Scan timing: clone 6.32s · analysis 34.11s · 24.0 MB · GitHub API rate-limit (preflight)
https://github.com/lyswhut/lx-music-desktop
· scanned 2026-06-05 11:34 UTC (5 days, 10 hours ago)
· 10 languages
1036 raw signals (160 security + 876 graph) 11th percentile · Typescript · medium (20-100K LoC) System graph score 82 (lower by 30)
Last scanned 5 days, 10 hours ago · v2 · 481 actionable findings from 2 signal sources. 117 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
43.4 | 0.25 | 10.85 |
testing_score |
0.0 | 0.20 | 0.00 |
documentation_score |
69.7 | 0.15 | 10.46 |
practices_score |
80.0 | 0.15 | 12.00 |
code_quality |
60.0 | 0.10 | 6.00 |
| Overall | 1.00 | 52.1 |
Showing 342 of 481 actionable findings. 598 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/renderer/utils/musicSdk/kg/songList.js:230, 294, 336, 359 (4 hits)src/renderer/utils/musicSdk/kg/temp/songList-new.js:233, 429, 451 (3 hits)src/renderer/utils/musicSdk/kg/musicInfo.js:15src/renderer/utils/musicSdk/kg/util.js:14package-lock.json
package-lock.json
.github/workflows/beta-pack.yml:49, 68, 76, 84, 92, 110, 141, 149, +11 more (38 hits).github/workflows/release.yml:49, 90, 138, 181 (8 hits).github/workflows/build-test.yml:14, 17 (3 hits).github/workflows/publish-version-info.yml:12 (2 hits)package.json:1 (4 hits)package-lock.json
src/renderer/worker/download/download.ts:323
src/renderer/utils/request.js:53
src/common/utils/renderer.ts:54src/main/utils/store.ts:17src/renderer/core/useApp/useInitUserApi.ts:42src/renderer/utils/musicSdk/kw/util.js:43
src/main/modules/sync/server/server/auth.ts:28
package-lock.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
.well-known/security.txt
package-lock.json
package-lock.json
package-lock.json
package-lock.json
.github/workflows/beta-pack.yml:97
Weak hash
.github/workflows/release.yml:78
Weak hash
src/renderer/components/common/SoundEffectBtn/PitchShifter.vue:50, 76 (2 hits)src/renderer/components/common/TogglePlayModeBtn.vue:87, 98 (2 hits)src/renderer/components/common/VolumeBtn.vue:45, 55 (2 hits)build-config/renderer-scripts/webpack.config.base.js:7build-config/renderer-scripts/webpack.config.dev.js:1build-config/renderer-scripts/webpack.config.prod.js:2build-config/renderer/webpack.config.base.js:13build-config/renderer/webpack.config.dev.js:9package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
llms.txt
humans.txt
robots.txt
sitemap.xml
build-config/lib-update.js:1src/renderer/utils/musicSdk/kg/temp/musicSearch-new.js:1src/renderer/utils/musicSdk/kg/temp/songList-new.js:1src/renderer/utils/musicSdk/kw/api-temp.js:1src/renderer/utils/musicSdk/mg/temp/leaderboard-old.js:1package.json
CI/CD securitySupply chainNpm
Showing first 300 of 342. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/1fee4853-1002-43b2-a00d-3f10f3af7890/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/1fee4853-1002-43b2-a00d-3f10f3af7890/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.