https://github.com/shiroha-a/mk
· scanned 2026-06-16 00:11 UTC (2 months, 2 weeks ago)
248 raw signals (0 security + 248 graph)
Last scanned 2 months, 2 weeks ago · v1 · 226 actionable findings from 1 signal source. 22 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
Showing 60 of 226 actionable findings. 248 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
e2e/cypress/e2e/webauthn.cy.ts:20, 21 (2 hits).devcontainer/Dockerfile:10
containersRemote installer
Dockerfile:69
containersPinned dependencies
.github/workflows/docker.yml:57, 63, 76, 92 (4 hits).github/workflows/dropin-frontend-e2e.yml:43.github/workflows/docker.yml
CI/CD securitySupply chainGithub actions
internal/api/wellknown/handler.go:34
Cors wildcard
internal/api/admin/drive.go:289
Weak hash
internal/api/drive/handler.go:397
Weak hash
internal/core/drive/drive_service.go:319
Weak hash
internal/core/drive/file_info.go:15
Weak hash
internal/core/federation/resolver.go:1895
Weak hash
internal/entity/drive.go:28
Weak hash
internal/model/drive_file.go:10
Weak hash
.github/workflows/playwright.yml
Ports
.github/workflows/dropin-e2e.yml
Ports
.github/workflows/dropin-frontend-e2e.yml
Ports
Dockerfile:8tests/queue-bench/blackhole/Dockerfile:2tests/queue-bench/faker/Dockerfile:2.devcontainer/Dockerfile:1
containersPinned dependencies
tests/dropin/fedibird_mock/Dockerfile:4tests/federation/common/Dockerfile:3tests/queue-bench-autoscale/driver/Dockerfile:2.github/workflows/playwright.yml:99, 111, 143, 161 (4 hits).github/workflows/dropin-e2e.yml:55, 67, 106 (3 hits).github/workflows/queue-bench-smoke.yml:64, 74, 154 (3 hits).github/workflows/docker.yml:32, 43 (2 hits).github/workflows/ci.yml:131.github/workflows/dropin-frontend-e2e.yml:83e2e/cypress/package.json
LockfileReproducibilityGenerated repo pattern
This page is publicly accessible at:
https://repobility.com/scan/4301181b-f7e7-44e0-a59f-4211f4fd0257/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/4301181b-f7e7-44e0-a59f-4211f4fd0257/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.