https://github.com/github/gh-aw
· scanned 2026-06-05 14:43 UTC (5 days, 3 hours ago)
· 10 languages
143 findings 11/13 scanners ran 100th percentile · Go · huge (>500K LoC)
55 actionable findings from 1 signal source. 88 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
97.0 | 0.15 | 14.55 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
68.0 | 0.10 | 6.80 |
| Overall | 1.00 | 91.1 |
Showing 26 of 55 actionable findings. 143 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
actions/setup/js/extra_empty_commit.cjs:149actions/setup/js/push_experiment_state.cjs:115actions/setup/js/run_operation_update_upgrade.cjs:164.github/workflows/smoke-agent-public-approved.lock.yml:81, 84, 85, 86, 204, 505, 507, 747, +13 more (21 hits).devcontainer/setup.sh:30pkg/cli/devcontainer.go:157pkg/workflow/pip_validation.go:163.github/workflows/permissions.yml:150
Dockerfile:5
.devcontainer/Dockerfile:1
actions/setup/js/package.json:1
.github/workflows/smoke-service-ports.lock.yml:413
pkg/parser/github.go:75
.github/workflows/error-message-lint.yml:20, 25 (2 hits)actions/setup/js/action_setup_otlp.cjs:191
actions/setup/js/action_conclusion_otlp.cjs:97
.github/workflows/requirements.txt:2, 3, 4 (3 hits).dockerignore
CI/CD securitycontainers
.dockerignore
CI/CD securitycontainers
Dockerfile:5
CI/CD securitycontainers
.devcontainer/Dockerfile:1
CI/CD securitycontainers
pkg/cli/outcome_eval_update.go:1
.devcontainer/devcontainer.json:50.github/workflows/copilot-setup-steps.yml:17.github/workflows/daily-byok-ollama-test.md:23pkg/cli/outcome_eval_update.go:1
pkg/cli/completions.go:129pkg/cli/deploy_command.go:54pkg/cli/deps_outdated.go:169pkg/cli/codemod_github_repos.go:26, 54 (2 hits)pkg/linters/ossetenvlibrary/ossetenvlibrary.go:22, 24 (2 hits).github/drivers/copilot_sdk_driver_sample_typescript.ts:29pkg/cli/codemod_assign_to_agent.go:45pkg/cli/codemod_bash_single_quoted_args.go:17pkg/cli/codemod_dependabot_permissions.go:105pkg/cli/codemod_difc_proxy.go:66pkg/cli/codemod_engine_max_turns.go:39.github/aw/syntax-agentic.md
pkg/workflow/create_project_status_update.go:1
pkg/parser/workflow_update.go:1
This page is publicly accessible at:
https://repobility.com/scan/9488f272-c437-48f0-b23b-8dcbe61d9d74/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/9488f272-c437-48f0-b23b-8dcbe61d9d74/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.