https://github.com/tornidomaroc-web/fixor
· scanned 2026-06-16 00:40 UTC (2 months, 1 week ago)
290 raw signals (86 security + 204 graph)
Last scanned 2 months, 1 week ago · v1 · 205 actionable findings from 2 signal sources. 191 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
All 1635 nodes from the latest scan, grouped by kind. Each node is a unit the engine identified (file, function, endpoint, table…). Most users won't need this view — it's primarily for debugging the engine's graph extraction or for AI agents that want to enumerate the project structure.
| Label | Layer | Status | Path |
|---|---|---|---|
action |
software | healthy | fixtures/webhook-unverified/negative/16-remix-action-stripe… |
verify |
software | healthy | fixtures/webhook-unverified/negative/04-stripe-verify-middl… |
verifyGithubSig |
software | healthy | fixtures/webhook-unverified/negative/02-github-timing-safe-… |
_verify |
software | healthy | fixtures/webhook-unverified/negative/08-flask-github-compar… |
github_webhook |
software | healthy | fixtures/webhook-unverified/negative/08-flask-github-compar… |
handleStripeEvent |
software | healthy | fixtures/webhook-unverified/negative/12-app-router-stripe-c… |
POST |
software | healthy | fixtures/webhook-unverified/negative/12-app-router-stripe-c… |
action |
software | healthy | fixtures/webhook-unverified/negative/17-remix-action-github… |
POST |
software | healthy | fixtures/webhook-unverified/negative/14-app-router-apple-cr… |
POST |
software | healthy | fixtures/webhook-unverified/negative/13-app-router-content-… |
stripe_webhook |
software | healthy | fixtures/webhook-unverified/negative/07-flask-stripe-constr… |
computeFeed |
software | healthy | fixtures/webhook-unverified/negative/11-app-router-cache-ke… |
POST |
software | healthy | fixtures/webhook-unverified/negative/11-app-router-cache-ke… |
body |
software | healthy | fixtures/webhook-unverified/negative/11-app-router-cache-ke… |
POST |
software | healthy | fixtures/webhook-unverified/negative/15-app-router-graph-cl… |
body |
software | healthy | fixtures/webhook-unverified/negative/15-app-router-graph-cl… |
processGraphNotification |
software | healthy | fixtures/webhook-unverified/negative/15-app-router-graph-cl… |
github_webhook |
software | healthy | fixtures/webhook-unverified/positive/08-flask-github-no-sig… |
stripe_webhook |
software | healthy | fixtures/webhook-unverified/positive/07-flask-stripe-no-sig… |
POST |
software | healthy | fixtures/webhook-unverified/positive/15-app-router-graph-cl… |
body |
software | healthy | fixtures/webhook-unverified/positive/15-app-router-graph-cl… |
processGraphNotification |
software | healthy | fixtures/webhook-unverified/positive/15-app-router-graph-cl… |
processBillingEvent |
software | healthy | fixtures/webhook-unverified/positive/13-app-router-custom-u… |
POST |
software | healthy | fixtures/webhook-unverified/positive/13-app-router-custom-u… |
event |
software | healthy | fixtures/webhook-unverified/positive/13-app-router-custom-u… |
POST |
software | healthy | fixtures/webhook-unverified/positive/11-app-router-stripe-n… |
POST |
software | healthy | fixtures/webhook-unverified/positive/14-app-router-apple-cr… |
processLemonEvent |
software | healthy | fixtures/webhook-unverified/positive/12-app-router-lemon-di… |
POST |
software | healthy | fixtures/webhook-unverified/positive/12-app-router-lemon-di… |
action |
software | healthy | fixtures/webhook-unverified/positive/17-remix-action-github… |
action |
