Scan timing: clone 22.38s · analysis 33.63s · 54.1 MB · GitHub API rate-limit (preflight)
https://github.com/facebook/react-native
· scanned 2026-06-05 05:06 UTC (11 hours, 10 minutes ago)
· 10 languages
1374 findings (170 legacy + 1204 scanner) 11/13 scanners ran 20th percentile · Javascript · huge (>500K LoC) Scanner says 56 (higher by 31)
Last scanned 11 hours, 10 minutes ago · v2 · 772 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
81.0 | 0.20 | 16.20 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
66.0 | 0.10 | 6.60 |
| Overall | 1.00 | 86.8 |
Showing 79 of 772 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/react-native/React/Fabric/RCTScheduler.mm:203
qualitylegacy
packages/react-native/React/Base/RCTManagedPointer.mm:24
qualitylegacy
packages/react-native-babel-preset/src/plugin-warn-on-deep-imports.js:60
qualitylegacy
scripts/cxx-api/parser/snapshot.py:206
qualitylegacy
scripts/cxx-api/parser/snapshot.py:212
qualitylegacy
scripts/cxx-api/parser/snapshot.py:181
qualitylegacy
scripts/cxx-api/parser/snapshot.py:132
qualitylegacy
scripts/cxx-api/parser/snapshot.py:78
qualitylegacy
scripts/cxx-api/parser/snapshot.py:108
qualitylegacy
scripts/cxx-api/parser/snapshot.py:47
qualitylegacy
.github/workflows/publish-bumped-packages.yml:17
dependencylegacy
.github/workflows/on-issue-labeled.yml:54
dependencylegacy
.github/workflows/on-issue-labeled.yml:19
dependencylegacy
.github/workflows/bump-podfile-lock.yml:11
dependencylegacy
.github/workflows/needs-attention.yml:19
dependencylegacy
.github/workflows/create-draft-release.yml:16
dependencylegacy
.github/workflows/publish-release.yml:74
dependencylegacy
.github/workflows/publish-release.yml:29
dependencylegacy
.github/workflows/generate-changelog.yml:11
dependencylegacy
.github/workflows/create-release.yml:26
dependencylegacy
.github/workflows/on-issue-labeled.yml:55
dependencylegacy
.github/workflows/on-issue-labeled.yml:42
dependencylegacy
.github/workflows/on-issue-labeled.yml:22
dependencylegacy
.github/workflows/create-draft-release.yml:39
dependencylegacy
.github/workflows/create-draft-release.yml:29
dependencylegacy
.github/workflows/publish-release.yml:120
dependencylegacy
.github/workflows/publish-release.yml:111
dependencylegacy
.github/workflows/publish-release.yml:96
dependencylegacy
.github/workflows/publish-release.yml:86
dependencylegacy
.github/workflows/generate-changelog.yml:24
dependencylegacy
.github/workflows/close-pr.yml:14
dependencylegacy
.github/workflows/stale-bot.yml:30
dependencylegacy
.github/workflows/stale-bot.yml:13
dependencylegacy
.github/workflows/needs-attention.yml:21
dependencylegacy
.github/workflows/nightly.yml:76
dependencylegacy
.github/workflows/nightly.yml:45
dependencylegacy
.github/workflows/publish-release.yml:55
dependencylegacy
gradle/wrapper/gradle-wrapper.jar:1
dependencylegacy
packages/gradle-plugin/gradle/wrapper/gradle-wrapper.jar:1
dependencylegacy
private/helloworld/android/gradle/wrapper/gradle-wrapper.jar:1
dependencylegacy
packages/react-native/ReactAndroid/src/main/java/com/facebook/react/internal/featureflags/rewrite_feature_flag_defaults.py:69
path_traversallegacy
packages/gradle-plugin/react-native-gradle-plugin/src/main/kotlin/com/facebook/react/utils/AgpConfiguratorUtils.kt:141
xxelegacy
packages/eslint-config-react-native/shared.js:148
owaspeval_used
packages/react-native/Libraries/Core/Devtools/loadBundleFromServer.js:190
owaspeval_used
scripts/releases/ios-prebuild/folders.js:27
owaspexec_used
scripts/releases/ios-prebuild/setupDependencies.js:70
owaspexec_used
scripts/releases/utils/npm-utils.js:149
owaspexec_used
scripts/releases/utils/release-utils.js:22
owaspexec_used
scripts/releases/utils/scm-utils.js:32
owaspexec_used
scripts/cxx-api/parser/input_filters/main.py:41
qualitylegacy
scripts/cxx-api/parser/__main__.py:206
qualitylegacy
.github/actions/maestro-ios/action.yml:27
dependencylegacy
.github/actions/maestro-android/action.yml:35
dependencylegacy
packages/react-native-codegen/src/parsers/typescript/components/componentsUtils.js:106
qualitylegacy
packages/react-native-codegen/src/parsers/typescript/components/commands.js:76
qualitylegacy
packages/react-native-codegen/src/parsers/parserMock.js:3
qualitylegacy
packages/react-native-codegen/src/parsers/parserMock.js:1
qualitylegacy
packages/react-native-codegen/src/parsers/parser.js:1
qualitylegacy
packages/react-native-codegen/src/generators/modules/GenerateModuleObjCpp/serializeEventEmitter.js:39
qualitylegacy
packages/react-native-codegen/src/generators/modules/GenerateModuleObjCpp/header/serializeRegularStruct.js:103
qualitylegacy
packages/react-native-codegen/src/generators/modules/GenerateModuleJniH.js:54
qualitylegacy
packages/react-native-codegen/src/generators/modules/GenerateModuleJniCpp.js:1
qualitylegacy
packages/react-native-codegen/src/generators/components/GenerateThirdPartyFabricComponentsProviderObjCpp.js:35
qualitylegacy
packages/react-native-codegen/src/generators/components/GenerateThirdPartyFabricComponentsProviderH.js:35
qualitylegacy
packages/react-native-codegen/src/generators/components/GenerateShadowNodeH.js:44
qualitylegacy
packages/react-native-codegen/src/generators/components/GenerateShadowNodeCpp.js:32
qualitylegacy
packages/react-native-codegen/src/generators/components/GeneratePropsJavaPojo/PojoCollector.js:27
qualitylegacy
packages/react-native-codegen/src/generators/components/GeneratePropsJavaInterface.js:175
qualitylegacy
packages/react-native-codegen/src/generators/components/GeneratePropsJavaInterface.js:123
qualitylegacy
packages/react-native-codegen/src/generators/components/GeneratePropsH.js:727
qualitylegacy
packages/react-native-codegen/src/generators/components/GenerateEventEmitterH.js:282
qualitylegacy
packages/react-native-codegen/src/generators/components/GenerateComponentDescriptorH.js:36
qualitylegacy
packages/gradle-plugin/react-native-gradle-plugin/src/main/kotlin/com/facebook/react/tasks/GeneratePackageListTask.kt:13
qualitylegacy
flow-typed/npm/listr_v14.x.x.js:2
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/fd7f2e04-3ce2-42af-a904-2847dfc65c4d/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/fd7f2e04-3ce2-42af-a904-2847dfc65c4d/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.