https://github.com/daytonaio/daytona
· scanned 2026-06-05 08:09 UTC (5 days, 19 hours ago)
· 10 languages
1379 raw signals (361 security + 1018 graph) 11/13 scanners ran 15th percentile · Typescript · huge (>500K LoC) System graph score 56 (higher by 18)
Last scanned 5 days, 19 hours ago · v2 · 597 actionable findings from 2 signal sources. 273 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
85.0 | 0.25 | 21.25 |
testing_score |
62.0 | 0.20 | 12.40 |
documentation_score |
82.0 | 0.15 | 12.30 |
practices_score |
91.0 | 0.15 | 13.65 |
code_quality |
57.0 | 0.10 | 5.70 |
| Overall | 1.00 | 74.3 |
Showing 458 of 597 actionable findings. 870 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.env
.env
docker/docker-compose.yaml:2, 106, 128, 153, 180, 191, 235, 260 (8 hits).devcontainer/docker-compose.yaml:18, 25, 59, 75 (4 hits)docker/docker-compose.yaml:2, 128 (2 hits).devcontainer/docker-compose.yaml:3.github/workflows/pr_checks.yaml:19
CI/CD securityworkflow secretsGitHub Actions
apps/api/src/audit/enums/audit-action.enum.ts:53, 54 (2 hits)apps/daemon/pkg/git/cli_errors.go:140
apps/daemon/pkg/git/clone.go:170
apps/dashboard/src/components/Playground/Sandbox/CodeSnippets/python.ts:172
libs/api-client-java/src/main/java/io/daytona/api/client/model/CreateDockerRegistry.java:68, 250 (2 hits)libs/api-client-java/src/main/java/io/daytona/api/client/model/CreateRegionResponse.java:74, 263 (2 hits)libs/api-client-java/src/main/java/io/daytona/api/client/model/GitCloneRequest.java:68, 275 (2 hits)libs/api-client-java/src/main/java/io/daytona/api/client/model/GitRepoRequest.java:63, 199 (2 hits)libs/api-client-java/src/main/java/io/daytona/api/client/model/SnapshotManagerCredentials.java:58, 173 (2 hits)libs/api-client-java/src/main/java/io/daytona/api/client/model/UpdateDockerRegistry.java:68, 250 (2 hits)libs/sdk-python/src/daytona/_async/git.py:240, 278 (2 hits)libs/sdk-python/src/daytona/_sync/git.py:238, 276 (2 hits)libs/sdk-ruby/lib/daytona/git.rb:180, 210 (2 hits)libs/toolbox-api-client-java/src/main/java/io/daytona/toolbox/client/model/GitCloneRequest.java:63, 274 (2 hits)libs/toolbox-api-client-java/src/main/java/io/daytona/toolbox/client/model/GitRepoRequest.java:53, 197 (2 hits)scripts/setup-domain-oss-deployment.sh:243, 330 (2 hits)apps/api/src/admin/controllers/runner.controller.ts:100
apps/api/src/admin/controllers/snapshot.controller.ts:50
apps/api/src/admin/controllers/organization.controller.ts:138
apps/api/src/admin/controllers/organization.controller.ts:98, 191 (2 hits)apps/api/src/sandbox-telemetry/controllers/sandbox-telemetry.controller.ts:67
apps/api/src/sandbox-telemetry/controllers/sandbox-telemetry.controller.ts:97
apps/api/src/api-key/api-key.controller.ts:153
apps/api/src/webhook/controllers/webhook.controller.ts:65
apps/api/src/webhook/controllers/webhook.controller.ts:94
apps/daemon/pkg/toolbox/process/interpreter/repl_worker.py:129
examples/ruby/declarative-image/main.rb:39examples/ruby/exec-command/exec.rb:16examples/ruby/exec-command/exec_linked.rb:43examples/python/git-lsp/main.py:12
examples/python/git-lsp/_async/main.py:13
guides/python/recursive-language-models/rlm/prompts.py:21
