live · scanning repos
Scanrepo
github.com
github.com / bisug

bisug/heroku-buildpack-bun

Shell·14 files·commit 0ef6b34·scanned 6d ago·cached ✓
4/100
SAFE
No malicious patterns found. Repo signals are consistent with a legitimate project.
verdict accurate?
CLI tool detected
threat-state: safelive

FINDINGS ░▒▓

infoAuthor has no other public repositoriesGitHub user "dependabot[bot]" has no other public repositories, common for burner accounts used in scams.+2

Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.

1 files scanned @ 0ef6b34 | 8/19/2026 | heuristic scan — always review manually

risk by category
code execution0
network & exfiltration0
file system access0
obfuscation0
supply chain2
owasp / injection0
telemetry
files 1/14rules hit 1engine v5commit 0ef6b34

github

bisug/heroku-buildpack-bun

Unofficial Heroku buildpack for Bun.js

Shell
5
0
107d
14 files
1 scanned(7%)
0ef6b34

architecture░▒▓

No architecture graph available. This usually happens when the repo contains no scannable JS/TS/Python files or only a single file was analyzed.

SAFE (4/100) — bisug/heroku-buildpack-bun — ScanRepo