Build product integrations with AI.
This report presents the forensic synthetic code analysis of NangoHQ/nango, a TypeScript project with 11,094 GitHub stars. SynthScan v2.0 examined 362,020 lines of code across 2107 source files, recording 609 pattern matches distributed across 12 syntactic categories. The overall adjusted score of 2.8 places this repository in the Likely human-written band.
The scanner applied 160+ deterministic lexical heuristics, multi-line block detectors, abstract syntax tree depth profilers, and a cross-file Jaccard similarity matrix to construct a statistically normalised synthetic code estimate. All matches are individually weighted by severity coefficient and contextual multiplier before summation, and the resulting headline score is temporally discounted to account for the repository's development history relative to the commercial emergence of large language model coding tooling (November 2022 onward).
Longitudinal tracking requires multiple scan runs. Once this repository is re-scanned after new commits land, this chart will visualise how the synthetic code signal evolves over time — enabling you to detect whether AI authorship is growing, stabilising, or being actively corrected by human engineers.
Classifies detected patterns by their diagnostic confidence and structural impact. CRITICAL patterns (coefficient 10) represent definitive synthetic signatures — hallucinated imports, explicit LLM attribution metadata — virtually never produced by human authors. HIGH (5) indicates strong structural tells such as cross-file repetition or cross-linguistic idioms. MEDIUM (2) covers recognisable conversational padding and AI-specific vocabulary. LOW (1) captures subtle indicators like tautological comments and generic boilerplate that require density to carry independent signal.
This horizontal bar chart decomposes the repository's raw synthetic code score by top-level directory, allowing you to pinpoint precisely which modules or components carry the highest AI authorship density. Directories with disproportionately high scores relative to their size warrant targeted manual review: concentrated AI signatures often trace back to mass-generated configuration layers, auto-ported test suites, LLM-scaffolded boilerplate classes, or entire subsystems authored under heavy copilot assistance. Use this view to prioritise your human code-review effort.
The scanner identified 609 distinct pattern matches across 12 syntactic categories. Each entry below represents a discrete location in the source code where the engine recorded a statistically significant AI authorship indicator. Expand any category row to inspect the individual file paths, line numbers, code snippets, and the lexical context (CODE, COMMENT, or STRING) in which each match was detected.
Reading the findings table: The Severity column indicates the diagnostic confidence level (CRITICAL / HIGH / MEDIUM / LOW). The Context column identifies whether the match occurred inside executable code, an inline comment, or a string literal — comment-context matches receive a ×1.5 weight because LLMs systematically over-annotate. The ⚡ bolt icon marks clustered matches: three or more patterns within a 10-line window, each receiving an additional ×1.5 density multiplier as dense clusters constitute far stronger evidence of synthetic authorship than isolated hits.
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| HIGH⚡ | docs/llms-full.txt | 8765 | const nango = new Nango({ secretKey: '<YOUR-API-KEY>' }); | CODE |
| HIGH⚡ | docs/llms-full.txt | 8765 | const nango = new Nango({ secretKey: '<YOUR-API-KEY>' }); | CODE |
| HIGH⚡ | docs/llms-full.txt | 8772 | --header 'Authorization: Bearer <YOUR-API-KEY>' | CODE |
| HIGH⚡ | docs/llms-full.txt | 8772 | --header 'Authorization: Bearer <YOUR-API-KEY>' | CODE |
| HIGH⚡ | packages/providers/providers.yaml | 10485 | doc_section: '#step-1-finding-your-api-key-warehouse-and-customer-number' | CODE |
| HIGH⚡ | packages/providers/providers.yaml | 10491 | doc_section: '#step-1-finding-your-api-key-warehouse-and-customer-number' | CODE |
| HIGH⚡ | packages/providers/providers.yaml | 10498 | doc_section: '#step-1-finding-your-api-key-warehouse-and-customer-number' | CODE |
