Scan timing: clone 6.1s · analysis 9.47s · 40.2 MB · GitHub API rate-limit (preflight)
https://github.com/rclone/rclone
· scanned 2026-06-05 09:56 UTC (5 days, 14 hours ago)
· 10 languages
491 raw signals (145 security + 346 graph) 11/13 scanners ran 67th percentile · Go · large (100-500K LoC) System graph score 64 (higher by 22)
Last scanned 5 days, 14 hours ago · v2 · 190 actionable findings from 2 signal sources. 122 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
77.0 | 0.15 | 11.55 |
practices_score |
97.0 | 0.15 | 14.55 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 86.8 |
Showing 140 of 190 actionable findings. 312 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
bin/update-authors.py:59
.github/workflows/build.yml:245, 496 (2 hits)backend/iclouddrive/iclouddrive.go:40
backend/seafile/webapi.go:223
backend/sftp/sftp.go:1170
fs/config/crypt.go:158
fs/config/ui.go:789, 803, 804 (3 hits)bin/manage_backends.py:103
Dockerfile:1, 36 (2 hits)contrib/docker-plugin/managed/Dockerfile:5fstest/testserver/images/test-hdfs/Dockerfile:2fstest/testserver/images/test-sftp-openssh/Dockerfile:2backend/cache/plex.go:122
backend/sftp/ssh_external.go:100
Dockerfile:26
CI/CD securitycontainers
.github/workflows/build.yml:107, 113, 134, 145, 273, 279, 286, 295, +4 more (22 hits).github/workflows/build_publish_docker_image.yml:59, 99, 136, 190, 205 (10 hits).github/workflows/build_publish_docker_plugin.yml:36 (2 hits).github/workflows/build.yml:304, 310, 318, 326, 334, 348 (12 hits).github/workflows/build_publish_docker_image.yml:107, 129, 132, 146, 155, 166, 217, 268, +2 more (11 hits).github/workflows/notify.yml:14.github/workflows/winget.yml:13backend/onedrive/onedrive.go:488
backend/onedrive/onedrive.go:493
backend/mailru/mailru.go:497
lib/oauthutil/oauthutil.go:725
lib/oauthutil/oauthutil.go:724
cmd/serve/dlna/dlna.go:352
backend/pcloud/pcloud.go:84
cmd/serve/http/http.go:324
backend/mailru/mailru.go:494
lib/oauthutil/oauthutil.go:633
backend/yandex/yandex.go:265
backend/jottacloud/jottacloud.go:655
fs/rc/js/serve.go:18
bin/make_backend_docs.py:73, 82 (2 hits)bin/check_autogenerated_edits.py:44.dockerignore
CI/CD securitycontainers
Dockerfile:36contrib/docker-plugin/managed/Dockerfile:5fstest/testserver/images/test-hdfs/Dockerfile:2fstest/testserver/images/test-sftp-openssh/Dockerfile:2Dockerfile:36contrib/docker-plugin/managed/Dockerfile:5fstest/testserver/images/test-sftp-openssh/Dockerfile:2Dockerfile:36contrib/docker-plugin/managed/Dockerfile:5fstest/testserver/images/test-sftp-openssh/Dockerfile:2.github/workflows/build_publish_docker_image.yml
CI/CD securitySupply chainGithub actions
backend/azureblob/azureblob.go:273
Weak hash
backend/azurefiles/azurefiles.go:160
Weak hash
backend/b2/api/types.go:56
Weak hash
backend/b2/b2.go:177
Weak hash
backend/box/api/types.go:81
Weak hash
backend/box/box.go:1547
Weak hash
backend/chunker/chunker.go:213
Weak hash
backend/cloudinary/cloudinary.go:527
Weak hash
backend/compress/compress.go:618
Weak hash
backend/compress/gzip_handler.go:203
Weak hash
