Scan timing: clone 25.99s · analysis 32.27s · 111.1 MB · GitHub API rate-limit (preflight)
https://github.com/dotnet/sdk
· scanned 2026-06-05 22:51 UTC (4 days, 5 hours ago)
· 10 languages
226 raw signals (68 security + 158 graph) 11/13 scanners ran 67th percentile · Csharp · huge (>500K LoC)
Last scanned 4 days, 5 hours ago · v2 · 92 actionable findings from 2 signal sources. 55 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
66.0 | 0.15 | 9.90 |
practices_score |
77.0 | 0.15 | 11.55 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 81.2 |
Showing 72 of 92 actionable findings. 147 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
documentation/manpages/tool/Dockerfile:1
src/Cli/dotnet/NugetPackageDownloader/WorkloadUnixFilePermissionsFileList.cs:31
documentation/manpages/tool/remove-metadata-and-embed-includes.py:39
.github/workflows/backport.yml:20.github/workflows/inter-branch-merge-flow.yml:14.github/workflows/update-static-web-assets-baselines.yml:27, 72, 161, 179, 201, 210, 312, 330, +2 more (20 hits).github/workflows/copilot-setup-steps.yml:39, 47 (4 hits).github/workflows/remove-lockdown-label.yml:23, 55 (4 hits).github/workflows/add-lockdown-label.yml:28 (2 hits).github/workflows/update-man-pages.yml:17 (2 hits).github/workflows/stale.yml:42.github/workflows/inter-branch-merge-flow.yml:14
CI/CD securitySupply chainGithub actions
.github/workflows/backport.yml:20
CI/CD securitySupply chainGithub actions
src/Cli/dotnet/Commands/New/PostActions/DotnetAddPostActionProcessor.cs:98src/Cli/dotnet/Commands/Package/PackageCommandParser.cs:78src/Cli/dotnet/Commands/Workload/GlobalJsonWorkloadSetFile.cs:46.dockerignore
CI/CD securitycontainers
documentation/manpages/tool/Dockerfile:1
CI/CD securitycontainers
index.html
eng/pipelines/search-cache-pipeline.yml:117
.github/workflows/backport.yml.github/workflows/fix-completions-on-comment.yml.github/workflows/inter-branch-merge-flow.yml.github/workflows/update-man-pages.yml.github/workflows/update-static-web-assets-baselines.yml.github/workflows/update-xlf-on-comment.yml.github/workflows/update-man-pages.yml
Ports
documentation/manpages/tool/Dockerfile:5
CI/CD securitycontainers
src/Cli/Microsoft.DotNet.Cli.Definitions/Commands/New/NewSearchCommandDefinition.cs:24src/Cli/Microsoft.TemplateEngine.Cli/Commands/CommandLineUtils.cs:11src/Cli/Microsoft.TemplateEngine.Cli/Commands/SymbolStrings.Designer.cs:18src/Cli/dotnet/CommandFactory/CommandResolution/PublishPathCommandSpecFactory.cs:46build:1
llms.txt
humans.txt
sitemap.xml
documentation/manpages/tool/Dockerfile:1
containersPinned dependencies
documentation/manpages/tool/man-pandoc-filter.py:29
documentation/manpages/tool/man-pandoc-filter.py:11
documentation/manpages/tool/man-pandoc-filter.py:39
documentation/manpages/tool/man-pandoc-filter.py:15
documentation/manpages/tool/man-pandoc-filter.py:53
This page is publicly accessible at:
https://repobility.com/scan/1776470e-4bc5-4eec-a374-966bb4e999a3/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/1776470e-4bc5-4eec-a374-966bb4e999a3/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.