https://github.com/tornidomaroc-web/fixor
· scanned 2026-06-16 00:40 UTC (2 months, 1 week ago)
290 raw signals (86 security + 204 graph)
Last scanned 2 months, 1 week ago · v1 · 205 actionable findings from 2 signal sources. 191 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
Showing 131 of 205 actionable findings. 396 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
repo-level (15 hits)repo-level (23 hits)fixtures/secrets-exposure/positive/03-firebase-admin-in-component.tsx:13
Private key in repo
fixtures/secrets-exposure/positive/03-firebase-admin-in-component.tsx:12
fixtures/secrets-exposure/positive/06-aws-keys-hardcoded.js:6
fixtures/secrets-exposure/positive/08-postgres-password-client.ts:8
src/analysis-engine/detectors/secrets-exposure.detector.ts:188
repo-level (14 hits)repo-level (2 hits)repo-level (55 hits)fixtures/auth-bypass/positive/20-fastapi-bare-delete-getdb.py:11
securityAuth fastapi unauth mutation
fixtures/auth-bypass/negative/23-flask-shorthand-login-required.py:10
securityAuth fastapi unauth mutation
fixtures/auth-bypass/negative/21-fastapi-security-current-user.py:11
securityAuth fastapi unauth mutation
fixtures/auth-bypass/positive/21-fastapi-noauth-tier-change.py:9
securityAuth fastapi unauth mutation
repo-level (26 hits)repo-level (57 hits).github/workflows/pages.yml
CI/CD securitySupply chainGithub actions
src/services/xss-fix.service.ts:36
Dangerous innerhtml
src/services/xss-fix.service.ts:31
Direct innerhtml assignment
src/config/vulnerability-registry.ts:75
Node child process
src/services/cmdi-fix.service.ts:34
Node child process
Dockerfile:1, 8 (2 hits).github/workflows/ci.yml:23, 26 (2 hits).github/workflows/pages.yml:36src/services/xss-fix.service.ts:40
Document write
repo-level (4 hits)fixtures/secrets-exposure/negative/09-slack-webhook-from-env.py:18
fixtures/secrets-exposure/positive/09-slack-webhook-hardcoded.py:21
fixtures/admin-check/negative/09-fastapi-rbac-dep.py:10
fixtures/auth-bypass/positive/08-jwt-verify-false.py:9
This page is publicly accessible at:
https://repobility.com/scan/01bde0d6-b133-467f-9e4b-0e98b55e7156/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/01bde0d6-b133-467f-9e4b-0e98b55e7156/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.