Skip to content

Analyse a repository

Security issues, secrets and dependency risk, each anchored to a file and line — and on a second run, what changed since the last one.

Rules cover JavaScript, TypeScript and Python. Secret scanning and dependency advisories work on any repository.

Any public repository. Nothing is installed or executed — the source is read, analysed and discarded.

Try
Upload a ZIP archive instead

Drop a .zip here, or

Up to 250 MB. Dependency folders are skipped automatically — there is no need to prune anything first.

Recent analyses

Vantage — repository analysis