https://github.com/storybookjs/storybook
· scanned 2026-06-05 06:59 UTC (5 days, 23 hours ago)
· 10 languages
1148 raw signals (138 security + 1010 graph) 11/13 scanners ran 69th percentile · Typescript · large (100-500K LoC) System graph score 59 (higher by 20)
Last scanned 5 days, 23 hours ago · v2 · 545 actionable findings from 2 signal sources. 98 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
85.0 | 0.25 | 21.25 |
testing_score |
72.0 | 0.20 | 14.40 |
documentation_score |
87.0 | 0.15 | 13.05 |
practices_score |
88.0 | 0.15 | 13.20 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 78.9 |
Showing 275 of 545 actionable findings. 643 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.env
code/frameworks/angular/src/server/framework-preset-angular-ivy.ts:28
.env
.github/workflows/publish.yml:55, 108, 191, 192, 193, 201, 226, 247, +3 more (11 hits)scripts/run-registry.ts:215
.github/workflows/nx.yml:33, 69, 85, 102 (4 hits).github/workflows/fork-checks.yml:16, 33, 53 (3 hits).github/workflows/handle-release-branches.yml:27, 36, 58 (3 hits).github/workflows/generate-sandboxes.yml:69, 73 (2 hits).github/workflows/publish.yml:52, 243 (2 hits).github/workflows/cron-weekly.yml:15.github/workflows/prepare-non-patch-release.yml:47.github/workflows/prepare-patch-release.yml:29.github/workflows/cron-weekly.yml:16.github/workflows/handle-release-branches.yml:42.github/workflows/nx.yml:90.github/workflows/publish.yml:189.github/workflows/triage.yml:21.github/workflows/trigger-circle-ci-workflow.yml:63code/lib/eslint-plugin/scripts/generate-rule.ts:32
Eval used
code/core/build-config.ts:9
Exec used
code/core/src/common/js-package-manager/BUNProxy.ts:184
Exec used
code/core/src/common/js-package-manager/NPMProxy.ts:167
Exec used
code/lib/eslint-plugin/build-config.ts:9
Exec used
scripts/build-package.ts:157
Exec used
scripts/prepare-sandbox.ts:73
Exec used
scripts/run-registry.ts:167
Exec used
scripts/tasks/build.ts:33
Exec used
scripts/tasks/check-sandbox.ts:13
Exec used
scripts/tasks/chromatic.ts:17
Exec used
scripts/tasks/compile.ts:35
Exec used
scripts/tasks/dev.ts:82
Exec used
scripts/tasks/publish.ts:26
Exec used
scripts/tasks/run-registry.ts:14
Exec used
scripts/tasks/sandbox-parts.ts:154
Exec used
scripts/tasks/serve.ts:37
Exec used
scripts/utils/cli-step.ts:126
Exec used
scripts/utils/yarn.ts:76
Exec used
code/core/src/controls/components/SaveStory.tsx:103code/core/src/core-server/build-static.ts:49code/core/src/core-server/utils/checklist.ts:91code/addons/docs/src/DocsRenderer.tsx:71
code/addons/vitest/src/vitest-plugin/utils.ts:35code/core/src/channels/postmessage/index.ts:151code/core/src/common/utils/get-addon-annotations.ts:44index.html
.well-known/security.txt
manifest.json
.github/workflows/code-simplifier.lock.yml.github/workflows/handle-release-branches.yml.github/workflows/prepare-non-patch-release.yml.github/workflows/prepare-patch-release.yml.github/workflows/publish.ymlcode/addons/a11y/src/components/VisionSimulator.tsx:64
Dangerous innerhtml
code/core/src/manager/components/sidebar/Brand.tsx:48
Dangerous innerhtml
code/core/src/preview-api/Errors.stories.tsx:48
Dangerous innerhtml
.github/workflows/danger-js.yml
Ports
.github/workflows/danger-js.yml
Ports
code/addons/pseudo-states/src/stories/CustomElementNested.stories.tsx:20, 22, 28 (3 hits)code/core/src/common/js-package-manager/Yarn2Proxy.ts:96, 192, 237 (3 hits)code/core/src/components/components/Tabs/TabList.tsx:16, 25, 64 (3 hits)code/addons/pseudo-states/src/stories/CustomElement.stories.tsx:22, 28 (2 hits)code/addons/vitest/build-config.ts:1, 3 (2 hits)code/addons/a11y/src/components/Report/Report.stories.tsx:9code/addons/pseudo-states/src/stories/CSSAtRules.stories.tsx:10code/addons/pseudo-states/src/stories/ShadowRoot.tsx:12.cursorrules:1
llms.txt
humans.txt
robots.txt
sitemap.xml
code/core/src/core-events/data/whats-new.ts:1code/core/src/core-server/utils/whats-new.ts:1code/core/src/manager/settings/whats_new.tsx:1package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/ff7f66c4-126b-4c0f-896b-d5a9a906e679/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/ff7f66c4-126b-4c0f-896b-d5a9a906e679/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.