libs/api-client-python/daytona_api_client/api_client.py:189, 191, 196, 197, 211, 212, 217, 220, +6 more (14 hits)apps/daemon/pkg/toolbox/process/interpreter/repl_worker.py:57, 76, 106, 107, 140, 152, 153, 162, +3 more (11 hits)guides/python/claude/claude-managed-agents/host_orchestrator_webhook.py:101
apps/api/Dockerfile:2, 42 (2 hits)apps/dashboard/Dockerfile:1, 29 (2 hits)apps/docs/Dockerfile:1, 52 (2 hits)apps/otel-collector/Dockerfile:1, 43 (2 hits)apps/proxy/Dockerfile:1, 42 (2 hits)apps/runner/Dockerfile:1, 57 (2 hits)apps/snapshot-manager/Dockerfile:1, 38 (2 hits)apps/ssh-gateway/Dockerfile:1, 38 (2 hits)examples/java/charts/gradle/wrapper/gradle-wrapper.jar:1
examples/java/gradle/wrapper/gradle-wrapper.jar:1
guides/python/reinforcement-learning/openenv/run.py:103
apps/daemon/pkg/toolbox/lsp/lsp.go:109
apps/cli/cmd/common/ssh_unix.go:24apps/cli/cmd/common/ssh_windows.go:24apps/daemon/pkg/common/spawn_tty.go:33apps/runner/pkg/sshgateway/service.go:242
docker/docker-compose.yaml:191
CI/CD securitycontainers
.devcontainer/docker-compose.yaml:25
CI/CD securitycontainers
docker/docker-compose.yaml:180
CI/CD securitycontainers
.devcontainer/docker-compose.yaml:18
CI/CD securitycontainers
docker/docker-compose.yaml:260
CI/CD securitycontainers
guides/python/claude/claude-managed-agents/Dockerfile.default:24, 60 (2 hits)images/sandbox-slim/Dockerfile:37images/sandbox-slim/Dockerfile:37
containersRemote installer
apps/api/src/organization/services/organization-usage.service.ts:366
Eval used
apps/daemon/pkg/toolbox/process/coderun/matplotlib_wrapper.py:504
Exec used
apps/daemon/pkg/toolbox/process/interpreter/repl_worker.py:127
Exec used
libs/sdk-python/scripts/chart_data_extractor_wrapper.py:501
Exec used
apps/api/src/admin/controllers/runner.controller.ts:100
apps/api/src/admin/controllers/snapshot.controller.ts:50
apps/api/src/admin/controllers/docker-registry.controller.ts:29
apps/api/src/admin/controllers/organization.controller.ts:44, 138 (2 hits)apps/api/src/admin/controllers/organization.controller.ts:98, 191 (2 hits)apps/api/src/admin/controllers/snapshot.controller.ts:30
apps/api/src/admin/controllers/audit.controller.ts:28
apps/api/src/admin/controllers/runner.controller.ts:49
apps/api/src/sandbox/controllers/snapshot.controller.ts:164
apps/api/src/api-key/api-key.controller.ts:137
apps/api/src/sandbox-telemetry/controllers/sandbox-telemetry.controller.ts:35
apps/api/src/api-key/api-key.controller.ts:153
apps/api/src/user/user.controller.ts:195
apps/api/src/audit/controllers/audit.controller.ts:29
apps/api/src/webhook/controllers/webhook.controller.ts:33
apps/api/src/api-key/api-key.controller.ts:37
apps/api/src/common/decorators/throttler-scope.decorator.ts:24
apps/api/src/sandbox/controllers/runner.controller.ts:74
apps/daemon/pkg/git/clone.go:134
apps/docs/src/components/menu/LocaleSelector.tsx:40
guides/python/langchain/data-analysis/anthropic/data_analysis.py:54