software | healthy | fixtures/webhook-unverified/positive/16-remix-action-stripe… |
requireAuth |
software | healthy | fixtures/auth-bypass/negative/04-jwt-verify-rethrows.js:req… |
loader |
software | healthy | fixtures/auth-bypass/negative/17-remix-loader-require-user-… |
main |
software | healthy | fixtures/auth-bypass/negative/05-default-id-in-seed.js:main |
make_test_token |
software | healthy | fixtures/auth-bypass/negative/07-jwt-verify-false-tests.py:8 |
decode_for_assertion |
software | healthy | fixtures/auth-bypass/negative/07-jwt-verify-false-tests.py:… |
user_token |
software | healthy | fixtures/auth-bypass/negative/07-jwt-verify-false-tests.py:… |
GET |
software | healthy | fixtures/auth-bypass/negative/14-app-router-bare-public-rea… |
listPublicPosts |
software | healthy | fixtures/auth-bypass/negative/01-anon-public-data.ts:listPu… |
userId |
software | healthy | fixtures/auth-bypass/negative/01-anon-public-data.ts:userId |
applyReadHistory |
software | healthy | fixtures/auth-bypass/negative/01-anon-public-data.ts:applyR… |
action |
software | healthy | fixtures/auth-bypass/negative/18-remix-action-inline-sessio… |
delete_post |
software | healthy | fixtures/auth-bypass/negative/23-flask-shorthand-login-requ… |
delete_team |
software | healthy | fixtures/auth-bypass/negative/21-fastapi-security-current-u… |
homepage |
software | healthy | fixtures/auth-bypass/negative/06-flask-anon-static.py:14 |
main |
software | healthy | fixtures/auth-bypass/negative/02-internal-dev-tool.ts:main |
delete_account |
software | healthy | fixtures/auth-bypass/negative/20-fastapi-depends-current-us… |
publicFeed |
software | healthy | fixtures/auth-bypass/negative/10-token-public-readonly.ts:p… |
token |
software | healthy | fixtures/auth-bypass/negative/10-token-public-readonly.ts:t… |
listAllUsers |
software | healthy | fixtures/auth-bypass/negative/03-defense-in-depth-role.ts:l… |
Showing first 50 of this kind. Full payload available via the JSON button at the top of the page.
| Label | Layer | Status | Path |
|---|---|---|---|
README.md |
software | healthy | README.md |
package.json |
software | healthy | package.json |
Dockerfile |
software | healthy | Dockerfile |
.gitleaks.toml |
software | healthy | .gitleaks.toml |
package-lock.json |
software | healthy | package-lock.json |
.env.example |
software | healthy | .env.example |
tsconfig.json |
software | healthy | tsconfig.json |
drizzle.config.ts |
software | healthy | drizzle.config.ts |
LICENSE |
software | healthy | LICENSE |
railway.json |
software | healthy | railway.json |
case-multi-dynamic.json |
software | healthy | fixtures/case-multi-dynamic.json |
case-safe-sequelize-orm.json |
software | healthy | fixtures/case-safe-sequelize-orm.json |
case-template-literal.json |
software | healthy | fixtures/case-template-literal.json |
case-safe-postgres.json |
software | healthy | fixtures/case-safe-postgres.json |
case-safe-mysql.json |
software | healthy | fixtures/case-safe-mysql.json |
case-false-positive-sql-word.json |
software | healthy | fixtures/case-false-positive-sql-word.json |
case-sql-words-nonquery.json |
software | healthy | fixtures/case-sql-words-nonquery.json |
case-postgres-concat.json |
software | healthy | fixtures/case-postgres-concat.json |
case-mysql-concat.json |
software | healthy | fixtures/case-mysql-concat.json |
case-double-quote-concat.json |
software | healthy | fixtures/case-double-quote-concat.json |
META.md |
software | healthy | fixtures/webhook-unverified/META.md |
10-go-slack-hmac-equal.go |
