ReactAndroid/src/main/java/com/facebook/react/internal/featureflags/rewrite_feature_flag_defaults.py:69
path_traversallegacy
packages/gradle-plugin/react-native-gradle-plugin/src/main/kotlin/com/facebook/react/utils/AgpConfiguratorUtils.kt:141
xxelegacy
packages/react-native-codegen/src/generators/components/GenerateEventEmitterH.js:164
xsslegacy
packages/react-native-codegen/src/cli/combine/combine-js-to-schema-cli.js:42
qualitylegacy
.github/workflow-scripts/checkForReproducer.js:81
qualitylegacy
.github/workflow-scripts/utils.js:25
qualitylegacy
.github/workflow-scripts/publishTemplate.js:33
qualitylegacy
.github/workflow-scripts/maestro-ios.js:62
qualitylegacy
packages/eslint-config-react-native/shared.js:148
owaspeval_used
packages/react-native/Libraries/Core/Devtools/loadBundleFromServer.js:190
owaspeval_used
scripts/releases/ios-prebuild/folders.js:27
owaspexec_used
scripts/releases/ios-prebuild/setupDependencies.js:70
owaspexec_used
scripts/releases/utils/npm-utils.js:149
owaspexec_used
scripts/releases/utils/release-utils.js:22
owaspexec_used
scripts/releases/utils/scm-utils.js:32
owaspexec_used
packages/react-native/React/CxxModule/RCTCxxUtils.mm:35
error_handlinglegacy
packages/react-native/React/Base/RCTAssert.m:149
error_handlinglegacy
scripts/cxx-api/parser/input_filters/main.py:41
qualitylegacy
scripts/cxx-api/parser/__main__.py:206
qualitylegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
.github/actions/maestro-ios/action.yml:27
dependencylegacy
.github/actions/maestro-android/action.yml:35
dependencylegacy
.github/workflows/needs-attention.yml:21
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:151
supply-chaingithub-actionspinned-dependencies
.github/workflows/autorebase.yml:25
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:167
supply-chaingithub-actionspinned-dependencies
.github/workflows/monitor-new-issues.yml:31
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-ios-templateapp.yml:36
supply-chaingithub-actionspinned-dependencies
.github/workflows/on-issue-labeled.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/autorebase.yml
supply-chaingithub-actionsleast-privilege
packages/react-native/scripts/cocoapods/utils.rb:757
owaspweak_hash
packages/react-native/sdks/hermes-engine/hermes-utils.rb:229
owaspweak_hash
packages/react-native/Libraries/Animated/AnimatedEvent.js:101
qualitylegacy
packages/debugger-frontend/index.js:24
qualitylegacy
packages/assets-registry/path-support.js:66
qualitylegacy
packages/react-native-codegen/src/parsers/typescript/components/componentsUtils.js:106
qualitylegacy
packages/react-native-codegen/src/parsers/typescript/components/commands.js:76
qualitylegacy
packages/react-native-codegen/src/parsers/parserMock.js:3
qualitylegacy
packages/react-native-codegen/src/parsers/parserMock.js:1
qualitylegacy
packages/react-native-codegen/src/parsers/parser.js:1
qualitylegacy
packages/react-native-codegen/src/generators/modules/GenerateModuleObjCpp/serializeEventEmitter.js:39
qualitylegacy
packages/react-native-codegen/src/generators/modules/GenerateModuleObjCpp/header/serializeRegularStruct.js:103
qualitylegacy
packages/react-native-codegen/src/generators/modules/GenerateModuleJniH.js:54
qualitylegacy
packages/react-native-codegen/src/generators/modules/GenerateModuleJniCpp.js:1
qualitylegacy
packages/react-native-codegen/src/generators/components/GenerateThirdPartyFabricComponentsProviderObjCpp.js:35
qualitylegacy
packages/react-native-codegen/src/generators/components/GenerateThirdPartyFabricComponentsProviderH.js:35
qualitylegacy
packages/react-native-codegen/src/generators/components/GenerateShadowNodeH.js:44
qualitylegacy
packages/react-native-codegen/src/generators/components/GenerateShadowNodeCpp.js:32
qualitylegacy
packages/react-native-codegen/src/generators/components/GeneratePropsJavaPojo/PojoCollector.js:27
qualitylegacy
packages/react-native-codegen/src/generators/components/GeneratePropsJavaInterface.js:175
qualitylegacy
packages/react-native-codegen/src/generators/components/GeneratePropsJavaInterface.js:123
qualitylegacy
packages/react-native-codegen/src/generators/components/GeneratePropsH.js:727
qualitylegacy
packages/react-native-codegen/src/generators/components/GenerateEventEmitterH.js:282
qualitylegacy
packages/react-native-codegen/src/generators/components/GenerateComponentDescriptorH.js:36
qualitylegacy
packages/gradle-plugin/react-native-gradle-plugin/src/main/kotlin/com/facebook/react/tasks/GeneratePackageListTask.kt:13
qualitylegacy
flow-typed/npm/listr_v14.x.x.js:2
qualitylegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
robots.txt
qualitylegacy
sitemap.xml
qualitylegacy
.github/workflows/create-release.yml:26
supply-chaingithub-actionspinned-dependencies
.github/workflows/generate-changelog.yml:11
supply-chaingithub-actionspinned-dependencies
.github/workflows/generate-changelog.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-release.yml:29
