Scan timing: clone 13.15s · analysis 8.94s · 33.9 MB · GitHub API rate-limit (preflight)
https://github.com/gohugoio/hugo
· scanned 2026-06-05 07:03 UTC (5 days, 23 hours ago)
· 10 languages
136 raw signals (52 security + 84 graph) 11/13 scanners ran 64th percentile · Go · large (100-500K LoC) System graph score 70 (higher by 14)
Last scanned 5 days, 23 hours ago · v2 · 64 actionable findings from 2 signal sources. 30 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
81.0 | 0.15 | 12.15 |
practices_score |
79.0 | 0.15 | 11.85 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 84.8 |
Showing 44 of 64 actionable findings. 94 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
docs/assets/js/main.js:30
docs/assets/js/alpinejs/data/explorer.js:29
Dockerfile:55
docs/.github/workflows/codeql-analysis.yml:21, 26 (4 hits)livereload/livereload.js:305
Exec used
helpers/general.go:39
Dockerfile:55
CI/CD securitycontainers
tpl/tplimpl/embedded/templates/sitemap.xml
hugolib/page__new.go:1
Dockerfile:55
containersChecksum
.github/workflows/image.yml
CI/CD securitySupply chainGithub actions
deploy/deploy.go:317
Weak hash
tpl/crypto/init.go:41
Weak hash
.dockerignore
CI/CD securitycontainers
commands/config.go:118commands/convert.go:116commands/deploy_flags.go:24common/loggers/handlerterminal.go:32internal/warpc/genwebp/webp.c:24internal/warpc/webp.go:163markup/internal/attributes/attributes.go:17resources/resource/resource_helpers.go:19resources/resource_transformers/cssjs/postcss.go:113resources/resource_transformers/cssjs/tailwindcss.go:74hugolib/page__new.go:1
Dockerfile:50
containersPinned dependencies
Dockerfile:10, 11 (2 hits)Dockerfile:8
containersPinned dependencies
This page is publicly accessible at:
https://repobility.com/scan/6516291b-a7ba-402f-8700-eb9126778b1e/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/6516291b-a7ba-402f-8700-eb9126778b1e/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.