software | healthy | fixtures/webhook-unverified/negative/10-go-slack-hmac-equal… |
16-remix-action-stripe-construct-event.ts |
software | healthy | fixtures/webhook-unverified/negative/16-remix-action-stripe… |
09-go-subtle-constant-time.go |
software | healthy | fixtures/webhook-unverified/negative/09-go-subtle-constant-… |
06-twilio-validate-request.js |
software | healthy | fixtures/webhook-unverified/negative/06-twilio-validate-req… |
04-stripe-verify-middleware.js |
software | healthy | fixtures/webhook-unverified/negative/04-stripe-verify-middl… |
02-github-timing-safe-equal.ts |
software | healthy | fixtures/webhook-unverified/negative/02-github-timing-safe-… |
08-flask-github-compare-digest.py |
software | healthy | fixtures/webhook-unverified/negative/08-flask-github-compar… |
12-app-router-stripe-construct-event-proper.ts |
software | healthy | fixtures/webhook-unverified/negative/12-app-router-stripe-c… |
01-stripe-construct-event.ts |
software | healthy | fixtures/webhook-unverified/negative/01-stripe-construct-ev… |
17-remix-action-github-timing-safe-equal.ts |
software | healthy | fixtures/webhook-unverified/negative/17-remix-action-github… |
14-app-router-apple-cross-file-verifier-helper.ts |
software | healthy | fixtures/webhook-unverified/negative/14-app-router-apple-cr… |
13-app-router-content-addressed-storage.ts |
software | healthy | fixtures/webhook-unverified/negative/13-app-router-content-… |
03-custom-strict-hmac.ts |
software | healthy | fixtures/webhook-unverified/negative/03-custom-strict-hmac.… |
18-remix-action-factory-utility-module.ts |
software | healthy | fixtures/webhook-unverified/negative/18-remix-action-factor… |
07-flask-stripe-construct-event.py |
software | healthy | fixtures/webhook-unverified/negative/07-flask-stripe-constr… |
11-app-router-cache-key-hashing.ts |
software | healthy | fixtures/webhook-unverified/negative/11-app-router-cache-ke… |
05-github-octokit-webhooks.js |
software | healthy | fixtures/webhook-unverified/negative/05-github-octokit-webh… |
15-app-router-graph-clientstate-challenge.ts |
software | healthy | fixtures/webhook-unverified/negative/15-app-router-graph-cl… |
06-twilio-no-sig.js |
software | healthy | fixtures/webhook-unverified/positive/06-twilio-no-sig.js |
08-flask-github-no-sig.py |
software | healthy | fixtures/webhook-unverified/positive/08-flask-github-no-sig… |
04-stripe-verify-toggle.js |
software | healthy | fixtures/webhook-unverified/positive/04-stripe-verify-toggl… |
07-flask-stripe-no-sig.py |
software | healthy | fixtures/webhook-unverified/positive/07-flask-stripe-no-sig… |
15-app-router-graph-clientstate-no-compare.ts |
software | healthy | fixtures/webhook-unverified/positive/15-app-router-graph-cl… |
13-app-router-custom-url-sig-header-no-verify.ts |
software | healthy | fixtures/webhook-unverified/positive/13-app-router-custom-u… |
11-app-router-stripe-no-sig.ts |
software | healthy | fixtures/webhook-unverified/positive/11-app-router-stripe-n… |
01-stripe-no-sig.ts |
software | healthy | fixtures/webhook-unverified/positive/01-stripe-no-sig.ts |
14-app-router-apple-cross-file-no-call.ts |
software | healthy | fixtures/webhook-unverified/positive/14-app-router-apple-cr… |
12-app-router-lemon-diy-hmac-stub.ts |
software | healthy | fixtures/webhook-unverified/positive/12-app-router-lemon-di… |
05-lemon-no-sig.js |
software | healthy | fixtures/webhook-unverified/positive/05-lemon-no-sig.js |
Showing first 50 of this kind. Full payload available via the JSON button at the top of the page.
