Scan timing: clone 3.99s · analysis 13.03s · 10.1 MB · GitHub API rate-limit (preflight)
https://github.com/chef/supermarket
· scanned 2026-06-05 18:26 UTC (4 days, 18 hours ago)
· 10 languages
319 raw signals (219 security + 100 graph) System graph score 76 (lower by 25)
Last scanned 4 days, 18 hours ago · v2 · 206 actionable findings from 2 signal sources. 63 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
22.9 | 0.25 | 5.72 |
testing_score |
15.0 | 0.20 | 3.00 |
documentation_score |
85.0 | 0.15 | 12.75 |
practices_score |
80.0 | 0.15 | 12.00 |
code_quality |
72.9 | 0.10 | 7.29 |
| Overall | 1.00 | 50.5 |
Showing 189 of 206 actionable findings. 269 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
docs-chef-io/content/supermarket/install_supermarket.md:75, 330, 331 (3 hits)src/supermarket/config/secrets.yml:16, 21 (2 hits)src/supermarket/app/assets/data/licenses.json:4395src/supermarket/engines/fieri/spec/dummy/config/secrets.yml:14src/supermarket/engines/fieri/Gemfile.lock
postgresql/default.toml:24, 29 (2 hits)src/supermarket/habitat-sidekiq/default.toml:26
src/supermarket/habitat-web/default.toml:82
src/supermarket/config/routes.rb:56
src/supermarket/engines/fieri/app/models/cookbook_artifact.rb:43
src/supermarket/app/controllers/api/v1_controller.rb:3src/supermarket/app/controllers/collaborators_controller.rb:6src/supermarket/app/controllers/sessions_controller.rb:2src/supermarket/app/controllers/api/v1_controller.rb:3src/supermarket/app/controllers/collaborators_controller.rb:6src/supermarket/app/controllers/sessions_controller.rb:2src/supermarket/exec/shared.sh:31
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/docker-compose.yml:2
CI/CD securitycontainers
src/supermarket/Gemfile.lock
src/supermarket/package-lock.json
src/supermarket/package-lock.json
.github/workflows/docs-lint.yml:26, 31, 36, 41, 55 (5 hits).github/workflows/brakeman-analysis.yml:27, 45 (4 hits).github/workflows/unit.yml:31, 73 (4 hits).github/workflows/ci-main-pull-request-stub.yml:52 (2 hits).github/workflows/ctl-cookbook-testing.yml:17, 30 (2 hits).github/workflows/lint.yml:18, 31 (2 hits).github/workflows/brakeman-analysis.yml:23 (2 hits).github/workflows/ci-main-pull-request-stub.yml:38 (2 hits).github/workflows/ctl-cookbook-testing.yml:16, 29 (2 hits).github/workflows/docs-lint.yml:23, 52 (2 hits).github/workflows/lint.yml:17, 30 (2 hits).github/workflows/unit.yml:29, 71 (2 hits).github/workflows/labeler.yml:12src/supermarket/Gemfile.lock
src/supermarket/package-lock.json
src/supermarket/package-lock.json
src/supermarket/package-lock.json
src/supermarket/package-lock.json
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/package-lock.json
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/engines/fieri/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/package-lock.json
src/supermarket/package-lock.json
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
docs-chef-io/go.mod
src/supermarket/package-lock.json
.github/workflows/unit.yml:18, 25, 60, 67 (4 hits)src/supermarket/config/routes.rb:93
src/supermarket/config/routes.rb:98
src/supermarket/config/routes.rb:96
src/supermarket/config/routes.rb:104
src/supermarket/config/routes.rb:83
src/supermarket/config/routes.rb:27
src/supermarket/config/routes.rb:20
src/supermarket/config/routes.rb:16, 21 (2 hits)src/supermarket/config/routes.rb:17
src/supermarket/config/routes.rb:18, 22 (2 hits)src/supermarket/config/routes.rb:19
src/supermarket/config/routes.rb:15
src/supermarket/config/routes.rb:23
src/supermarket/config/environments/development.rb:62
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/package-lock.json
src/supermarket/Gemfile.lock
src/supermarket/docker-compose.yml:2
CI/CD securitycontainers
src/supermarket/docker-compose.yml:8
CI/CD securitycontainers
src/supermarket/Gemfile.lock
src/supermarket/package-lock.json
src/supermarket/Gemfile.lock
src/supermarket/package-lock.json
src/supermarket/package-lock.json
src/supermarket/package-lock.json
src/supermarket/package-lock.json
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/package.json
src/supermarket/package.json
src/supermarket/package-lock.json
.well-known/security.txt
src/supermarket/Gemfile.lock
src/supermarket/package-lock.json
src/supermarket/package-lock.json
src/supermarket/Gemfile.lock
src/supermarket/engines/fieri/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/engines/fieri/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/engines/fieri/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/package-lock.json
src/supermarket/package-lock.json
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/package-lock.json
src/supermarket/Gemfile.lock
.github/workflows/ci-main-pull-request-stub.yml
CI/CD securitySupply chainGithub actions
nginx/default.toml:55
Weak hash
src/supermarket/app/helpers/users_helper.rb:43
Weak hash
src/supermarket/app/lib/supermarket/fips.rb:10
Weak hash
src/supermarket/app/models/user.rb:240
Weak hash
src/supermarket/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/package-lock.json
src/supermarket/package-lock.json
src/supermarket/docker-compose.yml:8
CI/CD securitycontainers
src/supermarket/docker-compose.yml:2, 8 (2 hits)src/supermarket/package-lock.json
omnibus/cookbooks/omnibus-supermarket/recipes/postgresql.rb:1src/supermarket/app/assets/javascripts/cookbookDeprecate.js:4src/supermarket/app/assets/javascripts/group_members.js:4src/supermarket/app/assets/javascripts/groups.js:4src/supermarket/engines/fieri/spec/dummy/config/environments/development.rb:1src/supermarket/engines/fieri/spec/models/no_binaries_worker_spec.rb:12src/supermarket/spec/api/cookbook_show_spec.rb:34src/supermarket/spec/extractors/github_extractor_spec.rb:4src/supermarket/engines/fieri/Gemfile.lock
src/supermarket/Gemfile.lock
src/supermarket/package-lock.json
src/supermarket/Gemfile.lock
src/supermarket/package-lock.json
src/supermarket/engines/fieri/Gemfile.lock
This page is publicly accessible at:
https://repobility.com/scan/8fa01497-35dc-4e5f-a82a-98da800f40c7/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/8fa01497-35dc-4e5f-a82a-98da800f40c7/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.