Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

alibaba/open-code-review

https://github.com/alibaba/open-code-review · scanned 2026-07-23 19:36 UTC (4 days, 21 hours ago)

56 raw signals (0 security + 56 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 4 days, 21 hours ago · v3 · last Δ +0.3 (diff) · 53 actionable findings from 1 signal source. 3 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: excluding tests × Reset all

All 1186 nodes from the latest scan, grouped by kind. Each node is a unit the engine identified (file, function, endpoint, table…). Most users won't need this view — it's primarily for debugging the engine's graph extraction or for AI agents that want to enumerate the project structure.

LabelLayerStatusPath
action.yml software healthy action.yml
README.zh-CN.md software healthy README.zh-CN.md
ASSURANCE_CASE.md software healthy ASSURANCE_CASE.md
CONTRIBUTING.ru-RU.md software healthy CONTRIBUTING.ru-RU.md
CONTRIBUTING.ja-JP.md software healthy CONTRIBUTING.ja-JP.md
README.md software healthy README.md
install.sh software healthy install.sh
package.json software healthy package.json
CONTRIBUTING.md software healthy CONTRIBUTING.md
GOVERNANCE.md software healthy GOVERNANCE.md
CONTRIBUTING.zh-CN.md software healthy CONTRIBUTING.zh-CN.md
README.ja-JP.md software healthy README.ja-JP.md
README.ru-RU.md software healthy README.ru-RU.md
ROADMAP.md software healthy ROADMAP.md
go.mod software healthy go.mod
Makefile software healthy Makefile
CONTRIBUTING.ko-KR.md software healthy CONTRIBUTING.ko-KR.md
LICENSE software healthy LICENSE
CODE_OF_CONDUCT.md software healthy CODE_OF_CONDUCT.md
README.ko-KR.md software healthy README.ko-KR.md
SECURITY.md software healthy SECURITY.md
system_rules.go software healthy internal/config/rules/system_rules.go
system_rules_test.go software healthy internal/config/rules/system_rules_test.go
system_rules.json software healthy internal/config/rules/system_rules.json
resolve_github_test.go software healthy internal/config/rules/resolve_github_test.go
build_gradle.md software healthy internal/config/rules/rule_docs/build_gradle.md
github_config.md software healthy internal/config/rules/rule_docs/github_config.md
pot.md software healthy internal/config/rules/rule_docs/pot.md
json.md software healthy internal/config/rules/rule_docs/json.md
astro.md software healthy internal/config/rules/rule_docs/astro.md
cpp.md software healthy internal/config/rules/rule_docs/cpp.md
c.md software healthy internal/config/rules/rule_docs/c.md
github_workflows.md software healthy internal/config/rules/rule_docs/github_workflows.md
freemarker.md software healthy internal/config/rules/rule_docs/freemarker.md
rust.md software healthy internal/config/rules/rule_docs/rust.md
package_json.md software healthy internal/config/rules/rule_docs/package_json.md
ts_js_tsx_jsx.md software healthy internal/config/rules/rule_docs/ts_js_tsx_jsx.md
kotlin.md software healthy internal/config/rules/rule_docs/kotlin.md
default.md software healthy internal/config/rules/rule_docs/default.md
cargo_toml.md software healthy internal/config/rules/rule_docs/cargo_toml.md
java.md software healthy internal/config/rules/rule_docs/java.md
po.md software healthy internal/config/rules/rule_docs/po.md
pom_xml.md software healthy internal/config/rules/rule_docs/pom_xml.md
python.md software healthy internal/config/rules/rule_docs/python.md
yaml.md software healthy internal/config/rules/rule_docs/yaml.md
mapper_dao_xml.md software healthy internal/config/rules/rule_docs/mapper_dao_xml.md
arkts.md software healthy internal/config/rules/rule_docs/arkts.md
properties.md software healthy internal/config/rules/rule_docs/properties.md
allowed_ext_test.go software healthy internal/config/allowlist/allowed_ext_test.go
default_exclude_patterns.json software healthy internal/config/allowlist/default_exclude_patterns.json

Showing first 50 of this kind. Full payload available via the JSON button at the top of the page.

