Scan timing: clone 2.1s · analysis 40.89s · 10.3 MB · GitHub API rate-limit (preflight)
https://github.com/eclipse-sw360/sw360
· scanned 2026-06-05 14:53 UTC (5 days, 3 hours ago)
· 10 languages
274 raw signals (78 security + 196 graph) 14th percentile · Java · large (100-500K LoC) System graph score 70 (lower by 4)
Last scanned 5 days, 3 hours ago · v2 · 129 actionable findings from 2 signal sources. 44 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
26.9 | 0.25 | 6.72 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
96.0 | 0.15 | 14.40 |
practices_score |
89.0 | 0.15 | 13.35 |
code_quality |
66.5 | 0.10 | 6.65 |
| Overall | 1.00 | 66.1 |
Showing 108 of 129 actionable findings. 173 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
config/couchdb/sw360_setup.ini:9
rest/resource-server/src/docs/asciidoc/api-guide.adoc:142
rest/resource-server/src/docs/asciidoc/api-guide.adoc:161
clients/client/src/main/java/org/eclipse/sw360/clients/rest/resource/SW360Attributes.java:35
backend/licenseinfo/src/main/java/org/eclipse/sw360/licenseinfo/parsers/AbstractCLIParser.java:116
docker-compose.yml:35
CI/CD securitycontainers
docker-compose.yml:35, 43 (2 hits)keycloak/sw360-keycloak-common/pom.xml
libraries/exporters/src/main/java/org/eclipse/sw360/exporter/utils/ZipTools.java:52
docker-compose.yml:10
CI/CD securitycontainers
scripts/migrations/053_remove_whitespace_component_name.py:206scripts/migrations/062_update_packagIds_to_map.py:44scripts/migrations/063_migrate_oauth_client_owner_email.py:189scripts/migrations/064_migrate_unified_mail_export_config_key.py:70third-party/keycloak-tf/export_clients.py:46docker-compose.yml:43
CI/CD securitycontainers
docker-compose.yml:35
CI/CD securitycontainers
.github/workflows/scorecard.yml.github/workflows/sw360_container.yml.github/workflows/thrift_container.ymlbackend/fossology/src/main/java/org/eclipse/sw360/fossology/rest/FossologyRestClient.java:735
Weak hash
Dockerfile
Ports
Dockerfile
Ports
third-party/thrift/Dockerfile
Ports
.dockerignore
CI/CD securitycontainers
docker-compose.yml:43
CI/CD securitycontainers
docker-compose.yml:10, 35, 43 (3 hits)docker-compose.yml:10, 35, 43 (3 hits)Dockerfile:28
CI/CD securitycontainers
backend/common/src/main/java/org/eclipse/sw360/datahandler/db/spdx/packageinfo/SpdxPackageInfoDatabaseHandler.java:243, 244 (2 hits)libraries/datahandler/src/main/java/org/eclipse/sw360/datahandler/permissions/ReleasePermissions.java:49, 56 (2 hits)libraries/datahandler/src/main/java/org/eclipse/sw360/datahandler/permissions/SpdxDocumentPermissions.java:21, 26 (2 hits)libraries/datahandler/src/main/java/org/eclipse/sw360/datahandler/permissions/SpdxPackageInfoPermissions.java:22, 26 (2 hits)libraries/datahandler/src/main/java/org/eclipse/sw360/datahandler/permissions/VulnerabilityPermissions.java:18, 22 (2 hits)backend/common/src/main/java/org/eclipse/sw360/datahandler/db/ProjectRepository.java:210backend/common/src/main/java/org/eclipse/sw360/datahandler/db/ReleaseRepository.java:72backend/common/src/main/java/org/eclipse/sw360/datahandler/db/spdx/documentcreationinfo/SpdxDocumentCreationInfoDatabaseHandler.java:174
This page is publicly accessible at:
https://repobility.com/scan/7f6605cc-6a16-4dff-84b8-571aaccfc3aa/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/7f6605cc-6a16-4dff-84b8-571aaccfc3aa/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.