| Label | Layer | Status | Path |
|---|---|---|---|
fixtures |
software | healthy | fixtures |
webhook-unverified |
software | healthy | fixtures/webhook-unverified |
negative |
software | healthy | fixtures/webhook-unverified/negative |
positive |
software | healthy | fixtures/webhook-unverified/positive |
auth-bypass |
software | healthy | fixtures/auth-bypass |
negative |
software | healthy | fixtures/auth-bypass/negative |
positive |
software | healthy | fixtures/auth-bypass/positive |
idor |
software | healthy | fixtures/idor |
negative |
software | healthy | fixtures/idor/negative |
positive |
software | healthy | fixtures/idor/positive |
secrets-exposure |
software | healthy | fixtures/secrets-exposure |
negative |
software | healthy | fixtures/secrets-exposure/negative |
positive |
software | healthy | fixtures/secrets-exposure/positive |
real-shape |
software | healthy | fixtures/real-shape |
express-saas |
software | healthy | fixtures/real-shape/express-saas |
src |
software | healthy | fixtures/real-shape/express-saas/src |
middleware |
software | healthy | fixtures/real-shape/express-saas/src/middleware |
routes |
software | healthy | fixtures/real-shape/express-saas/src/routes |
lane-boundary |
software | healthy | fixtures/real-shape/lane-boundary |
fastapi-saas |
software | healthy | fixtures/real-shape/fastapi-saas |
app |
software | healthy | fixtures/real-shape/fastapi-saas/app |
routers |
software | healthy | fixtures/real-shape/fastapi-saas/app/routers |
idor-multi |
software | healthy | fixtures/idor-multi |
idor-tenant |
software | healthy | fixtures/idor-tenant |
negative |
software | healthy | fixtures/idor-tenant/negative |
positive |
software | healthy | fixtures/idor-tenant/positive |
env-exposure |
software | healthy | fixtures/env-exposure |
negative |
software | healthy | fixtures/env-exposure/negative |
positive |
software | healthy | fixtures/env-exposure/positive |
admin-check |
software | healthy | fixtures/admin-check |
negative |
software | healthy | fixtures/admin-check/negative |
positive |
software | healthy | fixtures/admin-check/positive |
test |
software | healthy | test |
apps |
software | healthy | apps |
dashboard |
software | healthy | apps/dashboard |
src |
software | healthy | apps/dashboard/src |
components |
software | healthy | apps/dashboard/src/components |
ui |
software | healthy | apps/dashboard/src/components/ui |
app |
software | healthy | apps/dashboard/src/app |
sign-up |
software | healthy | apps/dashboard/src/app/sign-up |
[[...sign-up]] |
software | healthy | apps/dashboard/src/app/sign-up/[[...sign-up]] |
api |
software | healthy | apps/dashboard/src/app/api |
health |
software | healthy | apps/dashboard/src/app/api/health |
orgs |
software | healthy | apps/dashboard/src/app/api/orgs |
[id] |
software | healthy | apps/dashboard/src/app/api/orgs/[id] |
settings |
software | healthy | apps/dashboard/src/app/api/orgs/[id]/settings |
billing |
software | healthy | apps/dashboard/src/app/api/billing |
webhook |
software | healthy | apps/dashboard/src/app/api/billing/webhook |
portal |
software | healthy | apps/dashboard/src/app/api/billing/portal |
checkout |
software | healthy | apps/dashboard/src/app/api/billing/checkout |
Showing first 50 of this kind. Full payload available via the JSON button at the top of the page.
| Label | Layer | Status | Path |
|---|---|---|---|
POST /webhook/github |
api | healthy | fixtures/webhook-unverified/negative/08-flask-github-compar… |
POST /webhook/stripe |
api | healthy | fixtures/webhook-unverified/negative/07-flask-stripe-constr… |
POST /posts/<int:post_id>/delete |
api | healthy | fixtures/auth-bypass/negative/23-flask-shorthand-login-requ… |
POST /teams/{team_id}/delete |
api | healthy | fixtures/auth-bypass/negative/21-fastapi-security-current-u… |
GET /api/homepage |
api | healthy | fixtures/auth-bypass/negative/06-flask-anon-static.py |
DELETE /account |
api | healthy | fixtures/auth-bypass/negative/20-fastapi-depends-current-us… |
ANY /account/delete |
api | healthy | fixtures/auth-bypass/negative/22-flask-login-required.py |
DELETE /users/{user_id} |
