Scan timing: clone 2.22s · analysis 3.32s · 6.7 MB · GitHub preflight 433ms
https://github.com/tukaani-project/xz.git
· scanned 2026-05-31 03:55 UTC (5 days, 7 hours ago)
· 10 languages
55 findings (31 legacy + 24 scanner) 75th percentile · C · medium (20-100K LoC) Scanner says 66 (higher by 3)
Last scanned 5 days, 7 hours ago · v3 · 39 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
80.0 | 0.15 | 12.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
40.0 | 0.20 | 8.00 |
documentation_score |
50.0 | 0.15 | 7.50 |
practices_score |
67.0 | 0.15 | 10.05 |
code_quality |
62.9 | 0.10 | 6.29 |
| Overall | 1.00 | 68.8 |
Showing 34 of 39 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
debug/translation.bash:53
secrets
.github/workflows/solaris.yml:20
dependencylegacy
.github/workflows/dragonflybsd.yml:20
dependencylegacy
.github/workflows/ci.yml:32
dependencylegacy
.github/workflows/haiku.yml:20
dependencylegacy
.github/workflows/msys2.yml:80
dependencylegacy
.github/workflows/freebsd.yml:37
dependencylegacy
.github/workflows/netbsd.yml:20
dependencylegacy
.github/workflows/msvc.yml:27
dependencylegacy
.github/workflows/openbsd.yml:20
dependencylegacy
.github/workflows/coverity.yml:15
dependencylegacy
.github/workflows/cifuzz.yml:51
dependencylegacy
.github/workflows/ci.yml:167
dependencylegacy
.github/workflows/msys2.yml:140
dependencylegacy
.github/workflows/cifuzz.yml:31
dependencylegacy
.github/workflows/cifuzz.yml:41
dependencylegacy
.github/workflows/cifuzz.yml:31
supply-chaingithub-actionspinned-dependencies
.github/workflows/cifuzz.yml:41
supply-chaingithub-actionspinned-dependencies
extra/7z2lzma/7z2lzma.bash
securityports
src/liblzma/lz/lz_encoder_hash_table.h:2
qualitylegacy
src/liblzma/common/stream_decoder_mt.c:423
qualitylegacy
src/liblzma/common/stream_buffer_decoder.c:21
qualitylegacy
lib/getopt_int.h:1
qualitylegacy
lib/getopt1.c:2
qualitylegacy
lib/getopt1.c:1
qualitylegacy
lib/getopt.c:2
qualitylegacy
lib/getopt-pfx-ext.h:1
qualitylegacy
lib/getopt-pfx-core.h:1
qualitylegacy
lib/getopt-ext.h:1
qualitylegacy
debug/sync_flush.c:1
qualitylegacy
.github/workflows/cifuzz.yml:51
supply-chaingithub-actionspinned-dependencies
extra/scanlzma/scanlzma.c:20
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/8cda9cc0-bfdb-41ae-adf8-e09d6275c1f7/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/8cda9cc0-bfdb-41ae-adf8-e09d6275c1f7/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.