Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

superset-sh/superset

https://github.com/superset-sh/superset · scanned 2026-05-14 22:55 UTC (3 weeks ago) · 10 languages

577 findings (45 legacy + 532 scanner) 6th percentile · Typescript · large (100-500K LoC) Scanner says 63 (lower by 4)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 3 weeks ago · v1 · 41 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.

JSON
Score breakdown â 2026-05-17-v4 calibration-aware
Component Sub-score Weight Contribution
structure_score 60.0 0.15 9.00
security_score 58.4 0.25 14.60
testing_score 30.0 0.20 6.00
documentation_score 90.0 0.15 13.50
practices_score 65.0 0.15 9.75
code_quality 60.0 0.10 6.00
Overall 1.00 58.9
Calibrated penalty buckets (security_score): authz: 12.7 · docker: 4.0 · journey: 33.8
Severity distribution — click a segment to filter
Active filters: excluding tests × Reset all
12 healthy 18 warning
GET /health
warning
endpoint 5 gaps risk 0.45
ALL /hosts/:hostId/trpc/*
warning
endpoint 5 gaps risk 0.05
auth
DELETE /terminal/sessions/:terminalId
warning
endpoint 5 gaps risk 0.05
auth
GET /hosts/:hostId/*
warning
endpoint 5 gaps risk 0.05
auth
GET /hosts/:hostId/_whoowns
warning
endpoint 5 gaps risk 0.05
auth
GET /remote-control/:sessionId
warning
endpoint 1 gap risk 0.05
auth
GET /terminal/:terminalId
warning
endpoint 5 gaps risk 0.05
auth
GET /terminal/resource-sessions
warning
endpoint 5 gaps risk 0.05
auth
GET /terminal/sessions
warning
endpoint 5 gaps risk 0.05
auth
GET /tunnel
warning
endpoint 5 gaps risk 0.05
auth
POST /terminal/sessions
warning
endpoint 5 gaps risk 0.05
auth
USE /events
warning
endpoint 3 gaps risk 0.05
auth
USE /hosts/:hostId/*
warning
endpoint 5 gaps risk 0.05
auth
USE /terminal/*
warning
endpoint 3 gaps risk 0.05
auth
USE /trpc/*
warning
endpoint 3 gaps risk 0.05
auth
GET /auth/callback
warning
endpoint 2 gaps
auth
GET /events
warning
endpoint 1 gap
auth
GET /hook/complete
warning
endpoint 2 gaps
auth

Showing first 18 of 30 flows. The full set is available via the Findings tab — filter by tags=flow-* for flow-tagged gaps.

For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/2e0fa7f3-3230-4398-84eb-683fa0568119/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/2e0fa7f3-3230-4398-84eb-683fa0568119/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.