Scan timing: clone 1.19s · analysis 2.78s · 0.3 MB · GitHub API rate-limit (preflight)
https://github.com/quay/mirror-registry
· scanned 2026-06-05 19:15 UTC (4 days, 16 hours ago)
· 10 languages
74 raw signals (34 security + 40 graph) 29th percentile · Go · tiny (<2K LoC)
Last scanned 4 days, 16 hours ago · v2 · 35 actionable findings from 2 signal sources. 19 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
75.0 | 0.15 | 11.25 |
security_score |
35.4 | 0.25 | 8.85 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
61.0 | 0.15 | 9.15 |
practices_score |
87.0 | 0.15 | 13.05 |
code_quality |
78.8 | 0.10 | 7.88 |
| Overall | 1.00 | 67.2 |
Showing 29 of 35 actionable findings. 54 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.env
.env
ansible-runner/context/app/project/roles/mirror_appliance/tasks/secret-vars.yaml:5
ansible-runner/context/app/project/roles/mirror_appliance/tasks/upgrade-config-vars.yaml:16, 26 (2 hits)Dockerfile:11, 77, 84, 111 (4 hits)Dockerfile.online:6, 67, 73, 88 (4 hits).github/workflows/pr-check.yml:41 (2 hits).github/workflows/pr-check.yml:22, 27 (4 hits)go.mod
go.mod
go.mod
go.mod
go.mod
.github/workflows/jobs.yml
CI/CD securitySupply chainGithub actions
Dockerfile.online:88
CI/CD securitycontainers
Dockerfile:111
CI/CD securitycontainers
Dockerfile:11, 84, 111 (3 hits)Dockerfile.online:6, 73, 88 (3 hits)Dockerfile.online:24
CI/CD securitycontainers
Dockerfile:29
CI/CD securitycontainers
Dockerfile:77
containersPinned dependencies
Dockerfile:11, 84, 111 (3 hits).github/workflows/pr-check.yml
CI/CD securitySupply chainGithub actions
.github/workflows/jobs.yml
CI/CD securitySupply chainGithub actions
.dockerignore
CI/CD securitycontainers
cmd/upgrade.go:49
duplicationquality
AGENTS.md:1
This page is publicly accessible at:
https://repobility.com/scan/6f2fb54f-3a0d-4b92-b3eb-ca3ad796244d/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/6f2fb54f-3a0d-4b92-b3eb-ca3ad796244d/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.