CRIT
SEC039
[SEC039] Plaintext-equivalent password hash — unsalted single-pass digest: Single-pass di…
app/Http/Controllers/UserController.php:87
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
resources/js/angular/controllers/head.js:30
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
resources/js/vue/components/shared/Repo…:22
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
app/Providers/AppServiceProvider.php:24
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
app/Models/BuildFile.php:28
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
app/Http/Controllers/SubmissionControll…:102
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
app/Console/Commands/QueueSubmissions.p…:97
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/release.yml:35
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/release.yml:12
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/ci.yml:69
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/ci.yml:29
HIGH
MINED118
[MINED118] Dockerfile FROM `cdash-root-intermediate (no tag)` not pinned by digest: `FROM…
Dockerfile:247
HIGH
MINED118
[MINED118] Dockerfile FROM `cdash-root-intermediate (no tag)` not pinned by digest: `FROM…
Dockerfile:244
HIGH
MINED118
[MINED118] Dockerfile FROM `registry.access.redhat.com/ubi9/php-83 (no tag)` not pinned b…
Dockerfile:135
HIGH
MINED118
[MINED118] Dockerfile FROM `php:8.3-apache-trixie` not pinned by digest: `FROM php:8.3-ap…
Dockerfile:13
HIGH
JRN009
Secret-like setting is echoed into a password input value
resources/js/vue/components/ProfilePage…:102
HIGH
SEC013
[SEC013] Path Traversal — User Input in File Path: User-controlled input used in file pat…
app/Console/Commands/ValidateXml.php:43
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
routes/web.php:142
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
routes/web.php:138
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
routes/web.php:135
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
routes/web.php:123
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
routes/web.php:115
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
routes/web.php:107
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
routes/web.php:99
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
routes/web.php:92
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
routes/web.php:84
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
routes/web.php:76
MED
SEC041
[SEC041] Tabnabbing — target="_blank" without rel="noopener noreferrer": <a target="_blan…
resources/views/components/footer.blade…:18
MED
SEC041
[SEC041] Tabnabbing — target="_blank" without rel="noopener noreferrer": <a target="_blan…
resources/js/angular/controllers/overvi…:41
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
resources/js/angular/controllers/head.js:30
MED
SEC105
[SEC105] Cookie missing HttpOnly/Secure flag: Session cookie missing HttpOnly (allows JS …
config/session.php:168
MED
AUC001
[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks…
—
MED
DKR002
Compose service `website` image has no explicit tag
docker/docker-compose.yml:2
MED
DKR002
Dockerfile base image has no explicit tag
Dockerfile:136
MED
DKR001
Docker final stage has no non-root USER
Dockerfile:255
MED
WEB003
Public web service has no security.txt
.well-known/security.txt
MED
DKR014
Dockerfile copies broad context with incomplete .dockerignore
Dockerfile:210
MED
DKR014
Dockerfile copies broad context with incomplete .dockerignore
Dockerfile:124
MED
AUC002
[AUC002] Low visible authorization coverage in route inventory: Only 8.5% of discovered r…
—
MED
WEB015
Public web app has no Content Security Policy
index.html
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
graphql/schema.graphql:100
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
routes/api.php:44
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
routes/api.php:42
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
routes/api.php:40
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
routes/api.php:26
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
routes/api.php:24
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
routes/api.php:22
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
routes/api.php:18
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
routes/web.php:303
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
routes/web.php:302
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
routes/web.php:323
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
routes/web.php:322
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
routes/web.php:320
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
routes/web.php:318
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
routes/web.php:313
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
routes/web.php:305
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
routes/web.php:279
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
routes/web.php:264
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
routes/web.php:230
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
routes/web.php:185
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
resources/js/angular/controllers/overvi…:34
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/ProjectHan…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/OpenCoverT…:3
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/OpenCoverT…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/NoteHandle…:28
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/NoteHandle…:3
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/NoteHandle…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/JavaJSONTa…:34
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/JavaJSONTa…:3
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/JavaJSONTa…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/JSCoverTar…:37
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/JSCoverTar…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/GcovTarHan…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/DynamicAna…:47
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/DynamicAna…:3
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/DynamicAna…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/DoneHandle…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/CoverageLo…:71
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/CoverageLo…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/CoverageJU…:42
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/CoverageJU…:3
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/CoverageJU…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/CoverageHa…:3
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/CoverageHa…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/ConfigureH…:57
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/ConfigureH…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/BuildPrope…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/BuildHandl…:1
LOW
AIC003
Duplicated implementation block across source files
app/Http/Submission/Handlers/BazelJSONH…:1
LOW
AIC003
Duplicated implementation block across source files
app/GraphQL/Validators/UpdateProjectInp…:17
LOW
AIC003
Duplicated implementation block across source files
app/Console/Commands/SaveUser.php:9
LOW
AUC005
[AUC005] No authorization-focused tests detected: No test files with common authorization…
—
LOW
WEB005
robots.txt does not advertise a sitemap
public/robots.txt
LOW
DKR010
Dockerfile leaves apt package indexes in the image layer
Dockerfile:65
LOW
DKR010
Dockerfile leaves apt package indexes in the image layer
Dockerfile:18
LOW
WEB002
Public web app has no sitemap
sitemap.xml
LOW
DKR008
.dockerignore misses sensitive defaults
.dockerignore
LOW
DKR012
Dockerfile keeps pip download cache
Dockerfile:176
LOW
DKR011
Dockerfile installs recommended OS packages
Dockerfile:65
LOW
DKR011
Dockerfile installs recommended OS packages
Dockerfile:18
LOW
WEB008
Public docs site has no llms.txt
llms.txt
LOW
DKC010
Compose service lacks no-new-privileges hardening
docker/docker-compose.yml:2
LOW
DKC006
Compose service does not declare a runtime user
docker/docker-compose.yml:2
LOW
WEB011
Public web app has no humans.txt
humans.txt
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
resources/js/vue/components/shared/ApiL…:56
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
resources/js/vue/app.js:51
INFO
MINED098
[MINED098] Global Scope Pollution: Attaching libraries/objects directly to the global win…
resources/js/angular/directives/timelin…:259
INFO
MINED098
[MINED098] Global Scope Pollution: Attaching libraries/objects directly to the global win…
resources/js/angular/controllers/testOv…:98
INFO
MINED098
[MINED098] Global Scope Pollution: Attaching libraries/objects directly to the global win…
resources/js/angular/controllers/head.js:78
INFO
MINED055
[MINED055] Npm Install No Lockfile: Production image runs npm install (resolves new versi…
install.sh:59
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
app/Http/Submission/Handlers/CoverageHa…:13
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
app/Http/Submission/Handlers/BuildPrope…:13
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
app/Http/Submission/Handlers/AbstractXm…:13
INFO
MINED048
[MINED048] Php Error Suppress: @function() suppresses errors silently. Hides real issues.
app/Utils/DatabaseCleanupUtils.php:31
INFO
MINED048
[MINED048] Php Error Suppress: @function() suppresses errors silently. Hides real issues.
app/Http/Controllers/SubmissionControll…:80
INFO
MINED048
[MINED048] Php Error Suppress: @function() suppresses errors silently. Hides real issues.
app/GraphQL/Directives/FilterableDirect…:63