Scan timing: clone 4.12s · analysis 21.99s · 17.8 MB · GitHub API rate-limit (preflight)
https://github.com/github/copilot-sdk
· scanned 2026-06-04 23:18 UTC (18 hours, 15 minutes ago)
· 10 languages
1079 findings (223 legacy + 856 scanner) 12th percentile · Java · large (100-500K LoC) Scanner says 80 (lower by 14)
Last scanned 18 hours, 15 minutes ago · v4 · 437 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
34.6 | 0.25 | 8.65 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
82.0 | 0.15 | 12.30 |
code_quality |
44.7 | 0.10 | 4.47 |
| Overall | 1.00 | 66.4 |
Top 10 actions, ranked by impact × ease. Severity drives impact; tag-based fix-clarity drives ease.
java/src/generated/java/com/github/copilot/generated/rpc/SessionShellApi.java:41.github/workflows/verify-compiled.yml:20.github/workflows/update-copilot-dependency.yml:54.github/workflows/codegen-check.yml:54.github/workflows/rust-sdk-tests.yml:65.github/workflows/java-sdk-tests.yml.github/workflows/docs-validation.yml:64.github/workflows/copilot-setup-steps.yml:49.github/workflows/copilot-setup-steps.yml:75.github/workflows/java-codegen-fix.lock.ymlClick "Find this gap" on any action above to jump to it on the Findings tab. Adjust the chip bar to filter by impact (severity), layer, or source.
This page is publicly accessible at:
https://repobility.com/scan/5ef0a980-c2f9-417c-a367-43c5f959e224/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/5ef0a980-c2f9-417c-a367-43c5f959e224/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.