Scan timing: clone 16.54s · analysis 23.14s · 41.9 MB · GitHub API rate-limit (preflight)
https://github.com/coollabsio/coolify
· scanned 2026-06-05 10:01 UTC (5 days, 14 hours ago)
· 10 languages
375 raw signals (167 security + 208 graph) 11/13 scanners ran 100th percentile · Php · large (100-500K LoC) System graph score 76 (higher by 15)
Last scanned 5 days, 14 hours ago · v2 · 130 actionable findings from 2 signal sources. 138 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
90.0 | 0.20 | 18.00 |
documentation_score |
85.0 | 0.15 | 12.75 |
practices_score |
95.0 | 0.15 | 14.25 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 90.8 |
Showing 112 of 130 actionable findings. 268 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
app/Models/StandaloneMysql.php:302
app/Models/StandaloneMariadb.php:296
tests/Unit/DockerNetworkInjectionTest.php:10, 34 (2 hits)tests/Feature/CommandInjectionSecurityTest.php:958tests/Unit/FileStorageSecurityTest.php:48tests/Unit/PersistentVolumeSecurityTest.php:66tests/Unit/PostgresqlInitScriptSecurityTest.php:46tests/Unit/ProxyConfigurationSecurityTest.php:48tests/Unit/ValidationPatternsTest.php:101routes/web.php:259
routes/web.php:237
routes/web.php:156
routes/web.php:154
routes/web.php:158
routes/web.php:240
routes/web.php:147
routes/web.php:148
routes/web.php:202
routes/web.php:203
app/Actions/Server/InstallDocker.php:118
docker/production/Dockerfile:21, 54, 66, 71 (4 hits)docker/development/Dockerfile:17, 22 (2 hits)docker/coolify-helper/Dockerfile:20docker/coolify-realtime/Dockerfile:6docker/testing-host/Dockerfile:8resources/views/livewire/project/new/simple-dockerfile.blade.php:1
CI/CD securitycontainers
app/Livewire/Project/New/SimpleDockerfile.php:1
CI/CD securitycontainers
other/nightly/docker-compose.yml
CI/CD securitycontainers
docker-compose.yml
CI/CD securitycontainers
docker/coolify-helper/Dockerfile:35
CI/CD securitycontainers
docker/coolify-helper/Dockerfile:53, 63 (2 hits).github/workflows/coolify-staging-build.yml:55, 58, 65, 72, 104, 111, 130 (7 hits).github/workflows/coolify-helper-next.yml:37, 44, 56, 79, 86, 112 (6 hits).github/workflows/coolify-helper.yml:37, 44, 56, 78, 85, 111 (6 hits).github/workflows/coolify-production-build.yml:45, 52, 64, 85, 92, 118 (6 hits).github/workflows/coolify-realtime.yml:41, 48, 60, 83, 90, 116 (6 hits).github/workflows/coolify-testing-host.yml:37, 44, 51, 74, 81, 100 (6 hits).github/workflows/coolify-realtime-next.yml:41, 48, 60, 83, 90 (5 hits).github/workflows/chore-lock-closed-issues-discussions-and-prs.yml:17 (2 hits).github/workflows/chore-manage-stale-issues-and-prs.yml:16 (2 hits).github/workflows/claude.yml:28 (2 hits).github/workflows/coolify-helper-next.yml:32, 72 (2 hits).github/workflows/coolify-helper.yml:32, 71 (2 hits).github/workflows/coolify-production-build.yml:40, 78 (2 hits).github/workflows/coolify-realtime.yml:36, 76 (2 hits).github/workflows/coolify-staging-build.yml:43, 90 (2 hits).github/workflows/coolify-testing-host.yml:32, 67 (2 hits)routes/web.php:113
routes/web.php:114
routes/web.php:110
routes/web.php:115
routes/web.php:120
routes/web.php:121
routes/web.php:124
routes/web.php:122
routes/web.php:117
routes/web.php:118
routes/web.php:243
routes/web.php:106
routes/web.php:105
routes/web.php:244
routes/web.php:246
routes/web.php:247
routes/web.php:129
routes/web.php:130
routes/web.php:245
routes/web.php:240
CHANGELOG.md:4465
CI/CD securityagent runtimepermissions
templates/compose/posthog.yaml:39templates/compose/pterodactyl-with-wings.yaml:137templates/compose/zep.yaml:122other/nightly/docker-compose.yml
CI/CD securitycontainers
docker-compose.yml
CI/CD securitycontainers
docker/coolify-realtime/Dockerfile:7
CI/CD securitycontainers
docker/production/Dockerfile:60
CI/CD securitycontainers
index.html
.well-known/security.txt
RELEASE.md:48
README.md:25
public/robots.txt
.github/workflows/claude.yml.github/workflows/cleanup-ghcr-untagged.yml.github/workflows/coolify-helper-next.yml.github/workflows/coolify-helper.yml.github/workflows/coolify-production-build.yml.github/workflows/coolify-realtime-next.yml.github/workflows/coolify-realtime.yml.github/workflows/coolify-staging-build.ymlpublic/js/monaco-editor-0.52.2/min/vs/basic-languages/mysql/mysql.js:8
Weak hash
templates/compose/authentik.yaml
Ports
templates/compose/documenso.yaml
Ports
templates/compose/pi-hole.yaml
Ports
templates/compose/ente-photos-with-s3.yaml
Ports
templates/compose/ente-photos-with-s3.yaml
Ports
templates/compose/pi-hole.yaml
Ports
templates/compose/ente-photos-with-s3.yaml
Ports
templates/compose/librespeed.yaml
Ports
.dockerignore
CI/CD securitycontainers
resources/views/livewire/project/new/simple-dockerfile.blade.php:10
CI/CD securitycontainers
app/Livewire/Project/New/SimpleDockerfile.php:24
CI/CD securitycontainers
resources/views/livewire/project/new/simple-dockerfile.blade.php:1
CI/CD securitycontainers
app/Livewire/Project/New/SimpleDockerfile.php:1
CI/CD securitycontainers
app/Actions/Database/StartMysql.php:16, 24, 88, 106, 171 (5 hits)app/Actions/Database/StartMongodb.php:24, 95, 113, 209 (4 hits)app/Actions/Database/StartPostgresql.php:42, 81, 94, 178 (4 hits)app/Actions/Database/StartRedis.php:16, 92, 174 (3 hits)app/Actions/Database/StartKeydb.php:16, 92 (2 hits)app/Actions/Database/StartMariadb.php:16, 88 (2 hits)app/Actions/Database/StartDragonfly.php:91app/Events/ApplicationStatusChanged.php:10llms.txt
humans.txt
sitemap.xml
public/robots.txt
docker/coolify-helper/Dockerfile:20docker/development/Dockerfile:17docker/production/Dockerfile:66docker/production/Dockerfile:54
containersPinned dependencies
docker/coolify-realtime/Dockerfile:6
containersPinned dependencies
docker/production/Dockerfile:21, 71 (2 hits)docker/development/Dockerfile:22
This page is publicly accessible at:
https://repobility.com/scan/05cb3054-9b53-4504-add5-4fe348d8bd1b/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/05cb3054-9b53-4504-add5-4fe348d8bd1b/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.