api | healthy | fixtures/auth-bypass/positive/20-fastapi-bare-delete-getdb.… |
POST /billing/tier |
api | healthy | fixtures/auth-bypass/positive/21-fastapi-noauth-tier-change… |
ANY /users/<int:user_id> |
api | healthy | fixtures/auth-bypass/positive/22-flask-bare-route-no-auth.py |
DELETE /api/notes/<int:note_id> |
api | healthy | fixtures/auth-bypass/positive/07-flask-anon-skip.py |
GET /{doc_id} |
api | healthy | fixtures/idor/negative/09-fastapi-ownership-check.py |
GET /{invoice_id} |
api | healthy | fixtures/idor/positive/03-fastapi.py |
POST /{invoice_id}/void |
api | healthy | fixtures/idor/positive/03-fastapi.py |
POST /users/{user_id}/role |
api | healthy | fixtures/real-shape/lane-boundary/fastapi-admin-no-auth.py |
GET /health |
api | healthy | fixtures/real-shape/fastapi-saas/app/main.py |
GET / |
api | healthy | fixtures/real-shape/fastapi-saas/app/routers/items.py |
GET /{item_id} |
api | healthy | fixtures/real-shape/fastapi-saas/app/routers/items.py |
DELETE /{item_id} |
api | healthy | fixtures/real-shape/fastapi-saas/app/routers/items.py |
GET /admin/stats |
api | healthy | fixtures/real-shape/fastapi-saas/app/routers/admin.py |
POST /admin/users/{user_id}/role |
api | healthy | fixtures/real-shape/fastapi-saas/app/routers/admin.py |
GET /me |
api | healthy | fixtures/real-shape/fastapi-saas/app/routers/users.py |
PATCH /me |
api | healthy | fixtures/real-shape/fastapi-saas/app/routers/users.py |
DELETE /{user_id} |
api | healthy | fixtures/real-shape/fastapi-saas/app/routers/users.py |
GET /{report_id} |
api | healthy | fixtures/idor-tenant/negative/03-fastapi-sqlalchemy-postfet… |
GET /internal/runtime |
api | healthy | fixtures/env-exposure/negative/09-fastapi-runtime-specific.… |
GET /internal/env-keys |
api | healthy | fixtures/env-exposure/negative/08-flask-env-keys-only.py |
GET /api/diagnostics |
api | healthy | fixtures/env-exposure/positive/08-flask-diagnostics.py |
ANY /admin/users/<int:user_id> |
api | healthy | fixtures/admin-check/negative/21-flask-admin-required.py |
POST /users/{user_id}/promote |
api | healthy | fixtures/admin-check/negative/20-fastapi-superuser-inline.py |
GET /admin/dashboard |
api | healthy | fixtures/admin-check/negative/09-fastapi-rbac-dep.py |
DELETE /api/users/<user_id> |
api | healthy | fixtures/admin-check/negative/08-flask-db-role.py |
GET /stats |
api | healthy | fixtures/admin-check/positive/20-fastapi-admin-stats-no-gat… |
POST /webhook/twilio/sms |
api | healthy | fixtures/webhook-unverified/negative/06-twilio-validate-req… |
POST /webhook/lemon |
api | healthy | fixtures/webhook-unverified/positive/05-lemon-no-sig.js |
GET /invoices |
api | healthy | fixtures/auth-bypass/positive/05-missing-middleware.js |
GET /subscription |
api | healthy | fixtures/auth-bypass/positive/05-missing-middleware.js |
POST /cancel |
api | healthy | fixtures/auth-bypass/positive/05-missing-middleware.js |
GET /:id |
api | healthy | fixtures/real-shape/express-saas/src/routes/documents.js |
POST /:id/role |
api | healthy | fixtures/real-shape/express-saas/src/routes/admin.js |
DELETE /:id |
api | healthy | fixtures/real-shape/express-saas/src/routes/accounts.js |
POST /users/:id/role |
api | healthy | fixtures/real-shape/lane-boundary/express-admin-no-auth.js |
GET /api/v1/health |
api | healthy | fixtures/env-exposure/negative/06-logger-only-env.js |
GET /healthz |
api | healthy | fixtures/env-exposure/negative/05-healthz-specific-fields.js |
GET /api/customers/:id |
api | healthy | fixtures/env-exposure/positive/07-error-includes-env.js |
GET /api/v1/diagnostics |
api | healthy | fixtures/env-exposure/positive/11-redacted-diagnostics.js |
POST /api/admin/promote |
api | healthy | fixtures/admin-check/negative/06-claims-middleware.js |
DELETE /api/users/:id |
api | healthy | fixtures/admin-check/negative/05-db-role-on-delete.js |
POST /webhook/usage |
api | healthy | fixtures/webhook-unverified/negative/03-custom-strict-hmac.… |
GET /teams |
api | healthy | fixtures/auth-bypass/negative/11-router-properly-guarded.ts |
Showing first 50 of this kind. Full payload available via the JSON button at the top of the page.
