GitHub security scanner for code, secrets and dependencies

Point RepoVerse at a GitHub repository and it reads the code the way a reviewer would: following request input through the program to the call where it becomes dangerous, checking every locked dependency against known advisories, and looking for credentials that should never have been committed.

What it checks

Three kinds of problem, each with its own evidence. Code flaws are found by a data-flow engine that parses JavaScript and TypeScript with the TypeScript compiler and follows values across assignments, closures, function calls and files. Line rules cover patterns in Python, Go, Ruby, PHP, Java and configuration files. Dependencies are read from lockfiles, so the version checked is the one actually installed, not the floor of a range.

  • Injection: SQL, shell commands, eval, MongoDB $where and operator injection, template injection
  • Server-side request forgery, path traversal, open redirects, regular-expression denial of service
  • Broken access control: lookups by request ID with no ownership check, admin guards defined but never applied
  • Sessions and auth: plaintext passwords, missing CSRF protection, insecure session cookies, session fixation
  • Secrets: cloud keys, tokens and private keys committed to the repository
  • Vulnerable dependencies from npm, yarn, pnpm, Pipfile, poetry, Cargo, composer and Gemfile lockfiles

How a finding is reported

Every finding names the file and line, the CWE, how bad it would be and — separately — how sure the engine is. A traced finding comes with the path from source to sink: the request field it started from, the function calls it passed through, and the line where it reached a database query or a shell. Repeats of the same mistake a few lines apart are grouped into one finding with every location listed, so the count at the top means something.

Each finding carries what an attacker gets out of it and what to change. For dependencies the report shows the installed version next to the range your manifest asked for, whether the package is direct or pulled in by another one, and the release that fixes it.

Measured, not claimed

The engine is checked against OWASP NodeGoat, a deliberately vulnerable Node.js application, pinned to one commit. Every labelled hole — server-side JavaScript injection, NoSQL injection, IDOR, missing access control, open redirect, ReDoS, SSRF, insecure sessions — must be found, past false positives must not return, and the holes it still misses are listed rather than hidden. Run over RepoVerse's own front end, it raises no false alarms.

What it does not do

It is static analysis: it reads code and never runs it, so a traced flow means the path exists in the source, not that a working exploit was demonstrated. Business-logic flaws specific to your application still need a person. Scanning a public repository and exploring its 3D city are free; the security review is part of the Pro plan because each review queries the vulnerability database on demand.

What it checks

  • CriticalRequest input is executed as code

    Whoever sends the request chooses what JavaScript runs on the server, with the process's permissions — read files, reach the database, open a shell.

    data flow · CWE-95

  • HighRequest input is built into a SQL statement

    The caller can rewrite the query: read other users' rows, bypass a login check, or modify data.

    data flow · CWE-89

  • CriticalRequest input reaches a shell command

    A `;` or `$(…)` in the input runs a second command on the host.

    data flow · CWE-78

  • HighRequest input runs inside a MongoDB `$where` expression

    `$where` is JavaScript evaluated by the database. A crafted value can return every document (`1'; return true; '`) or hang the server (`';while(true){}'`).

    data flow · CWE-943

  • HighRequest input chooses where the server sends an HTTP request

    Under the right network conditions the server can be made to call internal services or the cloud metadata endpoint (169.254.169.254) and hand the response back.

    data flow · CWE-918

  • HighRequest input becomes a filesystem path

    `../` sequences walk out of the intended directory and read or overwrite any file the process can reach.

    data flow · CWE-22

  • HighRequest input is written into the page as HTML

    Script in the input runs in the victim's browser on your origin, with their session.

    data flow · CWE-79

  • HighRequest input is matched against a backtracking-prone regular expression

    Nested quantifiers backtrack exponentially. A few dozen crafted characters pin the CPU, and in Node's single event loop that stalls every request on the server.

    data flow · CWE-1333

  • HighRecord looked up by an ID from the request, with no ownership check

    Changing the ID in the URL shows or changes another user's data (IDOR / BOLA).

    data flow · CWE-639

  • HighPassword stored without hashing

    Anyone who reads the database — a backup, an injection, an insider — gets every user's password, and with it their accounts on other sites.

    data flow · CWE-256

  • ModerateCookie sessions without CSRF protection

    Another site can submit forms to state-changing routes on behalf of a logged-in user — the browser attaches the session cookie automatically.

    data flow · CWE-352

  • HighCredential assigned as a literal

    A password, secret, token or API key is assigned a literal string rather than read from configuration.

    pattern

Questions

Which languages does the GitHub security scanner support?
Data-flow analysis covers JavaScript and TypeScript, including Express, Next.js and Node.js code. Line rules cover Python, Go, Ruby, PHP, Java, Kotlin, C#, Dockerfiles, GitHub Actions workflows and common configuration files. Dependency checks cover npm, PyPI, crates.io, Packagist, RubyGems and Go modules.
Does it find secrets committed to a repository?
Yes. Provider-format keys (AWS, GitHub, Stripe, Slack, OpenAI and others), private keys and high-entropy credentials assigned to secret-named variables are reported with the value blanked out of the report. Placeholder values and fixtures inside test folders are recognised and left out.
How is it different from npm audit?
npm audit checks dependencies only. RepoVerse also reads your own code for injection, access-control and session flaws, follows data across files, and covers several ecosystems from their lockfiles in the same report.
Is my code stored or sent anywhere?
Public repositories are read anonymously. Only the generated city and the review are kept. Private repositories require signing in with GitHub, and the token is used only to fetch the repository you asked for.

Related

Updated 2026-10-11