https://github.com/bluesky-social/social-app
· scanned 2026-06-05 23:28 UTC (4 days, 3 hours ago)
· 10 languages
826 raw signals (136 security + 690 graph) 11/13 scanners ran 48th percentile · Typescript · large (100-500K LoC) System graph score 46 (higher by 28)
Last scanned 4 days, 3 hours ago · v2 · 292 actionable findings from 2 signal sources. 189 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
25.0 | 0.20 | 5.00 |
documentation_score |
61.0 | 0.15 | 9.15 |
practices_score |
97.0 | 0.15 | 14.55 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 74.5 |
Showing 156 of 292 actionable findings. 481 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
dev-env/dev-infra/docker-compose.yaml:17 (2 hits)src/screens/Settings/components/ChangePasswordDialog.tsx:23
src/components/forms/InputGroup.tsx:28
modules/expo-bluesky-swiss-army/android/src/main/java/expo/modules/blueskyswissarmy/visibilityview/VisibilityViewManager.kt:52
bskylink/src/routes/createShortLink.ts:12
Dockerfile:7, 70, 100 (3 hits)Dockerfile.bskylink:1, 17 (2 hits)Dockerfile.bskyogcard:1, 22 (2 hits)Dockerfile.embedr:1, 64 (2 hits)package.json:1
src/components/Post/Embed/ExternalEmbed/ExternalPlayer.tsx:200
src/components/Post/Embed/ExternalEmbed/ExternalGif.tsx:57
dev-env/dev-infra/docker-compose.yaml
CI/CD securitycontainers
dev-env/dev-infra/docker-compose.yaml:17, 37 (3 hits)bskylink/tests/infra/docker-compose.yaml:17 (2 hits)Dockerfile.embedr:22
CI/CD securitycontainers
Dockerfile:43
CI/CD securitycontainers
.github/workflows/bundle-deploy-eas-update.yml:69
CI/CD securitySupply chainGitHub Actions
.github/workflows/bundle-deploy-eas-update.yml:69, 375 (2 hits).github/workflows/build-submit-android.yml:101.github/workflows/pull-request-commit.yml:131bskylink/src/metrics.ts:135src/Splash.tsx:175src/components/EmojiPicker/preload.web.ts:26.dockerignore
CI/CD securitycontainers
Dockerfile:38
CI/CD securitycontainers
Dockerfile.embedr:65
CI/CD securitycontainers
Dockerfile:100
CI/CD securitycontainers
Dockerfile.embedr:33
CI/CD securitycontainers
Dockerfile:52
CI/CD securitycontainers
index.html
.github/workflows/bundle-deploy-eas-update.yml:58, 90, 99, 173, 183, 191, 197, 320, +2 more (14 hits).github/workflows/build-submit-android.yml:44, 50, 131, 141, 177 (5 hits).github/workflows/pull-request-comment.yml:97, 144, 151, 184, 201 (5 hits).github/workflows/build-and-push-bskyweb-aws.yaml:28, 31, 39, 54 (4 hits).github/workflows/build-and-push-bskyweb-ghcr.yaml:29, 32, 40, 49 (4 hits).github/workflows/build-and-push-embedr-aws.yaml:28, 31, 39, 48 (4 hits).github/workflows/build-and-push-link-aws.yaml:28, 31, 39, 48 (4 hits).github/workflows/build-and-push-ogcard-aws.yaml:28, 31, 39, 48 (4 hits).github/workflows/build-and-push-bskyweb-aws.yaml.github/workflows/build-and-push-bskyweb-ghcr.yaml.github/workflows/build-and-push-embedr-aws.yaml.github/workflows/build-and-push-link-aws.yaml.github/workflows/build-and-push-ogcard-aws.yaml.github/workflows/claude.yml.github/workflows/nightly-update-source-languages.yamlDockerfile.embedr:71
CI/CD securitycontainers
Dockerfile:106
CI/CD securitycontainers
Dockerfile.embedr:71
CI/CD securitycontainers
Dockerfile:106
CI/CD securitycontainers
bskyembed/src/icons/Reply.tsx:3bskyembed/src/icons/Repost.tsx:3bskyogcard/src/types/bsky/index.ts:4bskyweb/cmd/embedr/server.go:43lingui.config.ts:14modules/expo-bluesky-swiss-army/android/src/main/java/expo/modules/blueskyswissarmy/sharedprefs/SharedPrefs.kt:46plugins/shareExtension/withExtensionInfoPlist.js:1plugins/shareExtension/withExtensionViewController.js:1llms.txt
humans.txt
sitemap.xml
Dockerfile:100
containersPinned dependencies
Dockerfile:7
containersPinned dependencies
Dockerfile:70
containersPinned dependencies
.github/workflows/bundle-deploy-eas-update.yml:51, 62, 140, 170, 177, 202, 285, 317, +3 more (19 hits).github/workflows/golang-test-lint.yml:18, 20, 36, 38 (8 hits).github/workflows/build-submit-android.yml:31, 38, 108, 118, 168, 187 (6 hits).github/workflows/pull-request-commit.yml:27, 34, 71, 113, 124 (5 hits).github/workflows/build-submit-ios.yml:31, 38, 66, 168 (4 hits).github/workflows/lint.yml:27, 55, 90, 93 (4 hits).github/workflows/pull-request-comment.yml:51, 81, 116, 123 (4 hits).github/workflows/verify-pnpm-lock.yml:15, 27 (4 hits)package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/249cc9eb-5ca4-4bb8-88aa-f2e4f2e3fed6/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/249cc9eb-5ca4-4bb8-88aa-f2e4f2e3fed6/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.