Scan timing: clone 23.93s · analysis 12.82s · 36.1 MB · GitHub API rate-limit (preflight)
https://github.com/holaboss-ai/holaOS
· scanned 2026-05-31 01:26 UTC (5 days, 7 hours ago)
· 10 languages
915 findings (167 legacy + 748 scanner) 11/13 scanners ran 37th percentile · Typescript · large (100-500K LoC) Scanner says 67 (higher by 6)
Last scanned 5 days, 7 hours ago · v2 · last Δ +4.9 (diff) · 609 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
58.0 | 0.20 | 11.60 |
documentation_score |
65.0 | 0.15 | 9.75 |
practices_score |
70.0 | 0.15 | 10.50 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 72.8 |
Bug-class explainers. Each card groups findings of the same shape — these are the patterns most likely to ship to prod and reappear in future scans unless you systematically fix the cause, not just the instance.
runtime/api-server/src/runner-worker.ts:219
apps/desktop/src/lib/workspaceSelection.tsx:26
apps/desktop/src/lib/chat/useChatComposerModelSel…:197
apps/desktop/src/features/workspace-onboarding/pr…:30
apps/desktop/src/components/publish/usePublishDra…:97
apps/desktop/src/components/panes/ChatPane/index.…:5320
apps/desktop/src/components/layout/new-shell/useS…:97
apps/desktop/src/components/layout/SettingsScreen…:915
apps/desktop/src/components/layout/AppShell.tsx:1441
sdk/app-builder-sdk/src/runtime/state.ts:103
runtime/harnesses/src/embedded-skills/app-builder…:103
runtime/api-server/src/session-scratchpad.ts:147
runtime/api-server/src/app.ts:5557
runtime/api-server/src/app.ts:5532
runtime/api-server/src/app.ts:4818
This page is publicly accessible at:
https://repobility.com/scan/2bb252b3-baf7-4896-a58a-4c45dc20c51c/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/2bb252b3-baf7-4896-a58a-4c45dc20c51c/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.