LabelLayerStatusPath
getPlatformPackageName software healthy scripts/platform.js:getPlatformPackageName
resolveNativeBinary software healthy scripts/platform.js:resolveNativeBinary
touchTimestamp software healthy scripts/update.js:touchTimestamp
acquireLock software healthy scripts/update.js:acquireLock
releaseLock software healthy scripts/update.js:releaseLock
getInstalledVersion software healthy scripts/update.js:getInstalledVersion
match software healthy scripts/update.js:match
fetchLatestVersion software healthy scripts/update.js:fetchLatestVersion
registry software healthy scripts/update.js:registry
semverGt software healthy scripts/update.js:semverGt
writeHint software healthy scripts/update.js:writeHint
removeHint software healthy scripts/update.js:removeHint
main software healthy scripts/update.js:main
info software healthy scripts/install.js:info
warn software healthy scripts/install.js:warn
error software healthy scripts/install.js:error
detectPlatform software healthy scripts/install.js:detectPlatform
loadPackageJson software healthy scripts/install.js:loadPackageJson
resolveVersion software healthy scripts/install.js:resolveVersion
buildUrl software healthy scripts/install.js:buildUrl
download software healthy scripts/install.js:download
downloadText software healthy scripts/install.js:downloadText
downloadBinary software healthy scripts/install.js:downloadBinary
computeChecksum software healthy scripts/install.js:computeChecksum
main software healthy scripts/install.js:main
extractHeadings software healthy scripts/github-actions/check-translation-sync.js:extractHea…
level2Headings software healthy scripts/github-actions/check-translation-sync.js:level2Head…
structuralSignature software healthy scripts/github-actions/check-translation-sync.js:structural…
sameSequence software healthy scripts/github-actions/check-translation-sync.js:sameSequen…
firstDiffIndex software healthy scripts/github-actions/check-translation-sync.js:firstDiffI…
describeHeading software healthy scripts/github-actions/check-translation-sync.js:describeHe…
compareReadmeStructures software healthy scripts/github-actions/check-translation-sync.js:compareRea…
counterpartPaths software healthy scripts/github-actions/check-translation-sync.js:counterpar…
findMissingTranslations software healthy scripts/github-actions/check-translation-sync.js:findMissin…
emitError software healthy scripts/github-actions/check-translation-sync.js:emitError
emitWarning software healthy scripts/github-actions/check-translation-sync.js:emitWarning
splitList software healthy scripts/github-actions/check-translation-sync.js:splitList
getChangedFiles software healthy scripts/github-actions/check-translation-sync.js:getChanged…
writeStepSummary software healthy scripts/github-actions/check-translation-sync.js:writeStepS…
runReadmeCheck software healthy scripts/github-actions/check-translation-sync.js:runReadmeC…
runDocsCheck software healthy scripts/github-actions/check-translation-sync.js:runDocsChe…
main software healthy scripts/github-actions/check-translation-sync.js:main
mode software healthy scripts/github-actions/check-translation-sync.js:mode
runPostReviewComments software healthy scripts/github-actions/post-review-comments.js:runPostRevie…
log software healthy scripts/github-actions/post-review-comments.js:log
out software healthy scripts/github-actions/post-review-comments.js:out
wrapSummary software healthy scripts/github-actions/post-review-comments.js:wrapSummary
secs software healthy scripts/github-actions/post-review-comments.js:secs
batchMaybeReachedServer software healthy scripts/github-actions/post-review-comments.js:batchMaybeRe…
maybeReachedServer software healthy scripts/github-actions/post-review-comments.js:maybeReached…

Showing first 50 of this kind. Full payload available via the JSON button at the top of the page.

