https://github.com/WeCr8-Solutions/shift-handover-hub
· scanned 2026-06-16 00:56 UTC (2 months, 1 week ago)
479 raw signals (77 security + 402 graph)
Last scanned 2 months, 1 week ago · v1 · 308 actionable findings from 2 signal sources. 354 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
Showing 160 of 308 actionable findings. 662 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
repo-level (31 hits)src/pages/Auth.tsx:198
src/pages/ResetPassword.tsx:75
.env
ConfigEnv fileRuntime env
repo-level (70 hits)repo-level (18 hits)repo-level (14 hits)repo-level (41 hits)repo-level (85 hits).mcp.json
VerificationMcp config
repo-level (59 hits).github/workflows/security-scan.yml:70, 82, 92, 104, 128, 204, 217 (7 hits).github/workflows/release.yml:30, 38, 46, 68, 78 (5 hits).github/workflows/zap-scan.yml:43, 66, 90, 112 (4 hits).github/workflows/codeql.yml:38, 47, 50 (3 hits).github/workflows/release.yml
CI/CD securitySupply chainGithub actions
supabase/functions/activate-station-context/index.ts:6
Cors wildcard
supabase/functions/ai-planning-assistant/index.ts:8
Cors wildcard
supabase/functions/apply-routing-change/index.ts:40
Cors wildcard
supabase/functions/auth-email-hook/index.ts:13
Cors wildcard
supabase/functions/billing-reminder-cron/index.ts:16
Cors wildcard
supabase/functions/concierge-accounting-export/index.ts:7
Cors wildcard
supabase/functions/create-cert-checkout/index.ts:12
Cors wildcard
supabase/functions/create-checkout/index.ts:6
Cors wildcard
supabase/functions/create-concierge-checkout/index.ts:7
Cors wildcard
supabase/functions/create-donation/index.ts:5
Cors wildcard
supabase/functions/customer-portal/index.ts:6
Cors wildcard
supabase/functions/erp-sync/index.ts:8
Cors wildcard
supabase/functions/extract-manual-pages/index.ts:4
Cors wildcard
supabase/functions/gca-progress-sync/index.ts:5
Cors wildcard
supabase/functions/issue-certificate/index.ts:19
Cors wildcard
supabase/functions/log-export/index.ts:64
Cors wildcard
supabase/functions/morning-brief-cron/index.ts:20
Cors wildcard
supabase/functions/oap-recert-reminder-cron/index.ts:15
Cors wildcard
supabase/functions/onboarding-bulk-import/index.ts:7
Cors wildcard
supabase/functions/parse-resume/index.ts:6
Cors wildcard
supabase/functions/process-notifications/index.ts:6
Cors wildcard
supabase/functions/relay-token/index.ts:23
Cors wildcard
supabase/functions/release-to-customer/index.ts:7
Cors wildcard
supabase/functions/report-issue/index.ts:5
Cors wildcard
supabase/functions/rls-health/index.ts:4
Cors wildcard
supabase/functions/sap-sync/index.ts:32
Cors wildcard
supabase/functions/seed-e2e/index.ts:8
Cors wildcard
supabase/functions/send-billing-reminder/index.ts:23
Cors wildcard
supabase/functions/send-concierge-receipt/index.ts:9
Cors wildcard
supabase/functions/send-email/index.ts:9
Cors wildcard
supabase/functions/send-policy-change-notification/index.ts:13
Cors wildcard
supabase/functions/social-agent/index.ts:2
Cors wildcard
supabase/functions/update-seats/index.ts:6
Cors wildcard
supabase/functions/verify-station-context-payment/index.ts:6
Cors wildcard
src/components/marketing/WhyJoblineFAQ.tsx:148
Dangerous innerhtml
src/components/ui/chart.tsx:70
Dangerous innerhtml
src/pages/resources/EssentialReading.tsx:103
Dangerous innerhtml
index.html:376
Direct innerhtml assignment
public/gcode-academy/index.html:3093
Direct innerhtml assignment
public/gcode-academy/src/gca-engine-v1.js:48
Direct innerhtml assignment
public/oap/index.html:2081
Direct innerhtml assignment
public/oap/src/oap-engine.js:125
Direct innerhtml assignment
public/status/index.html:498
Direct innerhtml assignment
public/gcode-academy/index.html:3660
Insert adjacent html
public/gcode-academy/src/gca-engine-v1.js:616
Insert adjacent html
scripts/generate-print-pdfs.mjs:11
Node child process
scripts/prerender.mjs:17
Node child process
scripts/run-demo-cert.mjs:1
Node child process
scripts/run-demo-dashboard-handoff.mjs:1
Node child process
scripts/run-demo-talent-profile.mjs:1
Node child process
scripts/write-release.mjs:1
Node child process
.github/workflows/test.yml:20, 23, 39, 51, 54, 72, 75, 97, +1 more (9 hits).github/workflows/security-scan.yml:31, 34, 55, 67, 112, 124, 135 (7 hits).github/workflows/zap-scan.yml:38, 55, 85, 102, 129 (5 hits).github/workflows/release.yml:17, 20, 59, 62 (4 hits).github/workflows/codeql.yml:35index.html:247
Document write
public/oap/index.html:1974
Document write
public/oap/src/oap-cert.js:195
Document write
src/components/admin/printables/printableSheets.ts:464
Document write
src/lib/auditHistoryExport.ts:190
Document write
src/lib/workOrderExport.ts:500
Document write
src/pages/ToolProficiency.tsx:237
Document write
desktop/package.json
LockfileReproducibilityGenerated repo pattern
This page is publicly accessible at:
https://repobility.com/scan/0fc40876-2d58-41e8-b23c-be9bf36cb4b8/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/0fc40876-2d58-41e8-b23c-be9bf36cb4b8/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.