Scan timing: clone 14.31s · analysis 17.12s · 81.9 MB · GitHub API rate-limit (preflight)
https://github.com/ethereum/go-ethereum
· scanned 2026-06-05 11:41 UTC (5 days, 10 hours ago)
· 10 languages
342 raw signals (118 security + 224 graph) 11/13 scanners ran 67th percentile · Go · large (100-500K LoC) System graph score 67 (higher by 18)
Last scanned 5 days, 10 hours ago · v2 · 124 actionable findings from 2 signal sources. 106 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
60.0 | 0.15 | 9.00 |
practices_score |
99.0 | 0.15 | 14.85 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 85.6 |
Showing 94 of 124 actionable findings. 230 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
graphql/internal/graphiql/graphiql.min.js:2
cmd/utils/prompt.go:33, 38 (2 hits)Dockerfile:7, 20 (2 hits)Dockerfile.alltools:7, 27 (2 hits)crypto/secp256k1/libsecp256k1/ci/linux-debian.Dockerfile:1crypto/secp256k1/libsecp256k1/.github/workflows/ci.yml:856
p2p/dnsdisc/sync.go:21
crypto/signify/signify_fuzz.go:88
crypto/secp256k1/libsecp256k1/.github/workflows/ci.yml:101, 152, 198, 251, 308, 355, 410, 467, +10 more (35 hits).github/workflows/go.yml:20, 31, 52, 70, 98, 129 (6 hits).github/workflows/validate_pr.yml:12, 51, 54 (6 hits).github/workflows/freebsd.yml:13crypto/secp256k1/libsecp256k1/.github/workflows/ci.yml:52, 59, 783 (4 hits).github/workflows/freebsd.yml:19 (2 hits)cmd/workload/filtertest.go:161cmd/workload/historytest.go:60cmd/workload/prooftest.go:65Dockerfile.alltools:27
CI/CD securitycontainers
Dockerfile:20
CI/CD securitycontainers
Dockerfile.alltools:27
CI/CD securitycontainers
Dockerfile:20
CI/CD securitycontainers
Dockerfile:20
containersPinned dependencies
graphql/internal/graphiql/graphiql.min.js:2
Dangerous innerhtml
graphql/internal/graphiql/react-dom.production.min.js:26
Dangerous innerhtml
internal/jsre/deps/web3.js:8607
Weak hash
.dockerignore
CI/CD securitycontainers
cmd/devp2p/discv4cmd.go:305cmd/devp2p/internal/ethtest/chain.go:197cmd/devp2p/internal/ethtest/engine.go:58accounts/abi/bind/v2/internal/contracts/solc_errors/bindings.go:2, 8, 102 (3 hits)common/fdlimit/fdlimit_unix.go:3, 19 (2 hits)core/types/tx_setcode.go:117, 118 (2 hits)accounts/abi/bind/v2/auth.go:20accounts/abi/bind/v2/base.go:59accounts/abi/bind/v2/internal/contracts/events/bindings.go:2accounts/abi/bind/v2/internal/contracts/nested_libraries/bindings.go:2accounts/abi/bind/v2/internal/contracts/uint256arrayreturn/bindings.go:2build:1
Dockerfile:7
containersPinned dependencies
This page is publicly accessible at:
https://repobility.com/scan/883bffd4-e24a-4bed-a8ca-09ff79b781d0/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/883bffd4-e24a-4bed-a8ca-09ff79b781d0/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.