Scan timing: clone 1.97s · analysis 26.37s · 17.8 MB · GitHub API rate-limit (preflight)
https://github.com/boxlite-ai/boxlite
· scanned 2026-05-31 01:24 UTC (5 days, 7 hours ago)
· 10 languages
1228 findings (275 legacy + 953 scanner) 11/13 scanners ran 71st percentile · Typescript · large (100-500K LoC) Scanner says 48 (higher by 31)
Last scanned 5 days, 7 hours ago · v2 · last Δ -0.7 (diff) · 755 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
40.0 | 0.20 | 8.00 |
documentation_score |
92.0 | 0.15 | 13.80 |
practices_score |
84.0 | 0.15 | 12.60 |
code_quality |
69.0 | 0.10 | 6.90 |
| Overall | 1.00 | 79.1 |
Showing 540 of 755 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
apps/dashboard/src/components/ui/stories/copyable-value.stories.tsx:27
credential_exposurelegacy
apps/api/src/audit/enums/audit-action.enum.ts:48
secrets
apps/api/src/audit/enums/audit-action.enum.ts:49
secrets
apps/dashboard/src/components/Playground/Sandbox/CodeSnippets/python.ts:172
secrets
apps/dashboard/src/components/ui/stories/copyable-value.stories.tsx:27
secrets
apps/infra/sst.config.ts:461
secrets
examples/python/03_lifecycle/share_across_processes.py:151
qualitylegacy
examples/python/03_lifecycle/manage_lifecycle.py:116
qualitylegacy
examples/python/03_lifecycle/clone_export_import.py:78
qualitylegacy
src/boxlite/src/images/archive/verifier.rs:87
qualitylegacy
examples/python/04_interactive/run_interactive_shell.py:46
qualitylegacy
examples/python/04_interactive/install_claude_interactively.py:194
qualitylegacy
apps/daemon/pkg/toolbox/process/interpreter/repl_worker.py:129
qualitylegacy
scripts/common.sh:85
qualitylegacy
examples/python/04_interactive/install_claude_interactively.py:43
qualitylegacy
scripts/images/create-oci-bundle.sh:125
qualitylegacy
apps/common-go/pkg/errors/middleware.go:176
qualitylegacy
src/boxlite/src/net/ca.rs:100
qualitylegacy
sdks/python/boxlite/browserbox.py:355
qualitylegacy
sdks/python/boxlite/browserbox.py:389
qualitylegacy
sdks/python/boxlite/browserbox.py:264
qualitylegacy
sdks/python/boxlite/browserbox.py:313
qualitylegacy
sdks/python/boxlite/browserbox.py:307
qualitylegacy
sdks/python/boxlite/browserbox.py:309
qualitylegacy
sdks/python/boxlite/browserbox.py:517
qualitylegacy
sdks/python/boxlite/browserbox.py:556
qualitylegacy
sdks/python/boxlite/browserbox.py:224
qualitylegacy
sdks/python/boxlite/browserbox.py:216
qualitylegacy
sdks/python/boxlite/browserbox.py:481
qualitylegacy
sdks/python/boxlite/browserbox.py:476
qualitylegacy
sdks/python/boxlite/browserbox.py:473
qualitylegacy
sdks/python/boxlite/browserbox.py:345
qualitylegacy
sdks/python/boxlite/browserbox.py:325
qualitylegacy
sdks/python/boxlite/browserbox.py:382
qualitylegacy
sdks/python/boxlite/browserbox.py:373
qualitylegacy
sdks/python/boxlite/browserbox.py:363
qualitylegacy
sdks/python/boxlite/browserbox.py:257
qualitylegacy
sdks/python/boxlite/browserbox.py:567
qualitylegacy
sdks/python/boxlite/codebox.py:105
qualitylegacy
sdks/python/boxlite/codebox.py:122
qualitylegacy
sdks/python/boxlite/codebox.py:73
qualitylegacy
sdks/python/boxlite/browserbox.py:600
qualitylegacy
sdks/python/boxlite/codebox.py:88
qualitylegacy
examples/python/02_features/forward_ports.py:40
qualitylegacy
.github/workflows/warm-caches.yml:58
dependencylegacy
.github/workflows/warm-caches.yml:53
dependencylegacy
.github/workflows/build-wheels.yml:28
dependencylegacy
.github/workflows/warm-caches.yml:66
dependencylegacy
.github/workflows/warm-caches.yml:63
dependencylegacy
apps/otel-collector/Dockerfile:46
dependencylegacy
apps/snapshot-manager/Dockerfile:41
dependencylegacy
apps/ssh-gateway/Dockerfile:41
dependencylegacy
apps/proxy/Dockerfile:45
