https://github.com/aquasecurity/trivy
· scanned 2026-06-04 04:11 UTC (1 day, 3 hours ago)
· 10 languages
259 findings (135 legacy + 124 scanner) 11/13 scanners ran 82nd percentile · Go · large (100-500K LoC) Scanner says 74 (higher by 14)
Last scanned 1 day, 3 hours ago · v2 · 197 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
88.0 | 0.15 | 13.20 |
practices_score |
86.0 | 0.15 | 12.90 |
code_quality |
75.0 | 0.10 | 7.50 |
| Overall | 1.00 | 88.3 |
Showing 97 of 197 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
pkg/iac/scanners/ansible/parser/template.go:58
qualitylegacy
.github/workflows/publish-chart.yaml:70
dependencylegacy
.github/workflows/publish-chart.yaml:71
dependencylegacy
pkg/fanal/analyzer/pkg/apk/apk.go:227
qualitylegacy
pkg/digest/digest.go:4
qualitylegacy
pkg/dependency/parser/java/jar/sonatype/sonatype.go:109
qualitylegacy
pkg/iac/scanners/cloudformation/parser/parser.go:88
qualitylegacy
pkg/iac/scanners/ansible/parser/template.go:71
qualitylegacy
Dockerfile.canary:1
dependencylegacy
Dockerfile:1
dependencylegacy
pkg/fanal/analyzer/secret/secret.go:98
resource_exhaustionlegacy
pkg/fanal/analyzer/imgconf/dockerfile/dockerfile.go:1
dockerlegacy
pkg/fanal/analyzer/config/dockerfile/docker.go:1
dockerlegacy
pkg/fanal/analyzer/buildinfo/dockerfile.go:1
dockerlegacy
pkg/plugin/plugin.go:71
qualitylegacy
pkg/fanal/analyzer/sbom/sbom.go:57
path_traversallegacy
pkg/fanal/analyzer/language/java/pom/pom.go:27
path_traversallegacy
pkg/x/http/trace.go:191
authlegacy
rpc/cache/service.twirp.go:1180
authlegacy
rpc/cache/service.twirp.go:1169
authlegacy
pkg/iac/scanners/terraform/parser/evaluator.go:250
authlegacy
pkg/rpc/server/listen.go:67
qualitylegacy
.dockerignore
dockerlegacy
docs/build/Dockerfile:1
dockerlegacy
Dockerfile.canary:1
dockerlegacy
Dockerfile:1
dockerlegacy
docs/tutorials/integrations/circleci.md:19
dependencylegacy
docs/guide/advanced/container/embed-in-dockerfile.md:12
dependencylegacy
contrib/Trivy.gitlab-ci.yml:15
dependencylegacy
.github/workflows/reusable-release.yaml
supply-chaingithub-actionsleast-privilege
pkg/dependency/parser/java/jar/parse.go:129
owaspweak_hash
pkg/digest/digest.go:23
owaspweak_hash
pkg/fanal/analyzer/pkg/apk/apk.go:227
owaspweak_hash
pkg/sbom/cyclonedx/marshal.go:279
owaspweak_hash
pkg/sbom/cyclonedx/unmarshal.go:267
owaspweak_hash
pkg/sbom/spdx/marshal.go:517
owaspweak_hash
pkg/sbom/spdx/unmarshal.go:257
owaspweak_hash
contrib/install.sh
securityports
.dockerignore
dockerlegacy
pkg/dependency/parser/java/pom/pom.go:343
error_handlinglegacy
pkg/dependency/parser/golang/binary/parse.go:64
error_handlinglegacy
pkg/cache/client.go:72
error_handlinglegacy
pkg/fanal/analyzer/imgconf/dockerfile/dockerfile.go:1
dockerlegacy
pkg/fanal/analyzer/config/dockerfile/docker.go:1
dockerlegacy
pkg/fanal/analyzer/buildinfo/dockerfile.go:1
dockerlegacy
docs/build/Dockerfile:6
dockerlegacy
pkg/fanal/analyzer/os/redhatbase/rocky.go:1
qualitylegacy
pkg/fanal/analyzer/os/redhatbase/oracle.go:1
qualitylegacy
pkg/fanal/analyzer/os/redhatbase/fedora.go:1
qualitylegacy
pkg/fanal/analyzer/os/redhatbase/centos.go:1
qualitylegacy
pkg/fanal/analyzer/language/java/gradle/pom.go:43
qualitylegacy
pkg/fanal/analyzer/language/java/gradle/lockfile.go:74
qualitylegacy
pkg/detector/ospkg/wolfi/wolfi.go:41
qualitylegacy
pkg/detector/ospkg/wolfi/wolfi.go:35
qualitylegacy
pkg/detector/ospkg/suse/suse.go:114
qualitylegacy
pkg/detector/ospkg/suse/suse.go:110
qualitylegacy
pkg/detector/ospkg/seal/seal.go:89
qualitylegacy
pkg/detector/ospkg/rocky/rocky.go:43
qualitylegacy
pkg/detector/ospkg/redhat/redhat.go:143
qualitylegacy
pkg/detector/ospkg/photon/photon.go:47
qualitylegacy
pkg/detector/ospkg/minimos/minimos.go:41
qualitylegacy
pkg/detector/ospkg/coreos/coreos.go:2
qualitylegacy
pkg/dependency/parser/rust/cargo/naive_pkg_parser.go:14
qualitylegacy
Dockerfile:1
supply-chaindockerpinned-dependencies
pkg/sbom/sbom.go:98
qualitylegacy
pkg/fanal/image/daemon/podman.go:20
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/6d822e81-bd19-495a-8800-a4180542b150/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/6d822e81-bd19-495a-8800-a4180542b150/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.