Scan timing: clone 2.84s · analysis 36.27s · 10.9 MB · GitHub API rate-limit (preflight)
https://github.com/k0rdent/kof
· scanned 2026-06-05 14:58 UTC (5 days, 2 hours ago)
· 10 languages
444 raw signals (158 security + 286 graph) 20th percentile · Typescript · medium (20-100K LoC) System graph score 79 (lower by 21)
Last scanned 5 days, 2 hours ago · v2 · 130 actionable findings from 2 signal sources. 171 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
52.2 | 0.25 | 13.05 |
testing_score |
70.0 | 0.20 | 14.00 |
documentation_score |
57.0 | 0.15 | 8.55 |
practices_score |
75.0 | 0.15 | 11.25 |
code_quality |
51.2 | 0.10 | 5.12 |
| Overall | 1.00 | 58.0 |
Showing 102 of 130 actionable findings. 301 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/pr_test_adopted_upgrade.yml:72, 73 (2 hits).github/workflows/pr_test_cross_namespace.yaml:49, 50 (2 hits).github/workflows/pr_test_helm_chart.yml:100, 101 (2 hits).github/workflows/pr_test_kcm_region_with_kof.yaml:53, 54 (2 hits).github/workflows/pr_test_kof_installation.yaml:53, 54 (2 hits).github/workflows/pr_test_mgmt_upgrade.yml:48, 49 (2 hits).github/workflows/pr_test_tenant_isolation_test.yaml:49, 50 (2 hits).github/actions/kind-config-patch/action.yaml:30
kof-operator/internal/s3/s3client.go:74
scripts/support-bundle-analyzer.py:65, 66, 88, 89, 95 (5 hits)scripts/victoria-migration/migration.py:302, 308 (2 hits)docker/opentelemetry-collector-contrib/Dockerfile:1, 2 (2 hits).github/workflows/pr_test_adopted_upgrade.yml:27.github/workflows/pr_test_cross_namespace.yaml:37.github/workflows/pr_test_helm_chart.yml:88kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
.pre-commit-config.yaml:17
kof-operator/go.mod
kof-operator/go.mod
kof-operator/go.mod
.github/workflows/pr_test_mgmt_upgrade.yml:27, 33 (2 hits).github/workflows/pr_test_adopted_upgrade.yml:27.github/workflows/pr_test_cross_namespace.yaml:37.github/workflows/pr_test_helm_chart.yml:88.github/workflows/pr_test_kcm_region_with_kof.yaml:41.github/workflows/pr_test_kof_installation.yaml:41.github/workflows/pr_test_tenant_isolation_test.yaml:37kof-operator/webapp/collector/package-lock.json
scripts/support-bundle-analyzer.py:18, 133, 278, 420, 433, 573, 857 (7 hits)scripts/check_values_consistency.py:96, 145, 184 (3 hits).agents/skills/troubleshoot/scripts/analyze_bundle.py:41scripts/victoria-migration/migration.py:415.dockerignore
CI/CD securitycontainers
docker/opentelemetry-collector-contrib/Dockerfile:3
CI/CD securitycontainers
kof-operator/webapp/collector/package-lock.json
kof-operator/go.mod
kof-operator/webapp/collector/package.json
kof-operator/webapp/collector/package.json
kof-operator/webapp/collector/package.json
kof-operator/webapp/collector/package.json
kof-operator/webapp/collector/package.json
kof-operator/webapp/collector/package.json
kof-operator/webapp/collector/package.json
scripts/requirements.txt:1, 2, 3, 4 (4 hits)kof-operator/webapp/collector/package-lock.json
docker/opentelemetry-collector-contrib/Dockerfile:2
containersPinned dependencies
repo-level (8 hits).github/workflows/release_images.yml:45, 47, 58 (4 hits).github/workflows/test_builds.yml:64, 82, 242, 282 (4 hits).github/workflows/build_images.yml:44, 46, 57 (3 hits).github/workflows/build_charts.yml:25, 48 (2 hits).github/workflows/helm-docs.yaml:12, 18 (2 hits).github/workflows/pr_conventional_commit.yaml:12 (2 hits).github/workflows/release_charts.yml:28, 81 (2 hits).github/workflows/build_charts.yml.github/workflows/build_images.yml.github/workflows/release_charts.yml.github/workflows/release_images.yml.github/workflows/test_builds.ymlkof-operator/internal/telemetry/telemetry.go:79
kof-operator/internal/audit/manifest.go:70
kof-operator/webapp/collector/src/components/pages/victoriaPage/victoria-details/VictoriaOverviewTab.tsx:74, 186, 229 (3 hits)kof-operator/api/v1beta1/vmstorageconnection_types.go:1, 3 (2 hits)kof-operator/internal/controller/promxyservergroup_controller.go:1, 4 (2 hits)kof-operator/api/v1beta1/promxyservergroup_types.go:1kof-operator/api/v1beta1/zz_generated.deepcopy.go:1kof-operator/internal/acl/handlers/jaeger_trace_handler.go:54kof-operator/internal/acl/handlers/prometheus_rules_handler.go:52kof-operator/internal/coldstorage/exporter.go:46kof-operator/webapp/collector/package.json
docker/opentelemetry-collector-contrib/Dockerfile:1
containersPinned dependencies
.github/workflows/pr_test_helm_chart.yml:24, 29, 42, 61, 77, 82 (12 hits).github/workflows/pr_test_cross_namespace.yaml:27, 31, 88, 141, 166 (8 hits).github/workflows/triage.yaml:16, 29, 46, 63 (8 hits).github/workflows/pr_test_adopted_upgrade.yml:53, 57, 173, 248, 271, 322 (7 hits).github/workflows/pr_test_mgmt_upgrade.yml:23, 39, 106, 143, 163 (5 hits).github/workflows/pr_check_values_consistency.yml:20, 23 (4 hits).github/workflows/pr_test_kcm_region_with_kof.yaml:31, 35, 97, 182 (4 hits).github/workflows/pr_test_kof_installation.yaml:31, 35, 97, 206 (4 hits)repo-level (2 hits)scripts/support-bundle-analyzer.py:911
scripts/victoria-migration/migration.py:26
scripts/victoria-migration/migration.py:157
scripts/victoria-migration/migration.py:351
This page is publicly accessible at:
https://repobility.com/scan/3b1b00cf-5230-4db8-82a0-a709fa6bec87/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/3b1b00cf-5230-4db8-82a0-a709fa6bec87/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.