| HIGH | packages/providers/providers.yaml | 295 | doc_section: '#step-2-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 675 | doc_section: '#step-1-obtain-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 736 | doc_section: '#step-1-generating-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 764 | doc_section: '#step-1-generating-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 849 | doc_section: '#step-1-generating-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 1008 | doc_section: '#step-1-getting-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 1310 | doc_section: '#step-1-obtain-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 1333 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 1511 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 1562 | doc_section: '#step-1-generating-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 1582 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 1691 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 1915 | doc_section: '#step-1-generating-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 1924 | doc_section: '#step-1-generating-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 2068 | doc_section: '#step-1-obtaining-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 2415 | doc_section: '#step-1-generating-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 2917 | doc_section: '#step-2-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 3054 | doc_section: '#step-1-generating-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 3216 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 3231 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 3493 | doc_section: '#step-2-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 3656 | doc_section: '#step-2-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 3694 | doc_section: '#step-2-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 3756 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 3855 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 3892 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 3968 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 3995 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 4535 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 4956 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 5970 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 5988 | doc_section: '#step-1-obtaining-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 6143 | doc_section: '#step-1-obtain-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 6269 | doc_section: '#step-1-get-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 6874 | doc_section: '#step-1-get-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 6930 | doc_section: '#step-2-obtaining-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 7088 | doc_section: '#step-2-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 7179 | doc_section: '#step-1-generate-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 7411 | doc_section: '#step-1-getting-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 7497 | doc_section: '#step-2-generating-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 7757 | doc_section: '#step-1-generating-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 7895 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 7933 | doc_section: '#step-1-generating-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 8138 | doc_section: '#step-2-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 8251 | doc_section: '#step-1-getting-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 8331 | doc_section: '#step-1-generating-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 8934 | doc_section: '#step-1-getting-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 9696 | doc_section: '#step-2-obtaining-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 9996 | doc_section: '#step-1-generating-your-api-key-and-app-id' | CODE |
| HIGH | packages/providers/providers.yaml | 10004 | doc_section: '#step-1-generating-your-api-key-and-app-id' | CODE |
| HIGH | packages/providers/providers.yaml | 10367 | doc_section: '#step-1-generating-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 10463 | doc_section: '#step-1-finding-your-api-key' | CODE |
| HIGH | packages/providers/providers.yaml | 10524 | doc_section: '#step-2-generating-your-api-key' | CODE |
| 69 more matches not shown… | ||||
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | docs/custom.js | 188 | function updateQuickstartCopyPageAction() { | CODE |
