How it works

GiTRay answers one question before you clone, install or open a repository: does it use a trick that malware is known to use? This is what happens when you press Scan.

  1. 01Metadata, not a clone

    Repository, owner and release details come from the GitHub API. Release files are never downloaded; their SHA-256 fingerprints are looked up on VirusTotal.

  2. 02Read in memory, with limits

    The source archive is streamed and unpacked in memory with hard limits on size, file count and time, ZIP files inside it included. Files that .gitattributes keeps out of GitHub's archive are fetched separately. Nothing is written to disk and nothing is executed.

  3. 03Explainable rules

    Each rule looks for one known trick and explains why it is dangerous. Every finding comes with file, line, the exact code and a 0-100 score contribution.

  4. 04A score and a verdict

    Each rule adds its strongest finding once, up to 100. Below 30 is Clean, from 30 Suspicious, from 70 Dangerous. When a safety limit stops the scan, the verdict is Incomplete, never Clean.

What GiTRay never does

  • Run code from the repository

    No install, no build, no scripts, no sandbox. Every file is only read.

  • Write the repository to disk

    The archive is unpacked in memory with hard limits, so an archive bomb cannot fill a disk.

  • Download release files

    Only their SHA-256 fingerprints are looked up on VirusTotal. No file is ever uploaded or downloaded.

  • Trust what the repository says

    File names, README text and code are shown with hidden characters made visible and links disarmed. Links from the repository are never clickable.

Limits

  • Results are heuristics. A Clean verdict lowers the risk; it does not prove a repository is safe.
  • Only known tricks are recognised. Brand-new techniques can pass until a rule learns them.
  • A result covers the scanned commit only. A later commit can change everything.
  • Git submodules are listed but not scanned, because they come from other repositories.
  • When a safety limit stops a scan, the result is Incomplete, never Clean.

Try it on a repository

Try:
See all 35 rules →