Scan timing: clone 4.64s · analysis 49.15s · 13.1 MB · GitHub API rate-limit (preflight)
https://github.com/Sage/carbon
· scanned 2026-06-05 12:51 UTC (5 days, 9 hours ago)
· 10 languages
360 raw signals (126 security + 234 graph) 52nd percentile · Typescript · large (100-500K LoC)
Last scanned 5 days, 9 hours ago · v2 · 156 actionable findings from 2 signal sources. 87 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
68.9 | 0.25 | 17.23 |
testing_score |
71.0 | 0.20 | 14.20 |
documentation_score |
83.7 | 0.15 | 12.55 |
practices_score |
84.0 | 0.15 | 12.60 |
code_quality |
59.5 | 0.10 | 5.95 |
| Overall | 1.00 | 75.3 |
Showing 104 of 156 actionable findings. 243 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.env
.env
.github/workflows/pr.yml:23
CI/CD securityworkflow secretsGitHub Actions
.github/workflows/playwright.yml:22, 23, 30, 50, 62, 63, 75, 85 (12 hits).github/workflows/semantic-commit-lint.yml:12, 16 (4 hits).github/workflows/semantic-release.yml:19, 23, 54, 58 (4 hits).github/workflows/chromatic-push.yml:17, 20 (2 hits).github/workflows/chromatic.yml:39, 43 (2 hits).github/workflows/ci.yml:58, 104 (2 hits).github/workflows/codeql-analysis.yml:19 (2 hits).github/workflows/codeql-analysis.yml:23, 29, 32 (6 hits).github/workflows/semantic-release.yml:31, 68 (3 hits).github/workflows/chromatic.yml:17 (2 hits).github/workflows/playwright.yml:15
package.json (2 hits)package.json
package.json
package.json
package.json
package.json
package.json
index.html
.well-known/security.txt
src/components/adaptive-sidebar/adaptive-sidebar.stories.tsx:551
src/components/action-popover/action-popover.stories.tsx:41, 201 (2 hits)src/components/adaptive-sidebar/adaptive-sidebar-test.stories.tsx:105, 468 (2 hits)src/components/box/components.test-pw.tsx:5, 29 (2 hits)src/components/card/components.test-pw.tsx:111, 113 (2 hits).storybook/welcome-page/header/header.component.jsx:25src/__internal__/legacy-input/input.component.tsx:44src/components/action-popover/action-popover-test.stories.tsx:816src/components/adaptive-sidebar/adaptive-sidebar.stories.tsx:48package.json
package.json
package.json
package.json (4 hits)package.json
package.json
package.json
package.json (4 hits)llms.txt
humans.txt
robots.txt
sitemap.xml
package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/1d2b0c80-c5e1-48d3-bc2a-65a7c3970515/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/1d2b0c80-c5e1-48d3-bc2a-65a7c3970515/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.