| LOW | scripts/docs-generate-llms.ts | 294 | function resolveProviderCatalogConfig(provider: ProviderConfig | undefined): ProviderCatalogConfig { | CODE |
| LOW | scripts/docs-generate-llms.ts | 434 | function routeForExistingProviderPage(route: string, slug: string): string { | CODE |
| LOW | scripts/docs-generate-llms.ts | 447 | function routeForExistingOptionalPage(route: string, page: string): string | undefined { | CODE |
| LOW | scripts/docs-generate-llms.ts | 452 | function routeForExistingSetupPage(route: string): string | undefined { | CODE |
| LOW | …ts/one-off/backfill-orb-subscription-dates/backfill.ts | 39 | async function fetchOrbSubscriptionSchedule(subscriptionId: string): Promise<OrbSubscriptionScheduleItem[]> { | CODE |
| LOW | scripts/validation/providers/sync-scopes.ts | 419 | function getDiffTargetProviderNames(providerMap: ProvidersMap): string[] { | CODE |
| LOW | scripts/validation/providers/sync-scopes.ts | 430 | function getExplicitTargetProviderNames(providerMap: ProvidersMap): string[] { | CODE |
| LOW | scripts/validation/providers/validate.ts | 327 | function findConnectionConfigReferences(obj: Record<string, any>, path: string[] = []): Ref[] { | CODE |
| LOW | packages/records/lib/helpers/uniqueKey.ts | 7 | export function verifyUniqueKeysAreUnique(records: FormattedRecord[]): { nonUniqueKeys: Set<string> } { | CODE |
| LOW | packages/egress/lib/denylist.ts | 16 | export function canonicalizeHostnameForDenylist(host: string): string { | CODE |
| LOW | packages/egress/lib/denylist.ts | 28 | export function formatHostForUrlAuthority(host: string): string { | CODE |
| LOW | packages/egress/lib/denylist.ts | 78 | export function mergeProxyBaseUrlOverrideDenylist(customEntries: string[]): string[] { | CODE |
| LOW | packages/egress/lib/denylist.ts | 89 | export function resolveProxyBaseUrlOverrideDenylist(raw: string | undefined): string[] { | CODE |
| LOW | packages/egress/lib/denylist.ts | 121 | export function resolveProxyBaseUrlOverrideDenylistForRunner(raw: string | undefined): string[] { | CODE |
| LOW | packages/egress/lib/agent.ts | 56 | export function clearPinnedAddressCacheForTests(): void { | CODE |
| LOW | packages/egress/lib/validate.ts | 126 | async function resolveAndValidateAddresses( | CODE |
| LOW | packages/egress/lib/validate.ts | 187 | export async function resolveValidatedHostAddresses(hostname: string, policy: OutboundUrlPolicy, url: string): Promise<s | CODE |
| LOW | packages/egress/lib/validate.ts | 214 | export function assertSafeOutboundUrlSync(url: string, policy: OutboundUrlPolicy, ctx?: ValidateOutboundUrlContext): URL | CODE |
| LOW | packages/egress/lib/validate.ts | 234 | export function isBaseUrlOverrideDeniedByPolicy(url: string, policy: OutboundUrlPolicy): boolean { | CODE |
| LOW | packages/egress/lib/policy.ts | 123 | function isBaseUrlOverrideEnabledFromEnv(raw: string | undefined): boolean { | CODE |
| LOW | packages/egress/lib/policy.ts | 138 | export function resolvePolicyForRunnerSync(input: RunnerPolicyEnvInput): OutboundUrlPolicy { | CODE |
| LOW | packages/egress/lib/policy.ts | 157 | export function resolvePolicyFromProcessEnvForRunner(): OutboundUrlPolicy { | CODE |
| LOW | packages/egress/lib/policy.ts | 167 | export function resolveProxyDenylistFromServerRaw(raw: string | undefined): string[] { | CODE |
| LOW | packages/egress/lib/redirect.ts | 27 | export function absoluteUrlFromRedirectRequestOptions(options: Record<string, unknown>): string | null { | CODE |
| LOW | packages/egress/lib/redirect.ts | 65 | export function createAsyncRedirectValidator( | CODE |
| LOW | packages/runner/lib/monitor.ts | 224 | function getRenderTotalMemoryInBytes(): number { | CODE |
| LOW | packages/runner/lib/sdk/sdk.unit.test.ts | 752 | function expectInvalidCredentialsInLogs(persistClient: PersistClient, present: boolean): void { | CODE |
| LOW | packages/webapp/src/features/TokenEditorOverlay.tsx | 227 | function collectPrimitiveAliasRefs(ref: string): string[] { | CODE |
| LOW | packages/webapp/src/features/tokenContrast.ts | 218 | export function deriveContrastRelevantVars(opts: { isKnownToken: (cssVar: string) => boolean; surfaces: string[]; allVar | CODE |
| LOW | packages/webapp/src/features/tokenEditorPersistence.ts | 69 | export function syncPersistedOverridesToTheme(theme: ThemeKey) { | CODE |
