Scan timing: clone 6.97s · analysis 16.7s · 10.2 MB · GitHub API rate-limit (preflight)
https://github.com/spkenv/spk
· scanned 2026-06-05 23:52 UTC (4 days, 3 hours ago)
· 10 languages
222 raw signals (130 security + 92 graph) 8th percentile · Rust · large (100-500K LoC) System graph score 84 (lower by 31)
Last scanned 4 days, 3 hours ago · v2 · 82 actionable findings from 2 signal sources. 94 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
47.1 | 0.25 | 11.78 |
testing_score |
12.0 | 0.20 | 2.40 |
documentation_score |
89.0 | 0.15 | 13.35 |
practices_score |
75.0 | 0.15 | 11.25 |
code_quality |
49.6 | 0.10 | 4.96 |
| Overall | 1.00 | 52.7 |
Showing 58 of 82 actionable findings. 176 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.site/spi/.spdev/overrides.py:39
.github/workflows/coverage.yml:80
CI/CD securityworkflow secretsGitHub Actions
website/static/js/search.js:54
.site/spi/.spdev/overrides.py:12, 13, 81, 87, 93, 99, 100, 105, +2 more (10 hits)Cargo.lock
Cargo.lock
rpmbuild.Dockerfile:1
packages/Dockerfile:1
.github/workflows/rust.yml:19, 83, 121, 151, 233, 270 (9 hits).github/workflows/rpm.yml:15, 23, 36, 43 (5 hits).github/workflows/coverage.yml:48.github/workflows/cspell.yml:12.github/workflows/rust.yml:18, 23, 120, 148, 232, 267 (12 hits).github/workflows/coverage.yml:26, 78, 82 (6 hits).github/workflows/rpm.yml:14, 35, 38 (6 hits).github/workflows/cspell.yml:13.github/workflows/housekeeping.yml:18.github/workflows/hugo-link-check.yml:14Cargo.lock
Cargo.lock
Cargo.lock
Cargo.lock
Cargo.lock
Cargo.lock
Cargo.lock
Cargo.lock
Cargo.lock
Cargo.lock
Cargo.lock
Cargo.lock
Cargo.lock
.github/workflows/rust.yml:107, 203 (2 hits).github/workflows/coverage.yml:20Cargo.lock
website/static/js/modernizr.custom-3.6.0.js:3
packages/Dockerfile:1
CI/CD securitycontainers
packages/spk-convert-pip/requirements.txt:5
.dockerignore
CI/CD securitycontainers
crates/spfs-cli/main/src/cmd_platforms.rs:19, 20 (2 hits)crates/spk-cli/group3/src/cmd_import_test.rs:16, 41 (2 hits)crates/spfs-cli/main/src/cmd_layers.rs:20crates/spfs-vfs/src/winfsp/mount.rs:86crates/spfs/src/fixtures.rs:175crates/spfs/src/runtime/startup_sh.rs:1crates/spfs/src/storage/fs/repository.rs:552crates/spfs/src/storage/proxy/repository.rs:94packages/spk-convert-pip/requirements.txt:2
packages/spk-convert-pip/requirements.txt:8
crates/spk-cli/group2/src/cmd_new.rs:1
crates/spfs-cli/cmd-clean/src/cmd_clean.rs:1
packages/Dockerfile:1
containersPinned dependencies
examples/cmake/package.py:46
This page is publicly accessible at:
https://repobility.com/scan/994cdc6d-c00a-437d-97ae-0a0df1f7ac9e/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/994cdc6d-c00a-437d-97ae-0a0df1f7ac9e/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.