dependencylegacy
apps/dex/Dockerfile:1
dependencylegacy
apps/runner/Dockerfile:63
dependencylegacy
apps/dex/Dockerfile:5
dependencylegacy
src/boxlite/resources/images/skillbox/Dockerfile:8
dependencylegacy
apps/runner/Dockerfile:1
dependencylegacy
apps/otel-collector/Dockerfile:1
dependencylegacy
apps/snapshot-manager/Dockerfile:1
dependencylegacy
apps/ssh-gateway/Dockerfile:1
dependencylegacy
apps/proxy/Dockerfile:1
dependencylegacy
apps/api/Dockerfile:1
dependencylegacy
examples/node/package.json:1
dependencylegacy
apps/otel-collector/exporter/go.mod:62
dependencylegacy
apps/runner/go.mod:108
dependencylegacy
apps/cli/go.mod:100
dependencylegacy
apps/common-go/go.mod:76
dependencylegacy
apps/daemon/pkg/toolbox/lsp/lsp.go:110
path_traversallegacy
apps/dashboard/src/components/ui/chart.tsx:78
xsslegacy
apps/dashboard/src/components/SandboxTable/types.ts:271
xsslegacy
apps/dashboard/src/components/SandboxTable/columns.tsx:251
xsslegacy
examples/python/04_interactive/install_claude_interactively.py:54
qualitylegacy
apps/daemon/pkg/toolbox/process/interpreter/repl_worker.py:127
qualitylegacy
apps/api/src/common/utils/docker-image.util.ts:154
qualitylegacy
apps/daemon/pkg/common/spawn_tty.go:34
qualitylegacy
apps/cli/cmd/common/ssh_windows.go:24
qualitylegacy
apps/cli/cmd/common/ssh_unix.go:24
qualitylegacy
apps/daemon/pkg/session/types.go:41
path_traversallegacy
src/boxlite/resources/images/skillbox/Dockerfile:54
dockerlegacy
src/boxlite/resources/images/skillbox/Dockerfile:47
dockerlegacy
apps/dashboard/src/pages/Registries.tsx:198
authlegacy
examples/python/02_features/forward_ports.py:40
integritysync-io-in-asyncperformance
apps/api/src/organization/services/organization-usage.service.ts:333
owaspeval_used
apps/daemon/pkg/toolbox/process/interpreter/repl_worker.py:127
owaspexec_used
sdks/node/lib/native-contracts.ts:265
owaspexec_used
sdks/python/boxlite/orchestration/guest/boxlite_runtime.py:147
error_handlinglegacy
sdks/python/boxlite/orchestration/box_runtime.py:173
error_handlinglegacy
sdks/python/boxlite/interactivebox.py:291
error_handlinglegacy
openapi/reference-server/server.py:859
qualitylegacy
openapi/reference-server/server.py:829
qualitylegacy
examples/python/07_advanced/ai_pipeline/host.py:127
qualitylegacy
examples/python/03_lifecycle/share_across_processes.py:234
qualitylegacy
examples/python/03_lifecycle/share_across_processes.py:140
qualitylegacy
examples/python/03_lifecycle/manage_lifecycle.py:316
qualitylegacy
examples/python/03_lifecycle/manage_lifecycle.py:287
qualitylegacy
examples/python/03_lifecycle/manage_lifecycle.py:190
qualitylegacy
examples/python/03_lifecycle/manage_lifecycle.py:110
qualitylegacy
examples/python/04_interactive/install_claude_interactively.py:196
qualitylegacy
examples/python/04_interactive/run_interactive_shell.py:48
qualitylegacy
examples/python/06_ai_agents/run_openclaw.py:134
qualitylegacy
examples/python/06_ai_agents/drive_box_with_llm.py:104
qualitylegacy
examples/python/06_ai_agents/drive_box_with_minimax.py:133
qualitylegacy
examples/python/07_advanced/use_native_api.py:259
qualitylegacy
examples/python/07_advanced/local_to_rest_migration.py:63
qualitylegacy
examples/python/08_rest_api/use_env_config.py:40
qualitylegacy
examples/python/02_features/forward_ports.py:44
qualitylegacy
apps/daemon/pkg/toolbox/process/interpreter/repl_worker.py:184
qualitylegacy
apps/daemon/pkg/toolbox/process/interpreter/repl_worker.py:165
qualitylegacy
apps/daemon/pkg/toolbox/process/interpreter/repl_worker.py:38
qualitylegacy
sdks/python/boxlite/orchestration/guest/boxlite_runtime.py:117
qualitylegacy
sdks/python/boxlite/orchestration/guest/boxlite_runtime.py:155