| Label | Layer | Status | Path |
|---|---|---|---|
the |
software | healthy | fixtures/webhook-unverified/negative/11-app-router-cache-ke… |
the |
software | healthy | fixtures/webhook-unverified/negative/15-app-router-graph-cl… |
CustomersAdminController |
software | healthy | fixtures/idor/negative/05-admin-via-decorator.ts:CustomersA… |
CustomersController |
software | healthy | fixtures/idor/positive/06-nestjs.ts:CustomersController |
User |
software | healthy | fixtures/real-shape/fastapi-saas/app/models.py:7 |
Item |
software | healthy | fixtures/real-shape/fastapi-saas/app/models.py:16 |
GitHubApiError |
software | healthy | src/integrations/github/github-api-error.ts:GitHubApiError |
FilePilotStore |
software | healthy | src/integrations/github/persistence/pilot-store.ts:FilePilo… |
AuthBypassDetector |
software | healthy | src/analysis-engine/detectors/auth-bypass.detector.ts:AuthB… |
CommandInjectionDetector |
software | healthy | src/analysis-engine/detectors/command-injection.detector.ts… |
EnvExposureDetector |
software | healthy | src/analysis-engine/detectors/env-exposure.detector.ts:EnvE… |
SqlInjectionDetector |
software | healthy | src/analysis-engine/detectors/sql-injection.detector.ts:Sql… |
AdminCheckDetector |
software | healthy | src/analysis-engine/detectors/admin-check.detector.ts:Admin… |
name |
software | healthy | src/analysis-engine/detectors/idor.detector.ts:name |
IdorDetector |
software | healthy | src/analysis-engine/detectors/idor.detector.ts:IdorDetector |
with |
software | healthy | src/analysis-engine/detectors/webhook-unverified.detector.t… |
WebhookUnverifiedDetector |
software | healthy | src/analysis-engine/detectors/webhook-unverified.detector.t… |
PathTraversalDetector |
software | healthy | src/analysis-engine/detectors/path-traversal.detector.ts:Pa… |
XssDetector |
software | healthy | src/analysis-engine/detectors/xss.detector.ts:XssDetector |
SecretsExposureDetector |
software | healthy | src/analysis-engine/detectors/secrets-exposure.detector.ts:… |
to |
software | healthy | src/test/test-webhook-unverified.ts:to |
that |
software | healthy | src/test/test-real-shape-reachability.ts:that |
the |
software | healthy | src/test/test-real-shape-reachability.ts:the |
this |
software | healthy | src/test/lib/production-scan.ts:this |
as |
software | healthy | src/cli/file-walker.ts:as |
names |
software | healthy | src/lib/anthropic-retry.ts:names |
from |
software | healthy | src/lib/llm-coverage.ts:from |
FixedWindowRateLimiter |
software | healthy | src/lib/rate-limiter.ts:FixedWindowRateLimiter |
| Label | Layer | Status | Path |
|---|---|---|---|
auth::fixtures/auth-bypass/positive/03-jwt-verify-swallowed… |
security | healthy | fixtures/auth-bypass/positive/03-jwt-verify-swallowed.ts |
auth::fixtures/auth-bypass/negative/04-jwt-verify-rethrows.… |
security | healthy | fixtures/auth-bypass/negative/04-jwt-verify-rethrows.js |
auth::README.md |
security | healthy | README.md |
auth::apps/dashboard/.env.example |
security | healthy | apps/dashboard/.env.example |
auth::fixtures/auth-bypass/positive/08-jwt-verify-false.py |
security | healthy | fixtures/auth-bypass/positive/08-jwt-verify-false.py |
auth::fixtures/idor/negative/06-role-check-in-handler.ts |
security | healthy | fixtures/idor/negative/06-role-check-in-handler.ts |
auth::landing/privacy.html |
security | healthy | landing/privacy.html |
auth::fixtures/idor/negative/05-admin-via-decorator.ts |
security | healthy | fixtures/idor/negative/05-admin-via-decorator.ts |
auth::fixtures/auth-bypass/negative/07-jwt-verify-false-tes… |
security | healthy | fixtures/auth-bypass/negative/07-jwt-verify-false-tests.py |