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-release.yml:74
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-release.yml:86
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-release.yml:96
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-release.yml:111
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-release.yml:120
supply-chaingithub-actionspinned-dependencies
.github/workflows/create-draft-release.yml:16
supply-chaingithub-actionspinned-dependencies
.github/workflows/create-draft-release.yml:29
supply-chaingithub-actionspinned-dependencies
.github/workflows/create-draft-release.yml:39
supply-chaingithub-actionspinned-dependencies
.github/workflows/bump-podfile-lock.yml:11
supply-chaingithub-actionspinned-dependencies
.github/workflows/on-issue-labeled.yml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/on-issue-labeled.yml:22
supply-chaingithub-actionspinned-dependencies
.github/workflows/on-issue-labeled.yml:42
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-bumped-packages.yml:17
supply-chaingithub-actionspinned-dependencies
.github/workflows/validate-cxx-api-snapshots.yml:37
supply-chaingithub-actionspinned-dependencies
.github/workflows/validate-cxx-api-snapshots.yml:44
supply-chaingithub-actionspinned-dependencies
.github/workflows/validate-cxx-api-snapshots.yml:71
supply-chaingithub-actionspinned-dependencies
.github/workflows/validate-cxx-api-snapshots.yml:82
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:13
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:18
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:35
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:40
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:65
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:70
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:82
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:93
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:99
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:120
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:127
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:138
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:144
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:176
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:181
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-dependencies.yml:188
supply-chaingithub-actionspinned-dependencies
.github/workflows/autorebase.yml:20
supply-chaingithub-actionspinned-dependencies
.github/workflows/analyze-pr.yml:17
supply-chaingithub-actionspinned-dependencies
.github/workflows/analyze-pr.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/analyze-pr.yml:33
supply-chaingithub-actionspinned-dependencies
.github/workflows/nightly.yml:59
supply-chaingithub-actionspinned-dependencies
.github/workflows/nightly.yml:94
supply-chaingithub-actionspinned-dependencies
.github/workflows/validate-dotslash-artifacts.yml:33
supply-chaingithub-actionspinned-dependencies
.github/workflows/validate-dotslash-artifacts.yml:47
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-android-templateapp.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-android-templateapp.yml:34
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-android-templateapp.yml:39
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-android-templateapp.yml:44
supply-chaingithub-actionspinned-dependencies
.github/workflows/api-changes.yml:16
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:31
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:34
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:67
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:103
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:109
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:115
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:135
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:138
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:153
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:160
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:192
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:197
supply-chaingithub-actionspinned-dependencies
.github/workflows/prebuild-ios-core.yml:203
supply-chaingithub-actionspinned-dependencies
.github/workflows/monitor-new-issues.yml:18
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-ios-templateapp.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-ios-templateapp.yml:40
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-ios-templateapp.yml:47
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-ios-templateapp.yml:55
supply-chaingithub-actionspinned-dependencies
Showing first 300 of 481. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/fd7f2e04-3ce2-42af-a904-2847dfc65c4d/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/fd7f2e04-3ce2-42af-a904-2847dfc65c4d/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.