qualitylegacy
sdks/python/boxlite/orchestration/box_runtime.py:163
qualitylegacy
sdks/python/boxlite/orchestration/box_runtime.py:118
deserializationlegacy
apps/dashboard/src/hooks/useDocsSearchCommands.tsx:99
securitylegacy
apps/dashboard/src/components/sandboxes/SandboxDetails.tsx:174
securitylegacy
apps/dashboard/src/components/SandboxTable/columns.tsx:80
securitylegacy
apps/proxy/pkg/proxy/proxy.go:239
qualitylegacy
apps/daemon/pkg/terminal/server.go:43
qualitylegacy
apps/cli/auth/auth.go:32
qualitylegacy
sdks/go/cmd/setup/main.go:167
securitylegacy
examples/node/browserbox_puppeteer.js:177
qualitylegacy
apps/dashboard/src/components/ui/stories/field.stories.tsx:38
qualitylegacy
apps/api/src/config/dto/configuration.dto.ts:163
qualitylegacy
sdks/python/boxlite/interactivebox.py:291
qualitylegacy
apps/ssh-gateway/Dockerfile:42
dockerlegacy
apps/snapshot-manager/Dockerfile:42
dockerlegacy
apps/runner/Dockerfile:63
dockerlegacy
apps/proxy/Dockerfile:46
dockerlegacy
apps/otel-collector/Dockerfile:47
dockerlegacy
apps/api/Dockerfile:1
dockerlegacy
apps/daemon/pkg/terminal/static/index.html:548
qualitylegacy
README.md:196
dependencylegacy
.github/workflows/warm-caches.yml:58
supply-chaingithub-actionspinned-dependencies
.github/workflows/warm-caches.yml:63
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-wheels.yml:33
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-wheels.yml:41
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-wheels.yml:74
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-wheels.yml:146
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-wheels.yml:168
supply-chaingithub-actionspinned-dependencies
.github/workflows/lint.yml:108
supply-chaingithub-actionspinned-dependencies
.github/workflows/lint.yml:130
supply-chaingithub-actionspinned-dependencies
.github/workflows/lint.yml:150
supply-chaingithub-actionspinned-dependencies
.github/workflows/lint.yml:254
supply-chaingithub-actionspinned-dependencies
.github/workflows/lint.yml:262
supply-chaingithub-actionspinned-dependencies
.github/workflows/lint.yml:281
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-runtime.yml:68
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-runtime.yml:76
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-runtime.yml:293
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-runtime.yml:322
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-node.yml:64
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-node.yml:72
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-node.yml:378
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-c.yml:64
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-c.yml:72
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-c.yml:218
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-runner-binary.yml:145
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-wheels.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/build-runtime.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/build-node.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/build-c.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/build-runner-binary.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/build-go.yml
supply-chaingithub-actionsleast-privilege
apps/dashboard/src/components/ui/chart.tsx:76
owaspdangerous_innerhtml
apps/dashboard/src/hooks/useDocsSearchCommands.tsx:119
owaspdangerous_innerhtml
apps/api/src/migrations/1744114341077-migration.ts:20
owaspweak_hash
apps/api/src/migrations/1744808444807-migration.ts:16
owaspweak_hash
apps/api/src/migrations/1744971114480-migration.ts:14
owaspweak_hash
apps/api/src/migrations/1745574377029-migration.ts:51
