GitHub Repository Security Scanner
One report for a public repository: secrets and risky code patterns, known-vulnerable dependencies from OSV.dev, and the OpenSSF Scorecard of its engineering security practices, with fix guidance and SARIF export.
Scan a repository
Public repositories only, default branch. The code is cloned to a temporary directory and deleted after the scan. A scan summary (repository URL, score, finding counts) is logged for usage analytics. Source code is not kept.
Scanning
0s elapsed
Steps are approximate for the code engine; the Scorecard and dependency checks report their own status. A first scan after idle can take ~30 s while the engine wakes.
Posture grade
Code findings
–
Vulnerable dependencies
–
OpenSSF Scorecard
– / 10
Code findings
Dependencies
Security practices
OpenSSF Scorecard checks, scored 0–10
What the scanner checks
Secrets & risky code
Pattern rules for leaked keys (AWS, GitHub, Google, Slack, private keys), hardcoded passwords, injection-prone calls, plus Bandit and Semgrep static analysis.
Known-vulnerable packages
Dependencies from package-lock.json / package.json, requirements.txt and go.mod are checked against OSV.dev (GitHub Advisories, PyPA, Go vuln DB).
Engineering practices
OpenSSF Scorecard: branch protection, code review, pinned dependencies, dangerous workflows, token permissions, signed releases and more.
Limits
Static analysis only, no runtime testing. Pattern rules can produce false positives. Without a lockfile, dependency versions are the declared minimums. Scorecard covers repositories in its weekly public dataset.