Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

block/buzz

https://github.com/block/buzz · scanned 2026-07-23 19:35 UTC (1 month, 2 weeks ago)

251 raw signals (0 security + 251 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 1 month, 2 weeks ago · v4 · 246 actionable findings from 1 signal source. 5 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: layer: security × excluding tests × Reset all
Corpus Intelligence Cross-corpus context (cohort percentile, top patterns, fix plan) is shown only on repositories you own. Sign up and connect your repo to view it.
Scan summary Repository scanned at 66.2/100 with 100.0% coverage. It contains 10486 nodes across 17 cross-layer flows, written primarily in mixed languages. Engine surfaced 251 findings — concentrated in frontend (119), quality (99), security (16). Risk profile is high: 0 critical, 2 high, 29 medium. Recommended next step: open the frontend layer findings first — that's where the highest-impact wins live.

Showing 14 of 246 actionable findings. 251 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

high System graph security Trivy conf 1.00 CVE-2026-48801: linkify-it 5.0.0 — pnpm-lock.yaml
linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy lin…
VulnCve 2026 48801
high System graph security Trivy conf 1.00 CVE-2026-59887: linkify-it 5.0.0 — pnpm-lock.yaml
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaini…
VulnCve 2026 59887
medium System graph security Trivy conf 1.00 CVE-2026-48988: markdown-it 14.1.1 — pnpm-lock.yaml
markdown-it is a Markdown parser. Versions 14.1.1 and below contain a ... markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from rep…
VulnCve 2026 48988
medium System graph security Trivy conf 1.00 CVE-2026-50185: cmov 0.5.3 — Cargo.lock
RustCrypto CMOV provides conditional move CPU intrinsics which are gua ... RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. From 0.1.1 until 0.5.4, the aarch64 implementati…
VulnCve 2026 50185
medium System graph security Trivy conf 1.00 GHSA-wrw7-89jp-8q8g: glib 0.18.5 — desktop/src-tauri/Cargo.lock
Unsoundness in `Iterator` and `DoubleEndedIterator` impls for `glib::VariantStrIter` The `VariantStrIter::impl_get` function (called internally by implementations of the `Iterator` and `DoubleEndedIterator` traits for this type) was unsound, resulting in undefined behaviour. An immutable referenc…
VulnGhsa wrw7 89jp 8q8g
medium System graph security security conf 0.65 Insecure pattern 'dangerous_innerhtml' in desktop/src/features/messages/ui/BotIdenticon.tsx:31
Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible.
desktop/src/features/messages/ui/BotIdenticon.tsx:31 Dangerous innerhtml
medium System graph security security conf 0.65 Insecure pattern 'domparser_html_parse' in desktop/src/features/messages/lib/normalizeMentionClipboard.ts:20
Found a known-risky pattern (domparser_html_parse). Review and replace if possible.
desktop/src/features/messages/lib/normalizeMentionClipboard.ts:20 Domparser html parse
medium System graph security security conf 0.65 Insecure pattern 'domparser_html_parse' in desktop/src/shared/lib/codeBlockClipboard.ts:51
Found a known-risky pattern (domparser_html_parse). Review and replace if possible.
desktop/src/shared/lib/codeBlockClipboard.ts:51 Domparser html parse
medium System graph security security conf 0.65 Insecure pattern 'domparser_html_parse' in web/src/features/repos/git-client.ts:364
Found a known-risky pattern (domparser_html_parse). Review and replace if possible.
web/src/features/repos/git-client.ts:364 Domparser html parse
medium System graph security Trivy conf 1.00 KSV-0125: Restrict container images to trusted registries — deploy/charts/buzz-push-gateway/templates/deployment.yaml
Restrict container images to trusted registries Container gateway in deployment buzz-push-gateway-buzz-push-gateway (namespace: default) uses an image from an untrusted registry. Rule: KSV-0125 Severity: MEDIUM Target: deploy/charts/buzz-push-gateway/templates/deployment.yaml
Misconfig
medium System graph security Secrets conf 0.58 Possible secret in scripts/dev-setup.sh
Detected 1 occurrence(s) matching password_literal. Rotate real credentials and move them to a secret manager.
scripts/dev-setup.sh:60 Password literal
low System graph security Trivy conf 1.00 DS-0026: No HEALTHCHECK defined — Dockerfile
No HEALTHCHECK defined Add HEALTHCHECK instruction in your Dockerfile Rule: DS-0026 Severity: LOW Target: Dockerfile
Misconfig
low System graph security Trivy conf 1.00 DS-0026: No HEALTHCHECK defined — Dockerfile.push-gateway
No HEALTHCHECK defined Add HEALTHCHECK instruction in your Dockerfile Rule: DS-0026 Severity: LOW Target: Dockerfile.push-gateway
Misconfig
low System graph security Trivy conf 1.00 KSV-0110: Workloads in the default namespace — deploy/charts/buzz-push-gateway/templates/deployment.yaml
Workloads in the default namespace deployment buzz-push-gateway-buzz-push-gateway in default namespace should set metadata.namespace to a non-default namespace Rule: KSV-0110 Severity: LOW Target: deploy/charts/buzz-push-gateway/templates/deployment.yaml
Misconfig
For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/5dac3faf-ed0f-4de0-b127-46d0aa2a3eda/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/5dac3faf-ed0f-4de0-b127-46d0aa2a3eda/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.