Scan timing: clone 4.84s · analysis 28.49s · 37.8 MB · GitHub API rate-limit (preflight)
https://github.com/spring-projects/spring-boot
· scanned 2026-06-05 07:23 UTC (5 days, 22 hours ago)
· 10 languages
234 raw signals (100 security + 134 graph) 11/13 scanners ran 45th percentile · Java · huge (>500K LoC) System graph score 63 (higher by 14)
Last scanned 5 days, 22 hours ago · v2 · 85 actionable findings from 2 signal sources. 82 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
68.0 | 0.15 | 10.20 |
practices_score |
81.0 | 0.15 | 12.15 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 77.3 |
Showing 35 of 85 actionable findings. 167 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
module/spring-boot-artemis/src/main/java/org/springframework/boot/artemis/autoconfigure/ArtemisEmbeddedConfigurationFactory.java:67
documentation/spring-boot-docs/src/main/kotlin/org/springframework/boot/docs/io/quartz/MySampleJob.kt:41
documentation/spring-boot-docs/src/docs/antora/modules/reference/partials/dockerfile:2, 16 (2 hits)integration-test/spring-boot-loader-integration-tests/src/dockerTest/resources/conf/oracle-jdk-17/Dockerfile:1, 6 (2 hits)gradle/wrapper/gradle-wrapper.jar:1
cli/spring-boot-cli/src/main/java/org/springframework/boot/cli/command/init/InitializrService.java:189
buildpack/spring-boot-buildpack-platform/src/main/java/org/springframework/boot/buildpack/platform/docker/transport/HttpClientTransport.java:163
build-plugin/spring-boot-maven-plugin/src/main/java/org/springframework/boot/maven/AbstractPackagerMojo.java:234
.github/workflows/release.yml:17, 74, 108, 125, 141, 172 (12 hits).github/workflows/release-milestone.yml:18, 63, 93, 124 (8 hits).github/workflows/verify.yml:41, 47, 52, 83 (8 hits).github/workflows/build-pull-request.yml:12, 21 (4 hits).github/workflows/build-and-deploy-snapshot.yml:18 (2 hits).github/workflows/ci.yml:45 (2 hits).github/workflows/run-system-tests.yml:27 (2 hits).github/workflows/trigger-docs-build.yml:29 (2 hits)build-plugin/spring-boot-gradle-plugin/src/main/java/org/springframework/boot/gradle/tasks/aot/ProcessAot.java:50
Exec used
build-plugin/spring-boot-gradle-plugin/src/main/java/org/springframework/boot/gradle/tasks/run/BootRun.java:66
Exec used
buildSrc/SpringRepositorySupport.groovy:45
build-plugin/spring-boot-gradle-plugin/src/main/java/org/springframework/boot/gradle/tasks/bundling/LoaderZipEntries.java:62build-plugin/spring-boot-maven-plugin/src/intTest/java/org/springframework/boot/maven/AbstractArchiveIntegrationTests.java:181build-plugin/spring-boot-maven-plugin/src/intTest/java/org/springframework/boot/maven/WarIntegrationTests.java:107.dockerignore
CI/CD securitycontainers
documentation/spring-boot-docs/src/docs/antora/modules/reference/partials/dockerfile:16
CI/CD securitycontainers
configuration-metadata/spring-boot-configuration-metadata/src/json-shade/java/org/springframework/boot/configurationmetadata/json/JSONObject.java:2, 264 (2 hits)configuration-metadata/spring-boot-configuration-processor/src/json-shade/java/org/springframework/boot/configurationprocessor/json/JSONObject.java:2, 264 (2 hits)configuration-metadata/spring-boot-configuration-processor/src/main/java/org/springframework/boot/configurationprocessor/metadata/ItemMetadata.java:45, 119 (2 hits)build-plugin/spring-boot-gradle-plugin/src/main/java/org/springframework/boot/gradle/tasks/bundling/BootWar.java:50build-plugin/spring-boot-maven-plugin/src/main/java/org/springframework/boot/maven/TestRunMojo.java:38build-plugin/spring-boot-maven-plugin/src/main/java/org/springframework/boot/maven/VersionExtractor.java:14buildpack/spring-boot-buildpack-platform/src/main/java/org/springframework/boot/buildpack/platform/docker/PushImageUpdateEvent.java:12buildpack/spring-boot-buildpack-platform/src/main/java/org/springframework/boot/buildpack/platform/docker/type/ManifestList.java:20
This page is publicly accessible at:
https://repobility.com/scan/90eb9932-2940-47c9-aed3-67b7a21c25b6/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/90eb9932-2940-47c9-aed3-67b7a21c25b6/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.