| LOW⚡ | packages/webapp/src/features/Playground/analytics.ts | 15 | export function trackPlaygroundRunClicked(properties: { function_type: string; integration: string; is_run_again: boolea | CODE |
| LOW⚡ | packages/webapp/src/features/Playground/analytics.ts | 19 | export function trackPlaygroundRunCompleted(properties: { function_type: string; integration: string; success: boolean; | CODE |
| LOW⚡ | packages/webapp/src/features/Playground/analytics.ts | 23 | export function trackPlaygroundRunCancelled(properties: { function_type: string; integration: string }) { | CODE |
| LOW | …ges/webapp/src/features/Playground/playground.utils.ts | 43 | export function validateAndParseInputs(inputFields: InputField[], inputValues: Record<string, string>): ParseResult { | CODE |
| LOW | packages/webapp/src/utils/connect-ui.ts | 3 | export function createConnectUIPreviewIFrame({ baseURL, apiURL, sessionToken, lang }: ConnectUIProps) { | CODE |
| LOW | packages/webapp/src/utils/scripts.ts | 75 | function propertiesToTypescriptExamples(schema: JSONSchema7): string[] { | CODE |
| LOW | packages/webapp/src/utils/scripts.ts | 102 | export function propertyToTypescriptExample(schema: JSONSchema7): string { | CODE |
| LOW | packages/webapp/src/utils/utils.ts | 46 | export function formatDateToPreciseUSFormat(dateString: string): string { | CODE |
| LOW | packages/webapp/src/utils/utils.ts | 88 | export function formatDateToInternationalFormat(dateString: string): string { | CODE |
| LOW | packages/webapp/src/utils/playground.ts | 22 | export function openPlaygroundWithContext(override: PlaygroundContextOverride) { | CODE |
| LOW | packages/webapp/src/utils/integrationConfig.ts | 11 | export function isIntegrationConfigFieldVisible( | CODE |
| LOW | packages/webapp/src/components/ui/Chart.tsx | 256 | function getPayloadConfigFromPayload(config: ChartConfig, payload: unknown, key: string) { | CODE |
| LOW | packages/webapp/src/components/ui/Dialog.tsx | 9 | function restoreLeakedRadixBodyPointerEvents(ownerDocument = globalThis?.document) { | CODE |
| LOW | …bapp/src/components/patterns/chart/usageChartColors.ts | 114 | export function resetUsageChartColorsForTests(): void { | CODE |
| LOW | packages/webapp/src/hooks/useIntegration.tsx | 107 | export function useDeleteIntegrationFunction(env: string, integrationId: string, functionName: string, type: 'sync' | 'a | CODE |
| LOW | packages/webapp/src/hooks/useAuth.tsx | 67 | export function useResendVerificationEmail() { | CODE |
| LOW | packages/webapp/src/hooks/useAuth.tsx | 85 | export function useResendVerificationEmailByUuid() { | CODE |
| LOW | packages/webapp/src/hooks/useAuth.tsx | 103 | export function useManagedEmailVerification() { | CODE |
| LOW | packages/webapp/src/hooks/useAuth.tsx | 119 | export function useManagedEmailVerificationAPI() { | CODE |
| LOW | packages/webapp/src/hooks/useAuth.tsx | 212 | export function useRequestPasswordResetAPI() { | CODE |
| LOW | packages/webapp/src/hooks/useAuth.tsx | 323 | export function usePostOnboardingHearAboutUs() { | CODE |
| LOW | packages/webapp/src/hooks/useRecords.tsx | 7 | export function useConnectionRecordModels(queries: GetConnectionRecordModels['Querystring'], params: GetConnectionRecord | CODE |
| LOW | packages/webapp/src/hooks/useRecords.tsx | 80 | export function useConnectionRecordPayload( | CODE |
| LOW | packages/webapp/src/hooks/useIntegrationFunctions.tsx | 17 | export function useGetIntegrationFunctions({ env, providerConfigKey, search, type, limit = DEFAULT_LIMIT }: UseGetIntegr | CODE |
| LOW | packages/webapp/src/hooks/useIntegrationFunctions.tsx | 63 | export function useGetIntegrationFunction({ env, providerConfigKey, name, type }: UseGetIntegrationFunctionArgs) { | CODE |
| LOW | packages/webapp/src/hooks/useIntegrationFunctions.tsx | 97 | export function useGetIntegrationFunctionCode({ env, providerConfigKey, name, type, enabled = true }: UseGetIntegrationF | CODE |
| LOW | packages/webapp/src/hooks/useIntegrationFunctions.tsx | 128 | export function useGetIntegrationTemplates({ env, providerConfigKey }: UseGetIntegrationTemplatesArgs) { | CODE |
| LOW | packages/webapp/src/hooks/usePlan.tsx | 212 | function topDimensionValuesQueryKey(timeframe: { start: string; end: string } | undefined, metric: UsageMetric, dimensio | CODE |
| LOW | packages/webapp/src/hooks/usePlan.tsx | 216 | function fetchTopDimensionValuesPage( | CODE |
| 202 more matches not shown… | ||||
