Scan timing: clone 8.2s · analysis 25.96s · 47.5 MB · GitHub API rate-limit (preflight)
https://github.com/git/git
· scanned 2026-06-05 09:29 UTC (5 days, 17 hours ago)
· 10 languages
437 raw signals (127 security + 310 graph) 11/13 scanners ran 38th percentile · C · large (100-500K LoC)
Last scanned 5 days, 17 hours ago · v2 · 165 actionable findings from 2 signal sources. 115 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
15.0 | 0.20 | 3.00 |
documentation_score |
45.0 | 0.15 | 6.75 |
practices_score |
77.0 | 0.15 | 11.55 |
code_quality |
54.0 | 0.10 | 5.40 |
| Overall | 1.00 | 64.5 |
Showing 138 of 165 actionable findings. 280 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
t/t0302-credential-store.sh:48t/t5564-http-proxy.sh:28t/unit-tests/u-urlmatch-normalization.c:207t/lib-git-p4.sh:196
t/lib-gitweb.sh:8
t/t5580-unc-paths.sh:11
compat/vcbuild/scripts/lib.pl:26
compat/vcbuild/scripts/clink.pl:133
compat/vcbuild/scripts/clink.pl:133compat/vcbuild/scripts/lib.pl:26t/helper/test-drop-caches.c:126t/t4053-diff-no-index.sh:199
git-p4.py:1501, 1529, 1530, 1531, 1540, 1542, 1643, 1649, +13 more (25 hits).github/workflows/main.yml:380, 383, 386, 391, 393, 395, 398, 401, +6 more (14 hits)t/unit-tests/clar/.github/workflows/ci.yml:25.github/workflows/main.yml:66, 115, 126, 143, 160, 176, 179, 211, +7 more (23 hits).github/workflows/coverity.yml:41, 101, 144 (5 hits)t/unit-tests/clar/.github/workflows/ci.yml:56 (2 hits).github/workflows/check-style.yml:23.github/workflows/check-whitespace.yml:22.github/workflows/l10n.yml:66.github/workflows/main.yml:116, 150, 177, 184, 189, 227 (8 hits).github/workflows/coverity.yml:44 (2 hits).github/workflows/l10n.yml:95 (2 hits)git-p4.py:1840
Tls verify false
git-p4.py:318
t/lib-git-p4.sh:196
t/t1460-refs-migrate.sh:32
git-p4.py:273, 311, 2683, 3118, 3181 (5 hits)git-p4.py:2294
Subprocess shell true
git-merge-octopus.sh:54
Weak hash
src/hash.rs:213
Weak hash
src/loose.rs:697
Weak hash
t/t0040-parse-options.sh:186
Weak hash
t/t0600-reffiles-backend.sh:316
Weak hash
t/t0612-reftable-jgit-compatibility.sh:22
Weak hash
t/t1050-large.sh:188
Weak hash
t/t1400-update-ref.sh:261
Weak hash
t/t1405-main-ref-store.sh:59
Weak hash
t/t1406-submodule-ref-store.sh:54
Weak hash
t/t1407-worktree-ref-store.sh:23
Weak hash
t/t1512-rev-parse-disambiguation.sh:110
Weak hash
t/t1901-repo-structure.sh:76
Weak hash
t/t2400-worktree-add.sh:253
Weak hash
t/t3304-notes-mixed.sh:129
Weak hash
t/t5300-pack-object.sh:589
Weak hash
t/t5310-pack-bitmaps.sh:223
Weak hash
t/t5319-multi-pack-index.sh:57
Weak hash
t/t5516-fetch-push.sh:1307
Weak hash
t/t5550-http-fetch-dumb.sh:90
Weak hash
t/t7400-submodule-basic.sh:479
Weak hash
t/t4150-am.sh
Ports
t/t3310-notes-merge-manual-resolve.sh
Ports
t/t1300-config.sh
Ports
t/t6120-describe.sh
Ports
t/t8008-blame-formats.sh
Ports
t/t3404-rebase-interactive.sh
Ports
t/t3206-range-diff.sh
Ports
t/t3301-notes.sh
Ports
t/t1400-update-ref.sh
Ports
t/t3301-notes.sh
Ports
t/t8007-cat-file-textconv.sh
Ports
t/t1400-update-ref.sh
Ports
t/t3301-notes.sh
Ports
t/t3311-notes-merge-fanout.sh
Ports
t/t3311-notes-merge-fanout.sh
Ports
t/t3301-notes.sh
Ports
t/t6404-recursive-merge.sh
Ports
t/t3309-notes-merge-auto-resolve.sh
Ports
t/t7501-commit-basic-functionality.sh
Ports
t/t1400-update-ref.sh
Ports
t/t1400-update-ref.sh
Ports
t/t1400-update-ref.sh
Ports
t/t1400-update-ref.sh
Ports
t/t3309-notes-merge-auto-resolve.sh
Ports
t/t9300-fast-import.sh
Ports
t/t3309-notes-merge-auto-resolve.sh
Ports
t/t1400-update-ref.sh
Ports
t/t5515-fetch-merge-logic.sh
Ports
t/t1400-update-ref.sh
Ports
t/t1400-update-ref.sh
Ports
t/t1400-update-ref.sh
Ports
t/t1400-update-ref.sh
Ports
t/t1400-update-ref.sh
Ports
t/t1300-config.sh
Ports
t/t4002-diff-basic.sh
Ports
t/t4002-diff-basic.sh
Ports
t/t3309-notes-merge-auto-resolve.sh
Ports
t/t3309-notes-merge-auto-resolve.sh
Ports
t/t4002-diff-basic.sh
Ports
t/t9604-cvsimport-timestamps.sh
Ports
t/t4002-diff-basic.sh
Ports
t/t3310-notes-merge-manual-resolve.sh
Ports
t/t3309-notes-merge-auto-resolve.sh
Ports
t/t3206-range-diff.sh
Ports
t/t4002-diff-basic.sh
Ports
t/t4002-diff-basic.sh
Ports
t/t3206-range-diff.sh
Ports
t/t0000-basic.sh
Ports
t/t4002-diff-basic.sh (2 hits)t/t4002-diff-basic.sh
Ports
t/t3206-range-diff.sh
Ports
t/t4002-diff-basic.sh
Ports
t/t5515-fetch-merge-logic.sh
Ports
t/t3310-notes-merge-manual-resolve.sh
Ports
t/t4002-diff-basic.sh
Ports
t/t5319-multi-pack-index.sh
Ports
t/t3308-notes-merge.sh
Ports
t/t3309-notes-merge-auto-resolve.sh
Ports
compat/regex/regex.h:3, 4 (2 hits)builtin/ls-tree.c:11builtin/show-ref.c:194compat/obstack.h:3compat/regex/regex_internal.h:2compat/simple-ipc/ipc-win32.c:127kwset.h:2repo-level (8 hits)repo-level (2 hits)git-p4.py:2894
git-p4.py:4030
git-p4.py:3115
git-p4.py:1673
git-p4.py:4538
git-p4.py:3326
This page is publicly accessible at:
https://repobility.com/scan/1c561cf2-5600-4ddc-8e44-4c536211ab9a/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/1c561cf2-5600-4ddc-8e44-4c536211ab9a/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.