https://github.com/golang/go
· scanned 2026-06-05 04:52 UTC (4 hours, 11 minutes ago)
· 10 languages
651 findings (117 legacy + 534 scanner) 11/13 scanners ran 33rd percentile · Go · huge (>500K LoC) Scanner says 72 (higher by 7)
Last scanned 4 hours, 11 minutes ago · v2 · 384 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
93.0 | 0.15 | 13.95 |
practices_score |
40.0 | 0.15 | 6.00 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 78.7 |
Showing 306 of 384 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/cmd/go/internal/base/env.go:26
secrets
src/cmd/go/internal/vcweb/hg.go:104
secrets
src/internal/exportdata/exportdata.go:331
secrets
src/net/url/gen_encoding_table.go:143
secrets
src/os/exec/exec.go:1237
secrets
src/crypto/internal/boring/notboring.go:43
qualitylegacy
src/crypto/internal/boring/hmac.go:41
qualitylegacy
src/crypto/crypto.go:27
qualitylegacy
src/cmd/distpack/pack.go:329
qualitylegacy
src/cmd/compile/internal/syntax/syntax.go:68
qualitylegacy
src/cmd/compile/internal/syntax/dumper.go:28
qualitylegacy
src/runtime/runtime-gdb.py:635
qualitylegacy
src/runtime/runtime-gdb.py:96
qualitylegacy
src/runtime/runtime-gdb.py:483
qualitylegacy
src/crypto/internal/fips140/nistec/fiat/Dockerfile:4
dependencylegacy
src/cmd/link/internal/ld/execarchive.go:33
injectionlegacy
src/cmd/go/internal/toolchain/switch.go:111
qualitylegacy
src/cmd/go/internal/toolchain/exec.go:61
qualitylegacy
misc/chrome/gophertool/gopher.js:29
qualitylegacy
src/cmd/pprof/pprof.go:87
qualitylegacy
src/cmd/go/internal/web/http.go:45
qualitylegacy
src/cmd/internal/par/work.go:10
qualitylegacy
src/cmd/go/internal/lockedfile/lockedfile_plan9.go:11
qualitylegacy
src/cmd/compile/internal/gc/compile.go:10
qualitylegacy
src/cmd/go/internal/cache/prog.go:87
qualitylegacy
src/cmd/go/internal/bug/bug.go:164
qualitylegacy
src/cmd/cover/func.go:203
qualitylegacy
src/cmd/go/internal/imports/build.go:88
owaspeval_used
src/cmd/go/internal/modindex/build.go:652
owaspeval_used
src/cmd/go/internal/modindex/read.go:511
owaspeval_used
src/cmd/internal/script/conds.go:81
owaspeval_used
src/runtime/os3_solaris.go:622
owaspexec_used
src/runtime/runtime-gdb.py:673
qualitylegacy
src/runtime/runtime-gdb.py:445
qualitylegacy
src/runtime/runtime-gdb.py:36
qualitylegacy
src/net/http/doc.go:71
qualitylegacy
src/net/http/triv.go:139
qualitylegacy
src/net/http/doc.go:71
qualitylegacy
src/cmd/cgo/util.go:31
qualitylegacy
misc/ios/go_ios_exec.go:82
qualitylegacy
src/cmd/trace/goroutines.go:232
xsslegacy
src/cmd/internal/pgo/serialize.go:52
xsslegacy
src/cmd/cover/html.go:57
xsslegacy
src/crypto/internal/fips140/fips140.go:24
qualitylegacy
src/cmd/go/internal/run/run.go:151
qualitylegacy
src/cmd/go/internal/doc/pkgsite.go:75
qualitylegacy
.dockerignore
dockerlegacy
src/crypto/internal/fips140/nistec/fiat/Dockerfile:5
dockerlegacy
src/crypto/internal/boring/Dockerfile:8
dockerlegacy
src/crypto/crypto.go:27
owaspweak_hash
src/crypto/internal/boring/hmac.go:41
owaspweak_hash
src/crypto/internal/boring/notboring.go:43
owaspweak_hash
src/crypto/internal/boring/sha.go:76
owaspweak_hash
src/crypto/internal/fips140/rsa/pkcs1v15.go:29
owaspweak_hash
src/crypto/sha1/sha1.go:21
owaspweak_hash
src/crypto/tls/auth.go:152
owaspweak_hash
src/crypto/tls/bogo_config.json:53
owaspweak_hash
src/crypto/tls/handshake_client.go:797
owaspweak_hash
src/crypto/tls/handshake_client_tls13.go:666
owaspweak_hash
src/crypto/tls/handshake_server.go:776
owaspweak_hash
src/crypto/tls/handshake_server_tls13.go:1094
owaspweak_hash
src/cmd/compile/internal/noder/linker.go:126
error_handlinglegacy
src/cmd/compile/internal/gc/obj.go:192
error_handlinglegacy
src/archive/zip/register.go:35
error_handlinglegacy
src/cmd/go/internal/fips140/mkzip.go:102
qualitylegacy
misc/ios/go_ios_exec.go:81
qualitylegacy
misc/chrome/gophertool/popup.js:33
qualitylegacy
src/crypto/internal/boring/Dockerfile:19
dockerlegacy
src/cmd/compile/internal/ssa/_gen/ARM64Ops.go:75
qualitylegacy
src/cmd/compile/internal/pgoir/irgraph.go:254
qualitylegacy
src/cmd/compile/internal/noder/html.go:71
qualitylegacy
src/cmd/compile/internal/mips64/ssa.go:2
qualitylegacy
src/cmd/compile/internal/liveness/mergelocals.go:664
qualitylegacy
src/cmd/compile/internal/ir/reassign_consistency_check.go:20
qualitylegacy
src/cmd/asm/internal/arch/arm64.go:14
qualitylegacy
src/crypto/internal/fips140/nistec/fiat/Dockerfile:4
supply-chaindockerpinned-dependencies
src/runtime/runtime-gdb.py:299
dead-code
src/runtime/runtime-gdb.py:437
dead-code
src/runtime/runtime-gdb.py:459
dead-code
src/runtime/runtime-gdb.py:668
dead-code
src/runtime/runtime-gdb.py:526
dead-code
src/runtime/runtime-gdb.py:316
dead-code
src/runtime/runtime-gdb.py:440
dead-code
Showing first 300 of 306. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/9a893486-8823-4472-92e2-5fded52d41d6/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/9a893486-8823-4472-92e2-5fded52d41d6/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.