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | docs/llms-full.txt | 9198 | "end_user_email": "user@example.com", | CODE |
| LOW | docs/llms-full.txt | 9214 | "end_user_email": "user@example.com", | CODE |
| LOW | docs/llms-full.txt | 9914 | "end_user_email": "user@example.com", | CODE |
| LOW | docs/llms-full.txt | 9930 | "end_user_email": "user@example.com", | CODE |
| LOW | docs/llms-full.txt | 10573 | "end_user_email": "user@example.com", | CODE |
| LOW | docs/llms-full.txt | 10589 | "end_user_email": "user@example.com", | CODE |
| LOW | docs/llms-full.txt | 10914 | "end_user_email": "user@example.com", | CODE |
| LOW | packages/node-client/lib/index.unit.test.ts | 128 | tags: { displayName: 'My User', email: 'user@example.com' } | CODE |
| LOW | packages/node-client/lib/index.unit.test.ts | 139 | expect(url.searchParams.get('tags[end_user_email]')).toBe('user@example.com'); | CODE |
| LOW⚡ | …cords/lib/stores/postgres/postgres.integration.test.ts | 75 | { id: '1', name: 'John Doe' }, | CODE |
| LOW⚡ | …cords/lib/stores/postgres/postgres.integration.test.ts | 76 | { id: '1', name: 'John Doe' }, | CODE |
| LOW⚡ | …cords/lib/stores/postgres/postgres.integration.test.ts | 77 | { id: '2', name: 'Jane Doe' }, | CODE |
| LOW⚡ | …cords/lib/stores/postgres/postgres.integration.test.ts | 153 | { id: '1', name: 'John Doe' }, | CODE |
| LOW⚡ | …cords/lib/stores/postgres/postgres.integration.test.ts | 154 | { id: '1', name: 'John Doe' }, | CODE |
| LOW⚡ | …cords/lib/stores/postgres/postgres.integration.test.ts | 155 | { id: '2', name: 'Jane Doe' }, | CODE |
| LOW⚡ | …cords/lib/stores/postgres/postgres.integration.test.ts | 480 | { id: '1', name: 'John Doe' }, | CODE |
| LOW⚡ | …cords/lib/stores/postgres/postgres.integration.test.ts | 481 | { id: '1', name: 'John Doe' }, | CODE |
| LOW⚡ | …cords/lib/stores/postgres/postgres.integration.test.ts | 482 | { id: '2', name: 'Jane Doe' }, | CODE |
| LOW⚡ | …cords/lib/stores/postgres/postgres.integration.test.ts | 622 | { id: '1', name: 'John Doe' }, | CODE |
| LOW⚡ | …cords/lib/stores/postgres/postgres.integration.test.ts | 623 | { id: '2', name: 'Jane Doe' }, | CODE |
| LOW⚡ | …cords/lib/stores/postgres/postgres.integration.test.ts | 632 | { id: '1', name: 'John Doe' }, | CODE |
| LOW⚡ | …cords/lib/stores/postgres/postgres.integration.test.ts | 633 | { id: '2', name: 'Jane Doe' } | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 35 | { id: '1', name: 'John Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 36 | { id: '2', name: 'Jane Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 96 | { id: '1', name: 'John Doe' }, // same | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 116 | decrypted: { id: '1', name: 'John Doe' } | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 171 | { id: '1', name: 'John Doe' }, // same | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 187 | decrypted: { id: '1', name: 'John Doe' } | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 208 | { id: '1', name: 'John Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 209 | { id: '2', name: 'Jane Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 288 | { id: '1', name: 'John Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 289 | { id: '2', name: 'Jane Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 307 | { id: '1', name: 'John Doe' }, // same | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 308 | { id: '2', name: 'Jane Doe' } // same | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 413 | const records = [{ id: '1', person: { name: 'John Doe', age: 35, children: [{ name: 'Jenny Doe', age: 3 }] } | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 463 | name: 'John Doe', | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 514 | { id: '1', name: 'John Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 515 | { id: '2', name: 'Jane Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 673 | { id: '1', name: 'John Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 674 | { id: '2', name: 'Jane Doe' } | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 784 | const toInsert = [{ id: '1', name: 'John Doe' }]; | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 793 | expect(records).toContainEqual(expect.objectContaining({ id: '1', name: 'John Doe' })); | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1020 | { id: '1', name: 