auth::landing/security.html |
security | healthy | landing/security.html |
auth::src/analysis-engine/detectors/secrets-exposure.detect… |
security | healthy | src/analysis-engine/detectors/secrets-exposure.detector.ts |
auth::landing/blog/llm-security-tools-leak-secrets/index.ht… |
security | healthy | landing/blog/llm-security-tools-leak-secrets/index.html |
auth::fixtures/secrets-exposure/negative/10-jwt-secret-from… |
security | healthy | fixtures/secrets-exposure/negative/10-jwt-secret-from-env.go |
auth::apps/dashboard/src/lib/github.ts |
security | healthy | apps/dashboard/src/lib/github.ts |
auth::fixtures/idor/positive/06-nestjs.ts |
security | healthy | fixtures/idor/positive/06-nestjs.ts |
auth::fixtures/admin-check/negative/04-jwt-claims-server-is… |
security | healthy | fixtures/admin-check/negative/04-jwt-claims-server-issued.ts |
auth::fixtures/secrets-exposure/positive/01-supabase-servic… |
security | healthy | fixtures/secrets-exposure/positive/01-supabase-service-role… |
auth::fixtures/idor/positive/01-nextjs-app-router.ts |
security | healthy | fixtures/idor/positive/01-nextjs-app-router.ts |
auth::scripts/secrets_scan.py |
security | healthy | scripts/secrets_scan.py |
auth::src/integrations/github/app-auth.service.ts |
security | healthy | src/integrations/github/app-auth.service.ts |
auth::fixtures/idor/negative/04-supabase-policy.ts |
security | healthy | fixtures/idor/negative/04-supabase-policy.ts |
auth::scripts/add-fixture-paths.mjs |
security | healthy | scripts/add-fixture-paths.mjs |
auth::src/analysis-engine/detectors/idor.detector.ts |
security | healthy | src/analysis-engine/detectors/idor.detector.ts |
auth::src/analysis-engine/detectors/auth-bypass.detector.ts |
security | healthy | src/analysis-engine/detectors/auth-bypass.detector.ts |
auth::fixtures/idor/positive/05-hono.ts |
security | healthy | fixtures/idor/positive/05-hono.ts |
auth::fixtures/secrets-exposure/positive/10-jwt-secret-cons… |
security | healthy | fixtures/secrets-exposure/positive/10-jwt-secret-const.go |
auth::src/analysis-engine/detectors/admin-check.detector.ts |
security | healthy | src/analysis-engine/detectors/admin-check.detector.ts |
| Label | Layer | Status | Path |
|---|---|---|---|
/page.tsx |
frontend | healthy | apps/dashboard/src/app/page.tsx |
/sign-up/[[...sign-up]] |
frontend | healthy | apps/dashboard/src/app/sign-up/[[...sign-up]]/page.tsx |
/sign-in/[[...sign-in]] |
frontend | healthy | apps/dashboard/src/app/sign-in/[[...sign-in]]/page.tsx |
/orgs/[id]/settings |
frontend | healthy | apps/dashboard/src/app/orgs/[id]/settings/page.tsx |
/orgs/[id]/scans |
frontend | healthy | apps/dashboard/src/app/orgs/[id]/scans/page.tsx |
/orgs/[id]/scans/[scanId] |
frontend | healthy | apps/dashboard/src/app/orgs/[id]/scans/[scanId]/page.tsx |
/orgs/[id]/billing |
frontend | healthy | apps/dashboard/src/app/orgs/[id]/billing/page.tsx |
/webhook/github |
frontend | healthy | fixtures/webhook-unverified/negative/05-github-octokit-webh… |
| Label | Layer | Status | Path |
|---|---|---|---|
postgres |
data | healthy | README.md |
redis |
data | healthy | package-lock.json |
mongodb |
data | healthy | package-lock.json |
mysql |
data | healthy | package-lock.json |
sqlite |
data | healthy | package-lock.json |
postgresql |
data | healthy | .env.example |
mariadb |
data | healthy | src/services/fix.service.ts |
| Label | Layer | Status | Path |
|---|---|---|---|
audit_log |
data | healthy | src/db/migrations/0001_tense_meltdown.sql |
org_settings |
data | healthy | src/db/migrations/0001_tense_meltdown.sql |
orgs |
data | healthy | src/db/migrations/0001_tense_meltdown.sql |
