dashboard radar bug_report school newspaper sensors
DevSecOps // Repository Security Posture Scan engine: checking…

GitHub Repository Security Scanner

One report for a public repository: secrets and risky code patterns, known-vulnerable dependencies from OSV.dev, and the OpenSSF Scorecard of its engineering security practices, with fix guidance and SARIF export.

Scan a repository

Try:

Public repositories only, default branch. The code is cloned to a temporary directory and deleted after the scan. A scan summary (repository URL, score, finding counts) is logged for usage analytics. Source code is not kept.

What the scanner checks

Secrets & risky code

Pattern rules for leaked keys (AWS, GitHub, Google, Slack, private keys), hardcoded passwords, injection-prone calls, plus Bandit and Semgrep static analysis.

Known-vulnerable packages

Dependencies from package-lock.json / package.json, requirements.txt and go.mod are checked against OSV.dev (GitHub Advisories, PyPA, Go vuln DB).

Engineering practices

OpenSSF Scorecard: branch protection, code review, pinned dependencies, dangerous workflows, token permissions, signed releases and more.

Limits

Static analysis only, no runtime testing. Pattern rules can produce false positives. Without a lockfile, dependency versions are the declared minimums. Scorecard covers repositories in its weekly public dataset.