https://github.com/aquasecurity/trivy
· scanned 2026-06-04 04:11 UTC (1 day, 12 hours ago)
· 10 languages
259 findings (135 legacy + 124 scanner) 11/13 scanners ran 70th percentile · Go · large (100-500K LoC) Scanner says 74 (higher by 14)
Last scanned 1 day, 12 hours ago · v2 · 197 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
88.0 | 0.15 | 13.20 |
practices_score |
86.0 | 0.15 | 12.90 |
code_quality |
75.0 | 0.10 | 7.50 |
| Overall | 1.00 | 88.3 |
Showing 20 of 197 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
pkg/rpc/server/listen.go:67
qualitylegacy
.dockerignore
dockerlegacy
.github/workflows/reusable-release.yaml
supply-chaingithub-actionsleast-privilege
pkg/dependency/parser/java/jar/parse.go:129
owaspweak_hash
pkg/digest/digest.go:23
owaspweak_hash
pkg/fanal/analyzer/pkg/apk/apk.go:227
owaspweak_hash
pkg/sbom/cyclonedx/marshal.go:279
owaspweak_hash
pkg/sbom/cyclonedx/unmarshal.go:267
owaspweak_hash
pkg/sbom/spdx/marshal.go:517
owaspweak_hash
pkg/sbom/spdx/unmarshal.go:257
owaspweak_hash
contrib/install.sh
securityports
This page is publicly accessible at:
https://repobility.com/scan/6d822e81-bd19-495a-8800-a4180542b150/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/6d822e81-bd19-495a-8800-a4180542b150/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.