Scan timing: clone 1.84s · analysis 27.25s · 1.6 MB · GitHub API rate-limit (preflight)
https://github.com/coder/code-server
· scanned 2026-06-05 07:33 UTC (5 days, 21 hours ago)
· 10 languages
274 raw signals (82 security + 192 graph) 57th percentile · Typescript · small (2-20K LoC) System graph score 55 (higher by 15)
Last scanned 5 days, 21 hours ago · v2 · 154 actionable findings from 2 signal sources. 24 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
100.0 | 0.15 | 15.00 |
security_score |
47.5 | 0.25 | 11.88 |
testing_score |
90.0 | 0.20 | 18.00 |
documentation_score |
33.6 | 0.15 | 5.04 |
practices_score |
89.0 | 0.15 | 13.35 |
code_quality |
66.0 | 0.10 | 6.60 |
| Overall | 1.00 | 69.9 |
Showing 110 of 154 actionable findings. 178 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/node/routes/vscode.ts:66
src/node/main.ts:62
test/unit/node/util.test.ts:200, 242, 256, 300, 301, 309 (6 hits)test/utils/constants.ts:1.github/workflows/build.yaml:150, 156, 197 (3 hits)src/node/cli.ts:14
src/node/routes/vscode.ts:213
.github/workflows/installer.yaml:44
.github/workflows/scripts.yaml:41
src/node/main.ts:62
Eval used
src/node/routes/vscode.ts:66
Eval used
src/node/routes/health.ts:6
src/node/routes/update.ts:7
src/node/update.ts:79
package-lock.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
ci/helm-chart/values.yaml:150docs/README.md:46docs/android.md:10docs/coder.md:14docs/install.md:42docs/ios.md:7install.sh:10src/browser/robots.txt
.github/workflows/release.yaml
CI/CD securitySupply chainGithub actions
.dockerignore
CI/CD securitycontainers
ci/release-image/Dockerfile:9
CI/CD securitycontainers
package.json
package.json
package.json
src/browser/robots.txt
package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/8618e285-16c4-4629-8ab9-901d19f88409/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/8618e285-16c4-4629-8ab9-901d19f88409/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.