https://github.com/anomalyco/opencode
· scanned 2026-06-05 04:39 UTC (4 hours, 17 minutes ago)
· 10 languages
918 findings (66 legacy + 852 scanner) 11/13 scanners ran 54th percentile · Typescript · medium (20-100K LoC) Scanner says 71 (higher by 4)
Last scanned 4 hours, 17 minutes ago · v2 · 492 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
60.0 | 0.15 | 9.00 |
practices_score |
57.0 | 0.15 | 8.55 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 75.5 |
Showing 370 of 492 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/generate.yml:40
dependencylegacy
packages/app/src/utils/aim.ts:49
qualitylegacy
packages/app/package.json:1
dependencylegacy
packages/app/src/context/sync.tsx:97
prototype_pollutionlegacy
.opencode/tool/github-pr-search.ts:60
xsslegacy
packages/opencode/src/cli/cmd/github.handler.ts:295
owaspexec_used
packages/app/src/pages/directory-layout.tsx:29
error_handlinglegacy
packages/app/src/entry.tsx:82
securitylegacy
README.fr.md:50
dependencylegacy
README.es.md:50
dependencylegacy
README.de.md:50
dependencylegacy
README.da.md:50
dependencylegacy
README.bs.md:50
dependencylegacy
README.br.md:50
dependencylegacy
README.bn.md:50
dependencylegacy
README.ar.md:50
dependencylegacy
.github/workflows/triage.yml:23
dependencylegacy
.github/workflows/review.yml:35
dependencylegacy
.github/workflows/pr-management.yml:40
dependencylegacy
.github/workflows/docs-locale-sync.yml:53
dependencylegacy
packages/opencode/Dockerfile:1
supply-chaindockerpinned-dependencies
packages/opencode/Dockerfile:16
supply-chaindockerpinned-dependencies
.github/workflows/stats.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/publish-github-action.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/publish-vscode.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/deploy.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/containers.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/opencode.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/docs-update.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/generate.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release-github-action.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/beta.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/docs-locale-sync.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/nix-hashes.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/publish.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/stats.yml
securityports
packages/app/public/oc-theme-preload.js:30
qualitylegacy
packages/app/src/i18n/th.ts:353
qualitylegacy
packages/app/src/i18n/ru.ts:627
qualitylegacy
packages/app/src/i18n/ru.ts:617
qualitylegacy
packages/app/src/i18n/ru.ts:356
qualitylegacy
packages/app/src/i18n/pl.ts:622
qualitylegacy
packages/app/src/i18n/pl.ts:354
qualitylegacy
packages/app/src/i18n/no.ts:622
qualitylegacy
packages/app/src/i18n/no.ts:355
qualitylegacy
packages/app/src/i18n/ko.ts:352
qualitylegacy
packages/app/src/i18n/ja.ts:353
qualitylegacy
packages/app/src/i18n/fr.ts:632
qualitylegacy
packages/app/src/i18n/fr.ts:356
qualitylegacy
packages/app/src/i18n/es.ts:361
qualitylegacy
packages/app/src/i18n/es.ts:355
qualitylegacy
packages/app/src/i18n/de.ts:633
qualitylegacy
packages/app/src/i18n/de.ts:623
qualitylegacy
packages/app/src/i18n/de.ts:359
qualitylegacy
packages/app/src/i18n/da.ts:620
qualitylegacy
packages/app/src/i18n/da.ts:354
qualitylegacy
packages/app/src/i18n/bs.ts:621
qualitylegacy
packages/app/src/i18n/bs.ts:355
qualitylegacy
packages/app/src/i18n/br.ts:354
qualitylegacy
packages/app/src/context/sync.tsx:10
qualitylegacy
packages/app/src/context/server.tsx:28
qualitylegacy
packages/app/src/components/status-popover-body.tsx:103
qualitylegacy
packages/app/src/components/settings-v2/providers.tsx:16
qualitylegacy
packages/app/src/components/settings-v2/models.tsx:17
qualitylegacy
packages/app/src/components/settings-v2/general.tsx:14
qualitylegacy
packages/app/src/components/dialog-custom-provider.tsx:145
qualitylegacy
.opencode/tool/github-triage.ts:17
qualitylegacy
packages/stats/server/Dockerfile:1
supply-chaindockerpinned-dependencies
packages/containers/base/Dockerfile:1
supply-chaindockerpinned-dependencies
package.json
supply-chainnpminstall-scripts
Showing first 300 of 370. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/4afeaf9c-2db6-4dd1-b456-0b3956a7aa2b/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/4afeaf9c-2db6-4dd1-b456-0b3956a7aa2b/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.