https://github.com/hashicorp/terraform-provider-aws.git
· scanned 2026-05-16 09:43 UTC (2 weeks, 6 days ago)
· 10 languages
544 findings (38 legacy + 506 scanner) 12th percentile · Go · huge (>500K LoC) Scanner says 96 (lower by 20)
Last scanned 2 weeks, 6 days ago · v1 · 35 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Bug-class explainers. Each card groups findings of the same shape — these are the patterns most likely to ship to prod and reappear in future scans unless you systematically fix the cause, not just the instance.
internal/acctest/statecheck/expect_regional_arn_f…:19
internal/acctest/statecheck/expect_global_arn_no_…:17
internal/acctest/querycheck/expect_no_identity_fu…:18
internal/acctest/knownvalue/regional_hostname_reg…:17
.ci/semgrep/acctest/precheck.go:22
.ci/semgrep/acctest/paralleltest.go:9
.ci/providerlint/passes/AWSAT006/AWSAT006.go:19
.ci/providerlint/passes/AWSAT005/AWSAT005.go:18
.ci/providerlint/passes/AWSAT003/AWSAT003.go:18
internal/service/securityhub/connector_v2.go:187
internal/service/securityhub/connector_v2.go:13
internal/service/securityhub/automation_rule_v2.go:314
This page is publicly accessible at:
https://repobility.com/scan/9a9e7132-3643-4b82-9d1f-4323f23805f3/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/9a9e7132-3643-4b82-9d1f-4323f23805f3/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.