https://github.com/xsantcastx/VarsityHubMobile
· scanned 2026-06-16 01:03 UTC (2 months, 1 week ago)
533 raw signals (0 security + 533 graph)
Last scanned 2 months, 1 week ago · v1 · 451 actionable findings from 1 signal source. 82 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
Showing 355 of 451 actionable findings. 533 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
scripts/prod-cross-system-e2e.sh:17, 18 (2 hits)server/scripts/admin-e2e-audit.ts:191, 387 (2 hits)server/scripts/cross-role-e2e-audit.ts:150, 173 (2 hits)server/scripts/e2e/README.md:69
server/scripts/load/p0-load-smoke.ts:34
server/scripts/ux-verification-final.ts:62, 71, 99 (3 hits)server/scripts/verify-ad-approval-flow.ts:48
server/scripts/verify-ad-dashboard-review-flow.ts:46
server/scripts/verify-admin-tools.ts:11
server/scripts/verify-app-review-account.ts:56
server/scripts/verify-coach-creating-flow.ts:23
server/scripts/verify-coach-flow.ts:27
server/scripts/verify-event-approval-flow.ts:51
server/scripts/verify-fan-flow.ts:20
server/scripts/verify-full-regression.ts:14
server/scripts/verify-guard-bypass.ts:16
server/scripts/verify-identity-uniqueness.ts:15
server/scripts/verify-onboarding-persistence.ts:14
server/scripts/verify-org-manager-access.ts:202, 248 (2 hits)server/scripts/verify-polling-approval.ts:26
server/scripts/verify-profile-team-security.ts:14
server/scripts/verify-push-token-registration.ts:16
server/scripts/verify-session-enforcement.ts:6, 7 (2 hits)server/scripts/verify-session-isolation.ts:15, 135 (2 hits).github/workflows/snyk-security.yml:71, 168 (2 hits).claude/commands/summary.md
VerificationClaude instruction
.cursor/settings.json
VerificationCursor rule
.github/workflows/snyk-security.yml:105, 112 (2 hits).github/workflows/auto-changelog.yml:147.github/workflows/secret-scan.yml:26.github/workflows/snyk-auto-remediate.yml:85.github/workflows/snyk-auto-remediate.yml
CI/CD securitySupply chainGithub actions
.github/workflows/auto-changelog.yml
CI/CD securitySupply chainGithub actions
server/mock-server.js:7
Cors wildcard
.github/workflows/auto-changelog.yml:40
Node child process
scripts/check-async-handler-usage.js:3
Node child process
scripts/check-error-envelope-usage.js:3
Node child process
scripts/check-secret-literals.js:3
Node child process
scripts/check-user-cache-invalidation.js:3
Node child process
scripts/ensure-server-prisma-client.js:3
Node child process
scripts/repeat-command.js:3
Node child process
scripts/run-with-retry.js:3
Node child process
server/scripts/lib/railwayVerificationEnv.ts:1
Node child process
server/scripts/load/validate-distributed-lock.ts:12
Node child process
scripts/beta-deploy.sh
Ports
scripts/prod-cross-system-e2e.sh
Ports
scripts/moved-from-root/OVERNIGHT_SUMMARY.sh
Ports
scripts/moved-from-root/OVERNIGHT_SUMMARY.sh
Ports
scripts/moved-from-root/OVERNIGHT_SUMMARY.sh
Ports
server/Dockerfile
Ports
server/Dockerfile
Ports
server/Dockerfile:3, 22 (2 hits).github/workflows/ci.yml:20, 30, 35, 62, 67, 95, 98, 114, +12 more (20 hits).github/workflows/npm-audit.yml:32, 81, 98 (3 hits).github/workflows/production-e2e.yml:37, 53, 298 (3 hits).github/workflows/snyk-security.yml:48, 51, 154 (3 hits).github/workflows/verify-production-ready.yml:13, 16, 36 (3 hits).github/workflows/environment-audit-consolidated.yml:177, 229 (2 hits).github/workflows/expo-doctor.yml:20, 23 (2 hits).github/workflows/nightly-build-health.yml:21, 117 (2 hits)server/src/routes/ads.ts:1387
Document write
package.json
CI/CD securitySupply chainNpm
server/package.json
CI/CD securitySupply chainNpm
Showing first 300 of 355. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/67ef2bee-0036-4674-b1fe-cebd1cb3cc5a/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/67ef2bee-0036-4674-b1fe-cebd1cb3cc5a/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.