LabelLayerStatusPath
internal software healthy internal
config software healthy internal/config
rules software healthy internal/config/rules
rule_docs software healthy internal/config/rules/rule_docs
allowlist software healthy internal/config/allowlist
template software healthy internal/config/template
prompts software healthy internal/config/template/prompts
toolsconfig software healthy internal/config/toolsconfig
testconnection software healthy internal/config/testconnection
pathutil software healthy internal/pathutil
mcp software healthy internal/mcp
agent software healthy internal/agent
viewer software healthy internal/viewer
static software healthy internal/viewer/static
templates software healthy internal/viewer/templates
delegate software healthy internal/delegate
release software healthy internal/release
llmloop software healthy internal/llmloop
gitcmd software healthy internal/gitcmd
tool software healthy internal/tool
scan software healthy internal/scan
model software healthy internal/model
stdout software healthy internal/stdout
diff software healthy internal/diff
session software healthy internal/session
suggestdiff software healthy internal/suggestdiff
telemetry software healthy internal/telemetry
llm software healthy internal/llm
scripts software healthy scripts
publish software healthy scripts/publish
github-actions software healthy scripts/github-actions
cmd software healthy cmd
opencodereview software healthy cmd/opencodereview
npm software healthy npm
darwin-arm64 software healthy npm/darwin-arm64
win32-arm64 software healthy npm/win32-arm64
darwin-x64 software healthy npm/darwin-x64
linux-arm64 software healthy npm/linux-arm64
win32-x64 software healthy npm/win32-x64
linux-x64 software healthy npm/linux-x64
extensions software healthy extensions
vscode software healthy extensions/vscode
__mocks__ software healthy extensions/vscode/__mocks__
src software healthy extensions/vscode/src
webview software healthy extensions/vscode/src/webview
__tests__ software healthy extensions/vscode/src/webview/__tests__
components software healthy extensions/vscode/src/webview/components
styles software healthy extensions/vscode/src/webview/styles
views software healthy extensions/vscode/src/webview/views
shared software healthy extensions/vscode/src/shared

Showing first 50 of this kind. Full payload available via the JSON button at the top of the page.

LabelLayerStatusPath
preact@^10.29.7 dependencies healthy extensions/vscode/package.json
@types/jest@^30.0.0 dependencies healthy extensions/vscode/package.json
@types/node@^18.0.0 dependencies healthy extensions/vscode/package.json
@types/vscode@^1.74.0 dependencies healthy extensions/vscode/package.json
@typescript-eslint/eslint-plugin@^6.18.0 dependencies healthy extensions/vscode/package.json
@typescript-eslint/parser@^6.18.0 dependencies healthy extensions/vscode/package.json
@vscode/vsce@^3.0.0 dependencies healthy extensions/vscode/package.json
css-loader@^7.1.4 dependencies healthy extensions/vscode/package.json
eslint@^8.56.0 dependencies healthy extensions/vscode/package.json
jest@^30.4.2 dependencies healthy extensions/vscode/package.json
style-loader@^4.0.0 dependencies healthy extensions/vscode/package.json
ts-jest@^29.4.12 dependencies healthy extensions/vscode/package.json
ts-loader@^9.5.0 dependencies healthy extensions/vscode/package.json
typescript@^5.3.0 dependencies healthy extensions/vscode/package.json
webpack@^5.108.4 dependencies healthy extensions/vscode/package.json
webpack-cli@^7.2.1 dependencies healthy extensions/vscode/package.json
@agentscope-ai/icons@^1.0.68 dependencies healthy pages/package.json
dompurify@^3.4.11 dependencies healthy pages/package.json
marked@^18.0.5 dependencies healthy pages/package.json
mermaid@^11.16.0 dependencies healthy pages/package.json
react@^18.2.0 dependencies healthy pages/package.json
react-dom@^18.2.0 dependencies healthy pages/package.json
react-router-dom@^6.8.0 dependencies healthy pages/package.json
three@^0.185.0 dependencies healthy pages/package.json
@babel/core@^7.23.5 dependencies healthy pages/package.json
@babel/preset-env@^7.29.5 dependencies healthy pages/package.json
@babel/preset-react@^7.23.5 dependencies healthy pages/package.json
@babel/preset-typescript@^7.23.3 dependencies healthy pages/package.json
@types/dompurify@^3.0.5 dependencies healthy pages/package.json
@types/react@^18.2.0 dependencies healthy pages/package.json
@types/react-dom@^18.2.0 dependencies healthy pages/package.json
@types/three@^0.185.0 dependencies healthy pages/package.json
autoprefixer@^10.4.16 dependencies healthy pages/package.json
babel-loader@^9.1.3 dependencies healthy pages/package.json
copy-webpack-plugin@^14.0.0 dependencies healthy pages/package.json
css-loader@^6.8.1 dependencies healthy pages/package.json
html-webpack-plugin@^5.5.3 dependencies healthy pages/package.json
postcss@^8.5.15 dependencies healthy pages/package.json
postcss-loader@^7.3.3 dependencies healthy pages/package.json
style-loader@^3.3.3 dependencies healthy pages/package.json
tailwindcss@^3.3.5 dependencies healthy pages/package.json
typescript@^5.3.2 dependencies healthy pages/package.json
webpack@^5.89.0 dependencies healthy pages/package.json
webpack-cli@^5.1.4 dependencies healthy pages/package.json
webpack-dev-server@^5.2.4 dependencies healthy pages/package.json

