https://github.com/u-root/u-root
· scanned 2026-06-05 17:20 UTC (4 days, 21 hours ago)
· 10 languages
219 raw signals (67 security + 152 graph) 11/13 scanners ran 88th percentile · Go · medium (20-100K LoC) System graph score 61 (higher by 20)
Last scanned 4 days, 21 hours ago · v2 · 71 actionable findings from 2 signal sources. 72 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
61.0 | 0.15 | 9.15 |
practices_score |
72.0 | 0.15 | 10.80 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 81.7 |
Showing 50 of 71 actionable findings. 143 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
cmds/exp/ssh/utils_plan9.go:54
.github/workflows/tinygo.yml:17
cmds/core/mount9p/mount9p.go:41
.github/workflows/codeql-analysis.yml:32, 46, 59 (6 hits).github/workflows/test-images.yml:55, 58, 66, 71 (4 hits).github/workflows/golangci-lint.yml:25 (2 hits).github/workflows/homepage.yml:20 (2 hits).github/workflows/tests.yml:69.github/workflows/go.yml:15, 17, 39, 42, 59, 62, 87, 90 (12 hits).github/workflows/tests.yml:49, 51 (3 hits).github/workflows/cifuzz.yml:23 (2 hits).github/workflows/codeql-analysis.yml:28 (2 hits).github/workflows/golangci-lint.yml:19, 20 (2 hits).github/workflows/homepage.yml:12, 13 (2 hits).github/workflows/test-images.yml:52 (2 hits).github/workflows/cifuzz.yml:9, 15 (2 hits).github/workflows/cifuzz.yml:9, 15 (2 hits)pkg/forth/forth.go:207
Eval used
pkg/boot/fit/vfit.go:35
Weak hash
pkg/netcat/const.go:26
Weak hash
pkg/tss/tss.go:80
Weak hash
pkg/txtlog/pcr_event.go:195
Weak hash
cmds/core/base64/base64.go:81cmds/core/cat/cat.go:28cmds/core/id/id.go:114cmds/core/kill/list_openbsd.go:1, 28, 95 (3 hits)cmds/core/kill/list_netbsd.go:1, 94 (2 hits)cmds/core/gosh/completer_liner.go:78cmds/core/init/init_plan9.go:1cmds/core/kill/list_freebsd.go:1cmds/core/kill/list_linux.go:1cmds/core/ls/ls_windows.go:1cmds/core/mknod/mknod_linux.go:1tools/golang_patched_dce/Dockerfile:1
containersPinned dependencies
.circleci/images/ovmf-amd64/Dockerfile:4.circleci/images/ovmf-arm64/Dockerfile:4.circleci/images/test-image-tamago/Dockerfile:1.circleci/images/kernel-amd64/Dockerfile:4.circleci/images/kernel-arm/Dockerfile:4.circleci/images/kernel-arm64/Dockerfile:4.circleci/images/multiboot-test-kernel-amd64/Dockerfile:4.circleci/images/uefipayload-amd64/Dockerfile:4.circleci/images/upl-fit-amd64/Dockerfile:4.circleci/images/upl-fit-arm64/Dockerfile:4
This page is publicly accessible at:
https://repobility.com/scan/2fcec4ea-77dc-4b3f-ba33-9dc1ecd00739/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/2fcec4ea-77dc-4b3f-ba33-9dc1ecd00739/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.