GitHub Reports — Open Source Security Reviews

CODERISKTOOLS OPEN SOURCE OBSERVATORY

Popular GitHub projects — reproducible scan-coverage index.

PUBLIC PUBLICATION HUB

Read the latest coverage index and reproduce the source

The WordPress page is the editorial entry point. The immutable report bytes, weekly index and source history live in the public reports repository and are published through its reviewed workflow.

  • public artifacts are reviewed through pull requests;
  • exact source commits, manifests and checksums remain reproducible;
  • raw findings, secrets and private operator evidence are not published.

Repository Reports & Scan Coverage

Reports 1–30: one continuous register of public repositories selected by GitHub popularity. This is not a vulnerability ranking, security score, certification, recommendation, or endorsement.

ReportRepositoryStars at snapshotReviewed commitScan statusCritical observationsHigh observationsMedium observationsLow observationsTotal observations
1codecrafters-io/build-your-own-x529,747aa17439b62f3COMPLETE00000
2sindresorhus/awesome487,2787cb5c8371c0fCOMPLETE00000
3freeCodeCamp/freeCodeCamp452,2858ae71bd8d832PARTIAL182201110349
4public-apis/public-apis451,760aacdeff11b41COMPLETE00606
5EbookFoundation/free-programming-books392,624281dfc4ac86bCOMPLETE3022025
6nilbuild/developer-roadmap362,0588d1f35105753COMPLETE122228062
7996icu/996.ICU276,450f5e35f48d769COMPLETE00022
8react/react246,624862e275a1c15COMPLETE015842101
9torvalds/linux240,021b95f03f04d47COMPLETE218161109102937
10ossu/computer-science207,02233d44a44e352COMPLETE00202
11tensorflow/tensorflow196,43635fd3492a4cbCOMPLETE6106429101361
12microsoft/vscode187,770d28fc4f1fb9fCOMPLETE3214575033186540
13kubernetes/kubernetes123,844bc5b2109f5ddCOMPLETE135169986872709
14nodejs/node118,3388cf16b31f61bCOMPLETE15083641416609990
15pallets/flask71,98836e4a824f340COMPLETE8712027
16moby/moby71,9666719bc3c8d67PARTIAL
17chrislgarry/Apollo-1171,803911e5c0283c6COMPLETE
18NationalSecurityAgency/ghidra71,799264130231b13PARTIAL
19juliangarnier/anime71,7472c9cf8ea0032NOT STARTED
20protocolbuffers/protobuf71,6820e436a47e854NOT STARTED
21ComposioHQ/awesome-claude-skills71,671be2a406907dbNOT STARTED
22OpenBB-finance/OpenBB71,3393e071fcc2cd9NOT STARTED
23nektos/act71,3104f411281417eNOT STARTED
24binary-husky/gpt_academic71,179d6bde0fa5437NOT STARTED
25toeverything/AFFiNE71,125fdfb6df82605NOT STARTED
26microsoft/ai-agents-for-beginners71,10015ad10ca6057NOT STARTED
27Leonxlnx/taste-skill70,923e988add20dabNOT STARTED
28datawhalechina/hello-agents70,426f8227af2efc4NOT STARTED
29swiftlang/swift70,2124ef9a5286c51NOT STARTED
30ansible/ansible70,2012d8c74aa7ae5NOT STARTED

Page 1 contains reports 1–30. A report page is limited to 50 rows; reports 51 and later will continue on the next page. An em dash means that aggregate counts have not been published in the immutable report yet; it never means zero.

Severity counts are scanner-rule observations in the tested scope, not confirmed vulnerabilities. Raw findings, secret values, paths, snippets, scores, and security conclusions are not published. Open the immutable coverage report JSON.

Scanner and scan scope

Primary scanner: CodeRiskTools Scanner 3.1.3 from 9batalion/coderisktools-scanner, pinned to exact source commit c1698b297e6200313276c8c2ef8e00a40ee9aa42.

Supporting tools: Git for exact-SHA checkout and provenance; Python for bounded orchestration, sharding, aggregation, deduplication checks, and checksums. Trivy, Gitleaks, OSV-Scanner, and other scanner engines were not used. Target repository code was never executed; repositories were treated as data.

Reports 16–30 continue the same register after reports 1–15. Each repository begins with default-branch, exact-SHA, license, and checkout-completeness readback. A status of NOT STARTED is not a clean result.

What the public index includes

  • project name and official GitHub repository link;
  • review week, SPDX license and CodeRiskTools engine versions;
  • completion status and clearly stated review limitations;
  • redacted posture signals, exact target commits and bounded scan status.

What is not published

Raw findings, source snippets, paths, rule matches, credentials, exploit instructions and uncoordinated vulnerability details are not published. Newly discovered critical issues are attributed only after confirmation and coordinated disclosure.

A review-required flag is an evidence signal, not a personal accusation or confirmed vulnerability. Secrets and exploit material are never published.

Loading, please wait…
BACK TO TOP