repomark is a local scanner. It reads selected repository files and local Git metadata, then writes reports. It makes no network requests and stores no credentials.
Report a security issue privately through the repository owner rather than opening a public issue with exploit details. Include reproduction steps, affected version, and impact. Do not include secrets or private repository contents.
repomark scores repository readiness signals. It is not a vulnerability scanner, dependency audit, or guarantee of code safety.