owaspweak_hash
apps/api/src/migrations/post-deploy/1774438866002-migration.ts:45
owaspweak_hash
sdks/node/lib/browserbox.ts
securityports
openapi/box.openapi.yaml
securityports
apps/dex/Dockerfile
securityports
apps/api-client-go/api/openapi.yaml
securityports
apps/api-client-go/api/openapi.yaml
securityports
apps/api-client-go/api/openapi.yaml
securityports
apps/api-client-go/api/openapi.yaml
securityports
apps/api-client-go/api/openapi.yaml
securityports
.dockerignore
dockerlegacy
apps/cli/cmd/auth/login.go:178
error_handlinglegacy
apps/cli/auth/auth.go:51
error_handlinglegacy
apps/cli/apiclient/api_client.go:85
error_handlinglegacy
apps/api/src/sandbox/entities/build-info.entity.ts:16
qualitylegacy
apps/api-client-go/model_create_volume.go:57
qualitylegacy
apps/api-client-go/model_create_user.go:208
qualitylegacy
apps/api-client-go/model_create_snapshot.go:291
qualitylegacy
apps/api-client-go/model_create_snapshot.go:266
qualitylegacy
apps/api-client-go/model_create_runner.go:78
qualitylegacy
apps/api-client-go/model_create_organization_role.go:98
qualitylegacy
apps/api-client-go/model_create_linked_account.go:78
qualitylegacy
apps/api-client-go/model_computer_use_stop_response.go:76
qualitylegacy
apps/api-client-go/model_computer_use_status_response.go:58
qualitylegacy
apps/api-client-go/api_webhooks.go:92
qualitylegacy
apps/api-client-go/api_webhooks.go:1
qualitylegacy
apps/api-client-go/api_volumes.go:420
qualitylegacy
apps/api-client-go/api_volumes.go:88
qualitylegacy
apps/api-client-go/api_volumes.go:1
qualitylegacy
apps/api-client-go/api_users.go:1
qualitylegacy
apps/api-client-go/api_regions.go:49
qualitylegacy
apps/api-client-go/api_regions.go:1
qualitylegacy
apps/api-client-go/api_preview.go:1
qualitylegacy
apps/api-client-go/api_object_storage.go:56
qualitylegacy
apps/api-client-go/api_object_storage.go:54
qualitylegacy
apps/api-client-go/api_object_storage.go:1
qualitylegacy
apps/api-client-go/api_jobs.go:166
qualitylegacy
apps/api-client-go/api_jobs.go:1
qualitylegacy
apps/api-client-go/api_health.go:54
qualitylegacy
apps/api-client-go/api_health.go:1
qualitylegacy
apps/api-client-go/api_docker_registry.go:99
qualitylegacy
apps/api-client-go/api_docker_registry.go:1
qualitylegacy
apps/api-client-go/api_config.go:49
qualitylegacy
apps/api-client-go/api_audit.go:1
qualitylegacy
apps/api-client-go/api_api_keys.go:1
qualitylegacy
src/boxlite/src/jailer/shim_copy.rs:1
qualitylegacy
apps/otel-collector/Dockerfile:46
supply-chaindockerpinned-dependencies
apps/snapshot-manager/Dockerfile:41
supply-chaindockerpinned-dependencies
apps/ssh-gateway/Dockerfile:41
supply-chaindockerpinned-dependencies
apps/proxy/Dockerfile:45
supply-chaindockerpinned-dependencies
apps/dex/Dockerfile:1
supply-chaindockerpinned-dependencies
apps/runner/Dockerfile:63
supply-chaindockerpinned-dependencies
apps/dex/Dockerfile:5
supply-chaindockerpinned-dependencies
src/boxlite/resources/images/skillbox/Dockerfile:8
supply-chaindockerpinned-dependencies
apps/runner/Dockerfile:1
supply-chaindockerpinned-dependencies
apps/otel-collector/Dockerfile:1
supply-chaindockerpinned-dependencies
apps/snapshot-manager/Dockerfile:1
supply-chaindockerpinned-dependencies
apps/ssh-gateway/Dockerfile:1
supply-chaindockerpinned-dependencies
apps/proxy/Dockerfile:1
supply-chaindockerpinned-dependencies
apps/api/Dockerfile:1
supply-chaindockerpinned-dependencies
Showing first 300 of 540. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/51fceb34-d3ee-486b-ae87-8ff06a5e27b3/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/51fceb34-d3ee-486b-ae87-8ff06a5e27b3/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.