Scan timing: clone 24.26s · analysis 3.23s · 28.5 MB · GitHub API rate-limit (preflight)
https://github.com/remorses/holocron
· scanned 2026-06-05 21:32 UTC (4 days, 11 hours ago)
· 10 languages
368 raw signals (48 security + 320 graph) 11/13 scanners ran 77th percentile · Typescript · medium (20-100K LoC) System graph score 75 (higher by 6)
Last scanned 4 days, 11 hours ago · v2 · 186 actionable findings from 2 signal sources. 22 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
70.0 | 0.15 | 10.50 |
practices_score |
67.0 | 0.15 | 10.05 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 80.5 |
Showing 118 of 186 actionable findings. 208 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/ci.yml:14, 22 (2 hits).github/workflows/ci.yml:18
CI/CD securitySupply chainGitHub Actions
og-worker/worker-configuration.d.ts:3044
Exec used
website/worker-configuration.d.ts:3080
Exec used
vite/src/components/config-panel-inner.tsx:34
.well-known/security.txt
vite/src/app-factory.tsx:725
Dangerous innerhtml
vite/src/components/icon.tsx:45
Dangerous innerhtml
vite/src/components/markdown/code-block.tsx:180
Dangerous innerhtml
vite/src/components/markdown/mermaid.tsx:97
Dangerous innerhtml
website/src/deploy-email.tsx:52
Dangerous innerhtml
integration-tests/scripts/test-e2e-start.ts:7vite/src/components/markdown/code-card.tsx:4vite/src/components/markdown/tabs.tsx:5vite/src/components/nav-drawer.tsx:102website/src/db.ts:19website/src/lib/memoize.ts:5humans.txt
This page is publicly accessible at:
https://repobility.com/scan/0db3f4e2-f899-4f69-a8bd-7fdf1e9b1bf5/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/0db3f4e2-f899-4f69-a8bd-7fdf1e9b1bf5/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.