backend/compress/zstd_handler.go:188
Weak hash
backend/doi/api/dataversetypes.go:37
Weak hash
backend/doi/dataverse.go:89
Weak hash
backend/doi/doi.go:133
Weak hash
backend/filefabric/api/types.go:283
Weak hash
backend/filescom/filescom.go:123
Weak hash
backend/gofile/api/types.go:83
Weak hash
backend/gofile/gofile.go:147
Weak hash
backend/googlecloudstorage/googlecloudstorage.go:1192
Weak hash
backend/internetarchive/internetarchive.go:70
Weak hash
backend/jottacloud/api/types.go:401
Weak hash
backend/jottacloud/jottacloud.go:138
Weak hash
backend/memory/memory.go:26
Weak hash
backend/netstorage/netstorage.go:713
Weak hash
backend/onedrive/api/types.go:141
Weak hash
backend/onedrive/onedrive.go:346
Weak hash
backend/opendrive/opendrive.go:142
Weak hash
backend/oracleobjectstorage/multipart.go:352
Weak hash
backend/oracleobjectstorage/object.go:53
Weak hash
backend/oracleobjectstorage/options.go:237
Weak hash
backend/oracleobjectstorage/oracleobjectstorage.go:225
Weak hash
backend/pcloud/api/types.go:107
Weak hash
backend/pcloud/pcloud.go:187
Weak hash
backend/pcloud/writer_at.go:83
Weak hash
backend/pikpak/pikpak.go:381
Weak hash
backend/protondrive/protondrive.go:942
Weak hash
backend/qingstor/qingstor.go:414
Weak hash
backend/s3/s3.go:214
Weak hash
backend/sftp/sftp.go:239
Weak hash
backend/shade/api/types.go:13
Weak hash
backend/sharefile/api/types.go:100
Weak hash
backend/sharefile/sharefile.go:1184
Weak hash
backend/swift/swift.go:1268
Weak hash
backend/ulozto/ulozto.go:369
Weak hash
backend/webdav/api/types.go:127
Weak hash
backend/webdav/webdav.go:225
Weak hash
backend/yandex/yandex.go:148
Weak hash
cmd/bisync/compare.go:131
Weak hash
cmd/bisync/listing.go:490
Weak hash
cmd/bisync/march.go:58
Weak hash
cmd/check/check.go:141
Weak hash
cmd/checksum/checksum.go:30
Weak hash
cmd/dedupe/dedupe.go:88
Weak hash
cmd/hashsum/hashsum.go:96
Weak hash
cmd/lsf/lsf.go:25
Weak hash
cmd/lsjson/lsjson.go:50
Weak hash
cmd/md5sum/md5sum.go:26
Weak hash
cmd/serve/s3/s3.go:30
Weak hash
cmd/serve/s3/server.go:86
Weak hash
cmd/serve/sftp/connection.go:99
Weak hash
cmd/serve/webdav/webdav.go:122
Weak hash
cmd/sha1sum/sha1sum.go:33
Weak hash
fs/operations/lsjson.go:86
Weak hash
fs/operations/operationsflags/operationsflags.go:68
Weak hash
fs/operations/rc.go:900
Weak hash
lib/http/auth.go:32
Weak hash
backend/ftp/ftp.go
Ports
backend/box/upload.go:227backend/cache/object.go:138backend/compress/zstd_handler.go:154backend/local/metadata_unix.go:1, 8 (2 hits)backend/opendrive/opendrive.go:188, 654 (2 hits)backend/premiumizeme/premiumizeme.go:236, 602 (2 hits)backend/shade/shade.go:581, 584 (2 hits)backend/yandex/yandex.go:120, 679 (2 hits)backend/compress/zstd_handler.go:21backend/filelu/filelu_object.go:52backend/filescom/filescom.go:505Dockerfile:1
containersPinned dependencies
This page is publicly accessible at:
https://repobility.com/scan/5a00e5cd-458d-444c-b328-c6d9527644dc/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/5a00e5cd-458d-444c-b328-c6d9527644dc/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.