https://github.com/alibaba/open-code-review
· scanned 2026-07-23 19:36 UTC (4 days, 20 hours ago)
56 raw signals (0 security + 56 graph)
Last scanned 4 days, 20 hours ago · v3 · last Δ +0.3 (diff) · 53 actionable findings from 1 signal source. 3 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
Showing 49 of 53 actionable findings. 56 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
pages/src/components/MarkdownRenderer.tsx:171
Fq dangerous html
.claude/commands/open-code-review.md
VerificationClaude instruction
.claude/commands/tag.md
VerificationClaude instruction
plugins/open-code-review/skills/open-code-review-delegate/SKILL.md
VerificationSkill file
skills/open-code-review-delegate/SKILL.md
VerificationSkill file
plugins/open-code-review/skills/open-code-review-delegate/SKILL.md:11
Supply chainSkill file
plugins/open-code-review/skills/open-code-review/SKILL.md:13
Supply chainSkill file
skills/open-code-review-delegate/SKILL.md:11
Supply chainSkill file
skills/open-code-review/SKILL.md:13
Supply chainSkill file
extensions/vscode/src/extension/services/CliService.ts:35
SecurityJavascript
scripts/update.js:61
SecurityJavascript
examples/gerrit_ci/post_review.py:241
SecurityPythonNon production context
examples/gitflic_ci/post_review.py:341
SecurityPythonNon production context
repo-level (2 hits).github/workflows/release.yml:147
CI/CD securitySupply chainGithub actions
.github/workflows/deploy-pages.yml
CI/CD securitySupply chainGithub actions
.github/workflows/release.yml
CI/CD securitySupply chainGithub actions
pages/src/components/MarkdownRenderer.tsx:171
Dangerous innerhtml
pages/src/components/MarkdownRenderer.tsx:123
Direct innerhtml assignment
examples/gitflic_ci/post_review.py:378
runtime safetyRobustness
pages/src/components/MarkdownRenderer.tsx:171
SecurityReact
plugins/open-code-review/skills/open-code-review/SKILL.md:54
Mcp skillData exfilE1
skills/open-code-review/SKILL.md:49
Mcp skillData exfilE1
pages/package.json
ScaOsvGhsa 4vvj 4cpr p986
pages/package.json
ScaOsvGhsa f5vj f2hx 8m93
pages/package.json
ScaOsvGhsa m28w 2pqf 7qgj
pages/package.json
ScaOsvGhsa mx8g 39q3 5c79
pages/package.json
FreshnessOutdated
pages/package.json
FreshnessOutdated
pages/package.json
FreshnessOutdated
.github/workflows/deploy-pages.yml:61.github/workflows/ocr-review.yml:48.github/workflows/vscode-ext.yml:33package.json
LockfileReproducibilityGenerated repo pattern
pages/package.json
LockfileReproducibilityGenerated repo pattern
package.json
CI/CD securitySupply chainNpm
examples/gerrit_ci/post_review.py:316
pages/package.json
ScaOsvGhsa 4x5r pxfx 6jf8
pages/package.json
ScaOsvGhsa c2j3 45gr mqc4
pages/package.json
ScaOsvGhsa 38r7 794h 5758
pages/package.json
ScaOsvGhsa 8fgc 7cc6 rx7x
This page is publicly accessible at:
https://repobility.com/scan/7a95775b-2115-4cb8-8ad8-5f2b7f7a74f6/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/7a95775b-2115-4cb8-8ad8-5f2b7f7a74f6/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.