https://github.com/Reshigan/Heirloom
· scanned 2026-06-15 23:50 UTC (2 months, 3 weeks ago)
334 raw signals (0 security + 334 graph)
Last scanned 2 months, 3 weeks ago · v1 · 268 actionable findings from 1 signal source. 66 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
Showing 221 of 268 actionable findings. 334 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
cloudflare/worker/src/services/pushSender.ts:53
Private key in repo
cloudflare/frontend/src/pages/Signup.tsx:91, 92 (2 hits)mobile/src/screens/LoginScreen.tsx:40
mobile/src/screens/SignupScreen.tsx:46, 48, 52 (3 hits)cloudflare/frontend/.env.production
ConfigEnv fileRuntime env
cloudflare/worker-configuration.d.ts:2997
Exec used
repo-level (51 hits).github/workflows/social-autopost.yml.github/workflows/social-batch.yml.github/workflows/social-promo.ymlcloudflare/frontend/scripts/live-seeded-shots.mjs:199
Cors wildcard
cloudflare/frontend/scripts/mock-authed-shots.mjs:24
Cors wildcard
cloudflare/worker/src/routes/voice.ts:250
Cors wildcard
cloudflare/frontend/public/offline-boot.js:34
Direct innerhtml assignment
cloudflare/frontend/src/loom/components/ClothWeave.tsx:396
Direct innerhtml assignment
cloudflare/frontend/src/loom/components/CosmicLoom.tsx:336
Direct innerhtml assignment
cloudflare/frontend/scripts/audit-pages.mjs:25
Local storage auth token
cloudflare/frontend/scripts/live-seeded-shots.mjs:189
Local storage auth token
cloudflare/frontend/scripts/mock-authed-shots.mjs:10
Local storage auth token
cloudflare/frontend/src/pages/AdminLogin.tsx:17
Local storage auth token
cloudflare/frontend/src/pages/GiftReceive.tsx:67
Local storage auth token
cloudflare/frontend/src/services/api.ts:12
Local storage auth token
scripts/generate-social-video.js:17
Node child process
scripts/generate-tiktok.mjs:23
Node child process
cloudflare/frontend/Dockerfile:1
containersPinned dependencies
backend/Dockerfile:1
containersPinned dependencies
.github/workflows/pr-checks.yml:13, 56, 59, 77, 80, 101, 104, 125, +1 more (9 hits).github/workflows/d1-backup.yml:20, 23, 69 (3 hits)
This page is publicly accessible at:
https://repobility.com/scan/40bc01d8-04f6-41b6-83f2-94df5efb3143/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/40bc01d8-04f6-41b6-83f2-94df5efb3143/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.