LabelLayerStatusPath
SidebarProvider software healthy extensions/vscode/src/extension/providers/SidebarProvider.t…
ConfigPanelProvider software healthy extensions/vscode/src/extension/providers/ConfigPanelProvid…
LineOffsetTracker software healthy extensions/vscode/src/extension/providers/lineOffset.ts:Lin…
CommentProvider software healthy extensions/vscode/src/extension/providers/CommentProvider.t…
GitService software healthy extensions/vscode/src/extension/services/GitService.ts:GitS…
CliService software healthy extensions/vscode/src/extension/services/CliService.ts:CliS…
ConfigService software healthy extensions/vscode/src/extension/services/ConfigService.ts:C…
ReviewSession software healthy extensions/vscode/src/extension/services/ReviewSession.ts:R…
BuildReviewInputTest software healthy examples/gerrit_ci/post_review_test.py:53
StripXssiTest software healthy examples/gerrit_ci/post_review_test.py:199
BuildEndpointTest software healthy examples/gerrit_ci/post_review_test.py:212
Recorder software healthy examples/gerrit_ci/post_review_test.py:277
PostTest software healthy examples/gerrit_ci/post_review_test.py:303
ParseArgsTest software healthy examples/gerrit_ci/post_review_test.py:495
FakeResponse software healthy examples/gerrit_ci/post_review_test.py:510
MakePosterTest software healthy examples/gerrit_ci/post_review_test.py:524
Hunk software healthy examples/gitflic_ci/post_review.py:57
FileDiff software healthy examples/gitflic_ci/post_review.py:70
OldLineForTest software healthy examples/gitflic_ci/post_review_test.py:64
ParseDiffTest software healthy examples/gitflic_ci/post_review_test.py:112
Recorder software healthy examples/gitflic_ci/post_review_test.py:137
PublishTest software healthy examples/gitflic_ci/post_review_test.py:157

LabelLayerStatusPath
App frontend healthy pages/src/App.tsx
MarkdownRenderer frontend healthy pages/src/components/MarkdownRenderer.tsx
UseCasesSection frontend healthy pages/src/components/UseCasesSection.tsx
FeaturesSection frontend healthy pages/src/components/FeaturesSection.tsx
QuickStartSection frontend healthy pages/src/components/QuickStartSection.tsx
FadeInSection frontend healthy pages/src/components/FadeInSection.tsx
LandingPage frontend healthy pages/src/components/LandingPage.tsx
BenchmarkSection frontend healthy pages/src/components/BenchmarkSection.tsx
WhySection frontend healthy pages/src/components/WhySection.tsx
Footer frontend healthy pages/src/components/Footer.tsx
ColorBends frontend healthy pages/src/components/ColorBends.tsx
HeroSection frontend healthy pages/src/components/HeroSection.tsx
HighlightsSection frontend healthy pages/src/components/HighlightsSection.tsx
Navbar frontend healthy pages/src/components/Navbar.tsx
OpenAIIcon frontend healthy pages/src/components/icons/OpenAIIcon.tsx
OcrIcon frontend healthy pages/src/components/icons/OcrIcon.tsx
ClaudeIcon frontend healthy pages/src/components/icons/ClaudeIcon.tsx
BenchmarkPage frontend healthy pages/src/pages/BenchmarkPage.tsx
QuickStartPage frontend healthy pages/src/pages/QuickStartPage.tsx
FeaturesPage frontend healthy pages/src/pages/FeaturesPage.tsx
DocsPage frontend healthy pages/src/pages/DocsPage.tsx
BlogPage frontend healthy pages/src/pages/BlogPage.tsx