cost_ledger |
data | healthy | src/db/migrations/0000_salty_colonel_america.sql |
installations |
data | healthy | src/db/migrations/0000_salty_colonel_america.sql |
scan_runs |
data | healthy | src/db/migrations/0000_salty_colonel_america.sql |
api_tokens |
data | healthy | src/db/migrations/0002_boring_the_twelve.sql |
| Label | Layer | Status | Path |
|---|---|---|---|
0001_tense_meltdown.sql |
data | healthy | src/db/migrations/0001_tense_meltdown.sql |
0000_salty_colonel_america.sql |
data | healthy | src/db/migrations/0000_salty_colonel_america.sql |
0005_omniscient_wolf_cub.sql |
data | healthy | src/db/migrations/0005_omniscient_wolf_cub.sql |
0002_boring_the_twelve.sql |
data | healthy | src/db/migrations/0002_boring_the_twelve.sql |
0006_dizzy_rhodey.sql |
data | healthy | src/db/migrations/0006_dizzy_rhodey.sql |
0003_dusty_hulk.sql |
data | healthy | src/db/migrations/0003_dusty_hulk.sql |
0004_paddle_rename.sql |
data | healthy | src/db/migrations/0004_paddle_rename.sql |
| Label | Layer | Status | Path |
|---|---|---|---|
private_key::.env.example |
security | healthy | .env.example |
aws_access_key::fixtures/secrets-exposure/positive/06-aws-k… |
security | healthy | fixtures/secrets-exposure/positive/06-aws-keys-hardcoded.js |
aws_secret::fixtures/secrets-exposure/positive/06-aws-keys-… |
security | healthy | fixtures/secrets-exposure/positive/06-aws-keys-hardcoded.js |
private_key::fixtures/secrets-exposure/positive/03-firebase… |
security | healthy | fixtures/secrets-exposure/positive/03-firebase-admin-in-com… |
password_literal::fixtures/secrets-exposure/positive/08-pos… |
security | healthy | fixtures/secrets-exposure/positive/08-postgres-password-cli… |
password_literal::src/analysis-engine/detectors/secrets-exp… |
security | healthy | src/analysis-engine/detectors/secrets-exposure.detector.ts |
| Label | Layer | Status | Path |
|---|---|---|---|
CheckoutRedirect |
frontend | healthy | fixtures/secrets-exposure/negative/04-stripe-in-getserversi… |
AdminDashboard |
frontend | healthy | fixtures/secrets-exposure/positive/01-supabase-service-role… |
RootLayout |
frontend | healthy | apps/dashboard/src/app/layout.tsx |
SignUpPage |
frontend | healthy | apps/dashboard/src/app/sign-up/[[...sign-up]]/page.tsx |
SignInPage |
frontend | healthy | apps/dashboard/src/app/sign-in/[[...sign-in]]/page.tsx |
| Label | Layer | Status | Path |
|---|---|---|---|
gha::secrets |
cicd | healthy | .github/workflows/secrets.yml |
gha::ci |
cicd | healthy | .github/workflows/ci.yml |
gha::pages |
cicd | healthy | .github/workflows/pages.yml |
| Label | Layer | Status | Path |
|---|---|---|---|
secrets |
cicd | healthy | .github/workflows/secrets.yml |
build-and-test |
cicd | healthy | .github/workflows/ci.yml |
deploy |
cicd | healthy | .github/workflows/pages.yml |
| Label | Layer | Status | Path |
|---|---|---|---|
vps::aws |
hardware | healthy | .gitleaks.toml |
vps::azure |
hardware | healthy | src/services/sarif-output.service.ts |
| Label | Layer | Status | Path |
|---|---|---|---|
repobility-clone-regh75ds |
software | healthy | /tmp/repobility-clone-regh75ds |
| Label | Layer | Status | Path |
|---|---|---|---|
port:3000 |
network | healthy | Dockerfile |
| Label | Layer | Status | Path |
|---|---|---|---|
image::Dockerfile |
hardware | healthy | Dockerfile |
| Label | Layer | Status | Path |
|---|---|---|---|
GITHUB_TOKEN |
cicd | healthy | — |
This page is publicly accessible at:
https://repobility.com/scan/01bde0d6-b133-467f-9e4b-0e98b55e7156/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/01bde0d6-b133-467f-9e4b-0e98b55e7156/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.