'John Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1021 | { id: '2', name: 'Jane Doe' } | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1045 | { id: '1', name: 'John Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1046 | { id: '2', name: 'Jane Doe' } | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1099 | { id: '1', name: 'John Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1100 | { id: '2', name: 'Jane Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1131 | const rec1 = { id: '1', name: 'John Doe' }; | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1132 | const rec2 = { id: '2', name: 'Jane Doe' }; | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1187 | { id: '1', name: 'John Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1188 | { id: '2', name: 'Jane Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1312 | { id: '1', name: 'John Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1313 | { id: '2', name: 'Jane Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1340 | { id: '1', name: 'John Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1341 | { id: '2', name: 'Jane Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1370 | { id: '1', name: 'John Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1371 | { id: '2', name: 'Jane Doe' } | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1407 | { id: '1', name: 'John Doe' }, | CODE |
| LOW | …cords/lib/stores/postgres/postgres.integration.test.ts | 1408 | { id: '2', name: 'Jane Doe' }, | CODE |
| 66 more matches not shown… | ||||
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | packages/webapp/src/features/tokenContrast.ts | 89 | // ── Colour math (WCAG 2.x) ────────────────────────────────────────────────── | COMMENT |
| MEDIUM | packages/webapp/src/features/tokenContrast.ts | 180 | // ── Intent-table walking ───────────────────────────────────────────────────── | COMMENT |
| MEDIUM | packages/webapp/src/components/PlainChat.tsx | 9 | // ─── Plain types ────────────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | packages/webapp/src/components/PlainChat.tsx | 130 | // ─── PlainChat ──────────────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …ages/webapp/src/pages/Environment/Settings/ApiKeys.tsx | 74 | // ── Scope selector with dropdown + collapsible groups ─────────────── | COMMENT |
| MEDIUM | …ages/webapp/src/pages/Environment/Settings/ApiKeys.tsx | 227 | // ── Create dialog ─────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …ages/webapp/src/pages/Environment/Settings/ApiKeys.tsx | 306 | // ── Key configuration page ────────────────────────────────────────── | COMMENT |
| MEDIUM | …ages/webapp/src/pages/Environment/Settings/ApiKeys.tsx | 406 | // ── Delete button with self-managed open state ───────────────────── | COMMENT |
| MEDIUM | …ages/webapp/src/pages/Environment/Settings/ApiKeys.tsx | 430 | // ── Managed secret key (env var) ──────────────────────────────────── | COMMENT |
| MEDIUM | …ages/webapp/src/pages/Environment/Settings/ApiKeys.tsx | 465 | // ── Main component ────────────────────────────────────────────────── | COMMENT |
| MEDIUM | packages/server/lib/authz/authz.integration.test.ts | 25 | // ── Helpers ────────────────────────────────────────────── | COMMENT |
| MEDIUM | packages/server/lib/authz/authz.integration.test.ts | 77 | // ── Administrator — always allowed ────────────────────── | COMMENT |
| MEDIUM | packages/server/lib/authz/authz.integration.test.ts | 139 | // ── production_support — denied writes on prod ────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 54 | // ── Integrations ──────────────────────────────────────────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 126 | // ── Connections ────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 170 | // ── Connect Sessions ──────────────────────────────────────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 186 | // ── Deploy ─────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 202 | // ── Records ────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 218 | // ── Syncs ──────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 248 | // ── Actions ────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 270 | // ── V1 passthrough (deprecated) ─────────────────────────────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 374 | // ── Proxy ──────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 390 | // ── Config ─────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 420 | // ── MCP ────────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 436 | // ── Wildcard ───────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 467 | // ── Credential stripping ───────────────────────────────────────── | COMMENT |
