Scan timing: clone 8.93s · analysis 54.08s · 19.9 MB · GitHub API rate-limit (preflight)
https://github.com/BradGroux/veritas-kanban
· scanned 2026-06-05 15:09 UTC (5 days, 1 hour ago)
· 10 languages
626 raw signals (174 security + 452 graph) 29th percentile · Typescript · large (100-500K LoC)
Last scanned 5 days, 1 hour ago · v2 · 298 actionable findings from 2 signal sources. 100 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
43.1 | 0.25 | 10.78 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
87.7 | 0.15 | 13.15 |
practices_score |
85.0 | 0.15 | 12.75 |
code_quality |
47.2 | 0.10 | 4.72 |
| Overall | 1.00 | 69.4 |
Showing 238 of 298 actionable findings. 398 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
server/src/__tests__/routes/auth.test.ts:28, 73 (2 hits)cli/src/__tests__/snapshot.test.ts:220docs/API-REFERENCE.md:671docs/API-WORKFLOWS.md:1343web/src/__tests__/multi-user-tab.test.tsx:123docs/TROUBLESHOOTING.md:179, 207, 210 (3 hits)docs/features/prd-driven-development.md:95, 775 (2 hits)docs/security.md:51, 58 (2 hits)server/.env.example:122, 125 (2 hits)docs/DEPLOYMENT.md:790docs/guides/SELF_HOST.md:729seed-demo-data.sh:45server/src/__tests__/governance-trace-service.test.ts:22server/src/__tests__/log-redaction.test.ts:31server/src/__tests__/skill-capability-service.test.ts:63server/src/middleware/request-id.ts:27
server/src/services/workflow-authoring-service.ts:1800
Dockerfile:17, 66 (2 hits)server/src/routes/scheduled-deliverables.ts:88
server/src/routes/task-subtasks.ts:105
server/src/routes/docs.ts:119
server/src/routes/config.ts:106
server/src/routes/scheduled-deliverables.ts:66
server/src/routes/task-subtasks.ts:64
server/src/routes/task-subtasks.ts:123
server/src/routes/config.ts:83
server/src/routes/scheduled-deliverables.ts:35
server/src/routes/scheduled-deliverables.ts:98
server/src/routes/task-subtasks.ts:26
server/src/routes/auth.ts:692
server/src/routes/auth.ts:256
server/src/routes/auth.ts:410
server/src/routes/auth.ts:480
server/src/routes/auth.ts:583
server/src/routes/auth.ts:279
server/src/routes/cost-prediction.ts:41
server/src/routes/auth.ts:607
server/src/routes/config.ts:60
server/src/routes/config.ts:120
server/src/routes/auth.ts:336
server/src/routes/config.ts:164
server/src/routes/config.ts:183
server/src/routes/docs.ts:99
.github/workflows/ci.yml:23, 58, 84, 135 (4 hits).github/workflows/scheduled-qa.yml:40, 87 (2 hits).github/workflows/desktop-artifacts.yml:33.github/workflows/desktop-release.yml:35.github/workflows/ci.yml:22, 25, 57, 60, 83, 86, 134, 137 (8 hits).github/workflows/scheduled-qa.yml:39, 42, 70, 86, 89, 165 (8 hits).github/workflows/desktop-artifacts.yml:32, 57, 100, 141 (4 hits).github/workflows/desktop-release.yml:34, 37 (2 hits)server/src/__fixtures__/skill-security/malicious/unpinned-dependency/package.json:1
.pre-commit-config.yaml:7
server/src/routes/chat.ts:23server/src/services/trace-service.ts:57server/src/services/worktree-service.ts:209server/src/services/activity-service.ts:194server/src/services/shared-resources-service.ts:41server/src/storage/sqlite/activity-repository.ts:39server/src/services/config-service.ts:35
CI/CD securityagent runtimepermissions
package.json
cli/package.json
package.json
.well-known/security.txt
server/src/__fixtures__/skill-security/malicious/remote-script/SKILL.md:6
.github/workflows/desktop-release.yml
CI/CD securitySupply chainGithub actions
demo/seed.sh
Ports
demo/seed.sh
Ports
demo/seed.sh
Ports
demo/seed.sh
Ports
demo/seed.sh
Ports
demo/seed.sh
Ports
.dockerignore
CI/CD securitycontainers
docker-compose.yml:15
CI/CD securitycontainers
server/src/services/device-session-service.ts:41, 82 (2 hits)server/src/storage/sqlite/prompt-registry-repository.ts:46, 340 (2 hits)server/src/storage/sqlite/status-history-repository.ts:107, 242 (2 hits)web/src/components/dashboard/DashboardPage.tsx:37, 115 (2 hits)cli/src/commands/snapshot.ts:81mcp/src/tools/tasks.ts:172mcp/src/utils/api.ts:1server/src/routes/scoring.ts:70web/package.json
server/package.json
cli/package.json
llms.txt
humans.txt
robots.txt
sitemap.xml
Dockerfile:17, 66 (2 hits)package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/52ffb460-31b3-4e4c-8fbc-f948099ce16c/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/52ffb460-31b3-4e4c-8fbc-f948099ce16c/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.