Scan timing: clone 14.27s · analysis 20.51s · 85.4 MB · GitHub preflight 454ms
https://github.com/google-gemini/gemini-cli
· scanned 2026-06-05 05:53 UTC (1 week, 1 day ago)
· 10 languages
881 raw signals (97 security + 784 graph) 11/13 scanners ran 68th percentile · Typescript · huge (>500K LoC) System graph score 58 (higher by 29)
Last scanned 1 week, 1 day ago · v2 · 430 actionable findings from 2 signal sources. 59 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
89.0 | 0.15 | 13.35 |
practices_score |
94.0 | 0.15 | 14.10 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 87.5 |
Showing 273 of 430 actionable findings. 489 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/ci.yml:47, 443 (2 hits).github/actions/push-docker/action.yml:50
.github/actions/push-sandbox/action.yml:56
.github/workflows/eval.yml:25
.github/workflows/gemini-automated-issue-dedup.yml:59
.github/workflows/gemini-scheduled-issue-dedup.yml:39
packages/vscode-ide-companion/src/ide-server.ts:213
evals/update_topic.eval.ts:200
Dockerfile:2, 42 (2 hits).gcp/Dockerfile.development:2.gcp/Dockerfile.gemini-code-builder:3packages/cli/package.json:1 (2 hits)packages/a2a-server/package.json:1packages/core/package.json:1packages/sdk/package.json:1packages/test-utils/package.json:1packages/cli/src/acp/commands/about.ts:32
Exec used
packages/cli/src/ui/commands/aboutCommand.ts:33
Exec used
packages/cli/src/ui/commands/bugCommand.ts:46
Exec used
packages/sdk/src/shell.ts:34
Exec used
packages/sdk/src/types.ts:183
Exec used
.github/workflows/eval-pr.yml
CI/CD securitySupply chainGithub actions
packages/cli/src/ui/components/Notifications.tsx:109packages/cli/src/ui/hooks/useLogger.ts:27packages/cli/src/ui/utils/directoryUtils.ts:128.gemini/skills/ci/scripts/ci.mjs:33
docs/cli/cli-reference.md:58docs/cli/settings.md:30docs/reference/configuration.md:128packages/cli/src/config/config.ts:258packages/cli/src/config/settingsSchema.ts:236.gcp/Dockerfile.gemini-code-builder:3
CI/CD securitycontainers
.gcp/Dockerfile.development:20
CI/CD securitycontainers
.gcp/Dockerfile.development:21
CI/CD securitycontainers
index.html
.well-known/security.txt
manifest.json
.dockerignore
CI/CD securitycontainers
.gcp/Dockerfile.gemini-code-builder:81
CI/CD securitycontainers
.gcp/Dockerfile.gemini-code-builder:81
CI/CD securitycontainers
evals/skill_extraction.eval.ts:117evals/tool_output_masking.eval.ts:6evals/validation_fidelity_pre_existing_errors.eval.ts:22packages/cli/src/acp/commands/commandRegistry.ts:5packages/cli/src/acp/commands/extensions.ts:32packages/cli/src/acp/commands/memory.ts:5packages/cli/src/acp/commands/restore.ts:1packages/cli/src/commands/extensions/enable.ts:72llms.txt
humans.txt
sitemap.xml
docs/cli/telemetry.md
Dockerfile:2, 42 (2 hits)package.jsonpackages/vscode-ide-companion/package.jsonthird_party/get-ripgrep/package.json
This page is publicly accessible at:
https://repobility.com/scan/99c256b4-7e59-4244-ad4e-e01584eb41f3/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/99c256b4-7e59-4244-ad4e-e01584eb41f3/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.