| MEDIUM | …rs/v1/environment/scopeEnforcement.integration.test.ts | 633 | // ── Internal script key (Nango-Is-Script header) ──────────────── | COMMENT |
| MEDIUM | …/design-system/tokens/stories/ColorPalette.stories.tsx | 15 | // ─── Semantic data ──────────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …/design-system/tokens/stories/ColorPalette.stories.tsx | 23 | // ─── Primitive data ─────────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …/design-system/tokens/stories/ColorPalette.stories.tsx | 70 | // ─── Stories ───────────────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | …es/design-system/tokens/stories/Typography.stories.tsx | 88 | // ─── Stories ───────────────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | packages/design-system/src/components/ui/button.tsx | 101 | // ─── Button ─────────────────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | packages/design-system/src/components/ui/button.tsx | 139 | // ─── IconButton ─────────────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | packages/billing/lib/clients/orb/adapters.unit.test.ts | 11 | // ─── toOrbEvent ─────────────────────────────────────────────────────────────── | COMMENT |
| MEDIUM⚡ | packages/billing/lib/clients/orb/adapters.unit.test.ts | 115 | // ─── toOrbPutCustomerPayload ────────────────────────────────────────────────── | COMMENT |
| MEDIUM⚡ | packages/billing/lib/clients/orb/adapters.unit.test.ts | 211 | // ─── fromOrbCustomer ────────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | packages/billing/lib/clients/orb/adapters.unit.test.ts | 267 | // ─── fromOrbAddress ─────────────────────────────────────────────────────────── | COMMENT |
| MEDIUM | packages/billing/lib/clients/orb/adapters.unit.test.ts | 281 | // ─── orbMetricToUsageMetric ─────────────────────────────────────────────────── | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | .agents/skills/agent-builder-skill/SKILL.md | 63 | ### Step 1: Identify the Use Case | COMMENT |
| LOW | .agents/skills/agent-builder-skill/SKILL.md | 77 | ### Step 2: Design Agent Scope | COMMENT |
| LOW | .agents/skills/agent-builder-skill/SKILL.md | 92 | ### Step 3: Write the System Prompt | COMMENT |
| LOW | .agents/skills/agent-builder-skill/SKILL.md | 173 | ### Step 4: Configure Tools Access | COMMENT |
| LOW | .agents/skills/agent-builder-skill/SKILL.md | 217 | ### Step 5: Choose Model | COMMENT |
| LOW | .agents/skills/agent-builder-skill/SKILL.md | 261 | ### Step 6: Write Clear Description | COMMENT |
| LOW | docs/llms-full.txt | 7681 | ## Step 1: Add a checkpoint schema to your sync declaration | COMMENT |
| LOW | docs/llms-full.txt | 7714 | ## Step 2: Replace `lastSyncDate` reads with `getCheckpoint()` | COMMENT |
| LOW | docs/llms-full.txt | 7750 | ## Step 3: Add `saveCheckpoint()` calls after each batch | COMMENT |
| LOW | docs/llms-full.txt | 7797 | ## Step 4: Test locally | COMMENT |
| LOW | docs/llms-full.txt | 7807 | ## Step 5: Deploy | COMMENT |
| LOW | docs/llms-full.txt | 7860 | ## Step 1: Start sending tags for new connect sessions | COMMENT |
| LOW | docs/llms-full.txt | 7903 | ## Step 2: Update webhook reconciliation to use `tags` | COMMENT |
| LOW | docs/llms-full.txt | 7925 | ## Step 3: Existing connections are already backfilled | COMMENT |
| LOW | docs/llms-full.txt | 7942 | ## Step 4: Stop using `end_user` | COMMENT |
| LOW | docs/llms-full.txt | 8007 | ## Step 1: Attach tags to all existing connections | COMMENT |
| LOW | docs/llms-full.txt | 8049 | ## Step 2: Implement the Connect and reconnect flows | COMMENT |
| LOW | docs/llms-full.txt | 8055 | ### Step 3: Clean up | COMMENT |
| LOW⚡ | …/server/lib/webhook/connectwise-psa-webhook-routing.ts | 91 | // Step 1: Hash the shared secret key with SHA256 | COMMENT |
| LOW⚡ | …/server/lib/webhook/connectwise-psa-webhook-routing.ts | 94 | // Step 2: Compute HMAC-SHA256 of the payload using the hashed key | COMMENT |
| LOW⚡ | …/server/lib/webhook/connectwise-psa-webhook-routing.ts | 97 | // Step 3: Compare signatures using timing-safe comparison | COMMENT |