apps/daemon/pkg/toolbox/process/interpreter/repl_worker.py:38, 165, 184 (3 hits)libs/sdk-python/src/daytona/_async/filesystem.py:529, 961, 1171 (3 hits)libs/sdk-python/src/daytona/_sync/filesystem.py:482, 920, 993 (3 hits)apps/daemon/pkg/toolbox/process/coderun/matplotlib_wrapper.py:317, 514 (2 hits)libs/sdk-python/scripts/chart_data_extractor_wrapper.py:313, 511 (2 hits)libs/sdk-python/src/daytona/_async/daytona.py:215, 221 (2 hits)libs/sdk-python/src/daytona/_sync/daytona.py:199, 205 (2 hits)libs/sdk-python/src/daytona/handle/pty_handle.py:244, 274 (2 hits).devcontainer/docker-compose.yaml:40, 75 (2 hits)docker/docker-compose.yaml:210, 260 (2 hits)docker/docker-compose.yaml:180
CI/CD securitycontainers
.devcontainer/docker-compose.yaml:18
CI/CD securitycontainers
docker/docker-compose.yaml:210
CI/CD securitycontainers
.devcontainer/docker-compose.yaml:40
CI/CD securitycontainers
apps/docs/Dockerfile:29, 41 (2 hits).devcontainer/Dockerfile:1apps/api/Dockerfile:42apps/dashboard/Dockerfile:30apps/docs/Dockerfile:53apps/otel-collector/Dockerfile:44apps/proxy/Dockerfile:43apps/runner/Dockerfile:58apps/snapshot-manager/Dockerfile:39guides/typescript/agentkit-inngest/coding-agent/anthropic/Dockerfile:8
CI/CD securitycontainers
.devcontainer/Dockerfile:6, 13 (2 hits)apps/api/src/interceptors/metrics.interceptor.ts:147, 150, 153, 156, 159, 162, 165, 168, +6 more (14 hits)apps/api/src/docker-registry/services/docker-registry.service.ts:466libs/billing-api-client/src/models/organization-tier-update.ts:1
index.html
.well-known/security.txt
.github/workflows/build_devcontainer.yaml.github/workflows/prepare-release.yaml.github/workflows/release.yaml.github/workflows/translate.yamlapps/dashboard/src/components/ui/chart.tsx:75
Dangerous innerhtml
apps/dashboard/src/hooks/useDocsSearchCommands.tsx:118
Dangerous innerhtml
apps/api/src/migrations/1744114341077-migration.ts:19
Weak hash
apps/api/src/migrations/1744808444807-migration.ts:15
Weak hash
apps/api/src/migrations/1744971114480-migration.ts:13
Weak hash
apps/api/src/migrations/1745574377029-migration.ts:50
Weak hash
apps/api/src/migrations/post-deploy/1774438866002-migration.ts:45
Weak hash
libs/api-client-go/api/openapi.yaml
Ports
libs/api-client-go/api/openapi.yaml
Ports
libs/api-client-go/api/openapi.yaml
Ports
libs/api-client-go/api/openapi.yaml
Ports
libs/api-client-go/api/openapi.yaml
Ports
libs/api-client-go/api/openapi.yaml
Ports
.dockerignore
CI/CD securitycontainers
apps/cli/apiclient/api_client.go:84apps/cli/auth/auth.go:50apps/cli/cmd/auth/login.go:177docker/docker-compose.yaml:2, 191 (2 hits)docker/docker-compose.yaml:2, 106, 128, 153, 167, 215, 235, 253, +1 more (9 hits).devcontainer/docker-compose.yaml:3docker/docker-compose.yaml:2, 106, 128, 153, 167, 191, 215, 235, +2 more (10 hits).devcontainer/docker-compose.yaml:3.devcontainer/docker-compose.yaml:40, 75 (2 hits)docker/docker-compose.yaml:210, 260 (2 hits)hack/computer-use/Dockerfile:11images/sandbox-slim/Dockerfile:4images/sandbox/Dockerfile:4.devcontainer/Dockerfile:17
CI/CD securitycontainers
apps/api/src/api-key/dto/api-key-response.dto.ts:14apps/api/src/audit/controllers/audit.controller.ts:44apps/api/src/docker-registry/providers/docker-registry.provider.ts:9apps/api/src/organization/controllers/organization.controller.ts:383apps/api/src/organization/dto/region-quota.dto.ts:21apps/api/src/organization/dto/update-organization-role.dto.ts:7apps/api/src/region/dto/update-region.dto.ts:4apps/api/src/usage/entities/sandbox-usage-period.entity.ts:21llms.txt
