https://github.com/charlesvestal/schwung
· scanned 2026-06-05 20:40 UTC (4 days, 12 hours ago)
· 10 languages
153 raw signals (69 security + 84 graph) 11/13 scanners ran 62nd percentile · C · large (100-500K LoC) System graph score 84 (lower by 16)
Last scanned 4 days, 12 hours ago · v2 · 72 actionable findings from 2 signal sources. 39 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
31.0 | 0.20 | 6.20 |
documentation_score |
70.0 | 0.15 | 10.50 |
practices_score |
75.0 | 0.15 | 11.25 |
code_quality |
46.0 | 0.10 | 4.60 |
| Overall | 1.00 | 67.3 |
Showing 50 of 72 actionable findings. 111 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
scripts/uninstall.sh:124
src/shared/filepath_browser.mjs:175
Dockerfile:3
.github/workflows/release.yml:16, 26 (3 hits)libs/quickjs/quickjs-2025-04-26/repl.js:586
Eval used
src/shared/parse_move_manual.mjs:303
src/modules/overtake/rnbo-runner/ui.js:128
src/shared/parse_move_manual.mjs:211
scripts/analyze_wavs.py:197
Error handlingquality
.dockerignore
CI/CD securitycontainers
Dockerfile:4
CI/CD securitycontainers
schwung-manager/static/htmx.min.js:1
scripts/uninstall.sh:124
README.md:45
.github/workflows/release.yml:23, 66 (3 hits).github/workflows/release.yml
CI/CD securitySupply chainGithub actions
scripts/install.sh:697
Weak hash
Dockerfile:9
CI/CD securitycontainers
src/lib/jack2/common/JackEngineControl.h:1, 2, 5 (3 hits)src/lib/jack2/common/JackAtomicState.h:1, 4 (2 hits)src/lib/jack2/common/JackAudioAdapterInterface.h:1, 2 (2 hits)src/lib/jack2/common/JackClientInterface.h:1, 2 (2 hits)src/lib/jack2/common/JackDriver.h:1, 3 (2 hits)src/lib/jack2/common/JackDummyDriver.h:1, 3 (2 hits)src/lib/jack2/common/JackEngine.h:1, 2 (2 hits)libs/quickjs/quickjs-2025-04-26/qjsc.c:357Dockerfile:3
containersPinned dependencies
This page is publicly accessible at:
https://repobility.com/scan/3e1c4285-0bca-4ba4-9c2b-65cfa56d6ae4/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/3e1c4285-0bca-4ba4-9c2b-65cfa56d6ae4/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.