LabelLayerStatusPath
192.168.1.5 network healthy internal/viewer/server_extra_test.go
127.0.0.1 network healthy internal/viewer/server.go
127.0.0.2 network healthy internal/viewer/hostguard_test.go
192.168.1.10 network healthy internal/viewer/hostguard_test.go
10.0.0.1 network healthy internal/viewer/hostguard_test.go
8.8.8.8 network healthy internal/viewer/hostguard_test.go
169.254.169.254 network healthy internal/viewer/hostguard_test.go
127.0.0.0 network healthy internal/viewer/hostguard.go
192.0.2.1 network healthy internal/telemetry/exporter_test.go
1.2.3.4 network healthy internal/llm/resolver.go
5.6.7.8 network healthy internal/llm/resolver.go
3.86.28.97 network healthy pages/src/components/icons/OcrIcon.tsx

LabelLayerStatusPath
/BenchmarkPage frontend healthy pages/src/pages/BenchmarkPage.tsx
/QuickStartPage frontend healthy pages/src/pages/QuickStartPage.tsx
/FeaturesPage frontend healthy pages/src/pages/FeaturesPage.tsx
/DocsPage frontend healthy pages/src/pages/DocsPage.tsx
/BlogPage frontend healthy pages/src/pages/BlogPage.tsx
/ frontend healthy pages/src/App.tsx
/benchmark frontend healthy pages/src/App.tsx
/quickstart frontend healthy pages/src/App.tsx
/docs frontend healthy pages/src/App.tsx
/docs/:slug frontend healthy pages/src/App.tsx
/blog frontend healthy pages/src/App.tsx
/blog/:slug frontend healthy pages/src/App.tsx

LabelLayerStatusPath
code-review cicd healthy .github/workflows/ocr-review.yml
check cicd healthy .github/workflows/vscode-ext.yml
check cicd healthy .github/workflows/pages-ci.yml
test cicd healthy .github/workflows/ci.yml
cross-compile cicd healthy .github/workflows/ci.yml
build cicd healthy .github/workflows/deploy-pages.yml
deploy cicd healthy .github/workflows/deploy-pages.yml
translation-sync cicd healthy .github/workflows/translation-sync.yml
build cicd healthy .github/workflows/release.yml
release cicd healthy .github/workflows/release.yml
npm-publish cicd healthy .github/workflows/release.yml

LabelLayerStatusPath
gha::ocr-review cicd healthy .github/workflows/ocr-review.yml
gha::vscode-ext cicd healthy .github/workflows/vscode-ext.yml
gha::pages-ci cicd healthy .github/workflows/pages-ci.yml
gha::ci cicd healthy .github/workflows/ci.yml
gha::deploy-pages cicd healthy .github/workflows/deploy-pages.yml
gha::translation-sync cicd healthy .github/workflows/translation-sync.yml
gha::release cicd healthy .github/workflows/release.yml
gitlab-ci cicd healthy examples/gitlab_ci/.gitlab-ci.yml

LabelLayerStatusPath
GITHUB_TOKEN cicd healthy
OCR_LLM_AUTH_TOKEN cicd healthy
OCR_LLM_MODEL cicd healthy
OCR_LLM_URL cicd healthy
NPM_TOKEN cicd healthy
OCR_LLM_USE_ANTHROPIC cicd healthy

LabelLayerStatusPath
auth::internal/llm/resolver_test.go security healthy internal/llm/resolver_test.go
auth::internal/llm/resolver.go security healthy internal/llm/resolver.go
auth::internal/llm/client_test.go security healthy internal/llm/client_test.go

LabelLayerStatusPath
generic_api_key::cmd/opencodereview/provider_tui_test.go security healthy cmd/opencodereview/provider_tui_test.go
password_literal::examples/gerrit_ci/post_review_test.py security healthy examples/gerrit_ci/post_review_test.py

LabelLayerStatusPath
repobility-clone-80chrt7x software healthy /tmp/repobility-clone-80chrt7x

LabelLayerStatusPath
port:3030 network healthy pages/webpack.config.js

LabelLayerStatusPath
vps::azure hardware healthy extensions/vscode/yarn.lock
For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/7a95775b-2115-4cb8-8ad8-5f2b7f7a74f6/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/7a95775b-2115-4cb8-8ad8-5f2b7f7a74f6/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.