humans.txt
sitemap.xml
guides/typescript/flue/.flue/agents/bug-fix.ts:1
apps/otel-collector/Dockerfile:43apps/proxy/Dockerfile:42apps/snapshot-manager/Dockerfile:38apps/ssh-gateway/Dockerfile:38.devcontainer/Dockerfile:1
containersPinned dependencies
apps/runner/Dockerfile:57
containersPinned dependencies
images/sandbox/Dockerfile:1
containersPinned dependencies
apps/dashboard/Dockerfile:29
containersPinned dependencies
apps/dashboard/Dockerfile:1
containersPinned dependencies
guides/typescript/agentkit-inngest/coding-agent/anthropic/Dockerfile:1
containersPinned dependencies
apps/docs/Dockerfile:1, 52 (2 hits)apps/otel-collector/Dockerfile:1apps/proxy/Dockerfile:1apps/runner/Dockerfile:1apps/snapshot-manager/Dockerfile:1apps/ssh-gateway/Dockerfile:1apps/api/Dockerfile:2, 42 (2 hits)images/sandbox-slim/Dockerfile:1
containersPinned dependencies
hack/computer-use/Dockerfile:1
containersPinned dependencies
guides/python/langchain/data-analysis/anthropic/data_analysis.py:54
Debug true
repo-level (7 hits)repo-level (11 hits)repo-level (2 hits)package.json
CI/CD securitySupply chainNpm
libs/runner-api-client/package.json
CI/CD securitySupply chainNpm
apps/daemon/pkg/toolbox/process/coderun/matplotlib_wrapper.py:466
libs/api-client-python/daytona_api_client/rest.py:61
libs/api-client-python/daytona_api_client/rest.py:57
apps/daemon/pkg/toolbox/process/interpreter/repl_worker.py:68
libs/api-client-python/daytona_api_client/api_client.py:114
libs/api-client-python/daytona_api_client/configuration.py:529
libs/api-client-python/daytona_api_client/models/create_sandbox.py:70libs/api-client-python/daytona_api_client/models/file_info.py:55libs/api-client-python/daytona_api_client/models/lsp_completion_params.py:54libs/api-client-python/daytona_api_client/models/mouse_click_response.py:49libs/api-client-python/daytona_api_client/models/mouse_position.py:49libs/api-client-python/daytona_api_client/models/organization_suspension.py:52libs/api-client-python/daytona_api_client/models/poll_jobs_response.py:49libs/api-client-python/daytona_api_client/models/trace_summary.py:54libs/api-client-python/daytona_api_client/models/create_sandbox.py:66libs/api-client-python/daytona_api_client/models/file_info.py:51libs/api-client-python/daytona_api_client/models/health_controller_check503_response.py:48libs/api-client-python/daytona_api_client/models/lsp_completion_params.py:50libs/api-client-python/daytona_api_client/models/mouse_click_response.py:45libs/api-client-python/daytona_api_client/models/mouse_position.py:45libs/api-client-python/daytona_api_client/models/organization_suspension.py:48libs/api-client-python/daytona_api_client/models/poll_jobs_response.py:45apps/daemon/pkg/toolbox/process/interpreter/repl_worker.py:47
Showing first 300 of 458. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/91c78baa-9673-483f-a92b-06479adf8c58/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/91c78baa-9673-483f-a92b-06479adf8c58/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.