Skip to content

MetaMask/Security-Code-Scanner

View on GitHub ↗Related repositories →

A GitHub action aggregating SAST tools to scan code for vulnerabilities

active 2024-09-052026-04-04 (UTC)

Partial coverage14,770 / 18,017 hourly files (82%) · 2 absent upstream · 3,246 failed, retryable2024-07-222026-08-11 (UTC)— sampled evenly across the window, so rankings and trends hold; absolute counts scale up.
Events
12
Pushes
0
Pull requests
6
Issues
0
Stars
1
Forks
1

Activity over time

Daily event counts in the loaded window

Line chart, 577 days from 2024-09-05 to 2026-04-04. Pushes: 0 total, peak 0 in a day. Pull requests: 6 total, peak 5 in a day. Issues: 0 total, peak 0 in a day. Comments: 1 total, peak 1 in a day. Stars: 1 total, peak 1 in a day.

  • Pushes
  • Pull requests
  • Issues
  • Comments
  • Stars

Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.

Top contributors

Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity

ContributorContributionsPushesPRsComments
dependabot[bot]6060
witmicko1000
socket-security[bot]1001

Recent activity

Latest issues, pull requests and releases

  • Pull request#2dependabot[bot]2025-11-15 10:27
  • Pull request#2dependabot[bot]2025-11-15 10:27
  • Pull request#2dependabot[bot]2025-11-15 10:27
  • Pull request#2dependabot[bot]2025-11-15 10:27
  • Pull request#2dependabot[bot]2025-11-15 10:27
  • Issue comment#21socket-security[bot]2025-01-21 23:36
    Bump undici from 5.28.3 to 5.28.5 in the npm_and_yarn group across 1 directory
  • Pull request#21dependabot[bot]2025-01-21 23:35

Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 1 stars here means stars gained during the window, not the repo's star count.