| LOW | packages/design-system/AGENTS.md | 13 | ### Step 1: Generate the base with shadcn CLI | COMMENT |
| LOW | packages/design-system/AGENTS.md | 24 | ### Step 2: Replace shadcn CSS variables with design tokens | COMMENT |
| LOW | packages/design-system/AGENTS.md | 125 | ### Step 3: Follow the component pattern | COMMENT |
| LOW | packages/design-system/AGENTS.md | 175 | ### Step 4: Add a Storybook story | COMMENT |
| LOW | packages/design-system/AGENTS.md | 200 | ### Step 5: Export from the barrel | COMMENT |
| LOW | .github/workflows/managed-release.yaml | 129 | # Step 1: Wait for PostgreSQL to be ready | COMMENT |
| LOW | .github/workflows/managed-release.yaml | 150 | # Step 2: Perform rolling restart of nango-self-server deployment | COMMENT |
| LOW | .github/workflows/managed-release.yaml | 164 | # Step 3: Wait for other pods to start successfully | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| CRITICAL | …rver/lib/webhook/dispatch-queue/publisher.unit.test.ts | 332 | expect(tracerMocks.span.setTag.mock.calls.filter(([tag]) => tag === 'error')).toHaveLength(0); | CODE |
| CRITICAL | …es/server/lib/controllers/connection/getConnections.ts | 16 | endUserId: bodySchema.shape.end_user.shape.id.optional(), | CODE |
| CRITICAL | …es/server/lib/controllers/connection/getConnections.ts | 18 | endUserOrganizationId: bodySchema.shape.end_user.shape.id.optional(), | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW⚡ | …/server/lib/webhook/connectwise-psa-webhook-routing.ts | 91 | // Step 1: Hash the shared secret key with SHA256 | COMMENT |
| LOW⚡ | …/server/lib/webhook/connectwise-psa-webhook-routing.ts | 94 | // Step 2: Compute HMAC-SHA256 of the payload using the hashed key | COMMENT |
| LOW⚡ | …/server/lib/webhook/connectwise-psa-webhook-routing.ts | 97 | // Step 3: Compare signatures using timing-safe comparison | COMMENT |
| LOW | .github/workflows/managed-release.yaml | 129 | # Step 1: Wait for PostgreSQL to be ready | COMMENT |
| LOW | .github/workflows/managed-release.yaml | 150 | # Step 2: Perform rolling restart of nango-self-server deployment | COMMENT |
| LOW | .github/workflows/managed-release.yaml | 164 | # Step 3: Wait for other pods to start successfully | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | docker-compose.yaml | 61 | nango-redis: | COMMENT |
| LOW | packages/records/lib/stores/postgres/postgres.ts | 141 | // same transaction: the partition is empty at that point so the (non- | COMMENT |
| LOW | packages/connect-ui/src/lib/zod-config.ts | 1 | import * as z from 'zod'; | COMMENT |
| LOW | packages/server/lib/utils/express.ts | 1 | import type { ConnectSession, DBAPISecret, DBEnvironment, DBPlan, DBTeam, DBUser, InternalEndUser } from '@nangohq/types | COMMENT |
| LOW | …rver/lib/controllers/v1/plans/usage/getBillingUsage.ts | 101 | // (`?metrics=records` → string) into an array so the enum check | COMMENT |
| LOW | …/lib/controllers/v1/user/patchUser.integration.test.ts | 41 | }); | COMMENT |
| LOW | …er/lib/controllers/v1/user/getUser.integration.test.ts | 41 | // TODO: can't test stuff that needs `user` because we are using an anonymous secret_key | COMMENT |
| LOW | …llers/v1/team/users/deleteTeamUser.integration.test.ts | 61 | // isSuccess(listBefore.json); | COMMENT |
| LOW | …ers/v1/environment/postEnvironment.integration.test.ts | 61 | error: { | COMMENT |
| LOW | …es/usage/lib/clickhouse/clickhouse.integration.test.ts | 321 | // exposes the two accumulators the formatter needs. | COMMENT |
| LOW | packages/usage/lib/clickhouse/clickhouse.query.ts | 181 | case 'function_compute_gbms': | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| HIGH | packages/kvstore/lib/InMemoryStore.ts | 163 | // AI generated - works well for `usage:*:something:*` | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | packages/providers/providers.scopes.yaml | 2637 | # source: https://developer.datev.de/en/guides/authentication (no comprehensive scopes list or discovery endpoint found) | COMMENT |
| MEDIUM | packages/connect-ui/src/lib/theme.ts | 53 | // Create a temporary element to leverage browser's color parsing | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | .github/workflows/managed-release.yaml | 79 | # Create a new kind cluster for testing | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | .github/workflows/managed-release.yaml | 210 | # Check if any pods are not running | COMMENT |