Scan timing: clone 6.37s · analysis 25.73s · 31.9 MB · GitHub API rate-limit (preflight)
https://github.com/go-gitea/gitea
· scanned 2026-06-05 10:17 UTC (5 days, 14 hours ago)
· 10 languages
445 raw signals (119 security + 326 graph) 11/13 scanners ran 91st percentile · Go · large (100-500K LoC) System graph score 74 (higher by 17)
Last scanned 5 days, 14 hours ago · v2 · 217 actionable findings from 2 signal sources. 65 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
90.0 | 0.15 | 13.50 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 90.5 |
Showing 125 of 217 actionable findings. 282 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
services/auth/source/smtp/auth.go:36
services/mailer/sender/smtp_auth.go:34
Dockerfile:12, 46 (2 hits)Dockerfile.rootless:12, 41 (2 hits)modules/gitrepo/gitrepo.go:56
modules/log/event_writer_file.go:34
modules/git/repo_index.go:113
modules/private/internal.go:60
modules/process/manager_exec.go:52services/mailer/sender/sendmail.go:50tools/lint-go-all.go:67modules/process/error.go:19
Exec used
modules/lfs/transferadapter.go:54
modules/httplib/serve.go:166
modules/lfs/transferadapter.go:57
modules/web/middleware/cookie.go:38
modules/git/repo.go:125
web_src/js/features/common-button.ts:73web_src/js/features/install.ts:98web_src/js/features/repo-issue-list.ts:112cmd/web_https.go:21
.dockerignore
CI/CD securitycontainers
Dockerfile:47
CI/CD securitycontainers
Dockerfile:8, 29 (2 hits)Dockerfile.rootless:8, 28 (2 hits)models/issues/issue_update.go:1models/user/user_update.go:1routers/web/repo/issue_new.go:1index.html
.github/workflows/cron-licenses.yml.github/workflows/cron-translations.yml.github/workflows/release-nightly.yml.github/workflows/release-tag-rc.yml.github/workflows/release-tag-version.ymlcmd/admin_auth_smtp.go:28
Weak hash
options/locale/locale_cs-CZ.json:880
Weak hash
options/locale/locale_de-DE.json:872
Weak hash
options/locale/locale_en-US.json:1005
Weak hash
options/locale/locale_fr-FR.json:1005
Weak hash
options/locale/locale_ga-IE.json:1005
Weak hash
options/locale/locale_ja-JP.json:1005
Weak hash
options/locale/locale_pt-BR.json:934
Weak hash
options/locale/locale_pt-PT.json:998
Weak hash
options/locale/locale_tr-TR.json:1007
Weak hash
options/locale/locale_uk-UA.json:891
Weak hash
options/locale/locale_zh-CN.json:1005
Weak hash
options/locale/locale_zh-TW.json:886
Weak hash
routers/api/packages/chef/auth.go:170
Weak hash
services/auth/source/smtp/auth.go:47
Weak hash
services/mailer/sender/smtp.go:108
Weak hash
services/packages/alpine/repository.go:301
Weak hash
services/packages/debian/repository.go:232
Weak hash
.dockerignore
CI/CD securitycontainers
cmd/actions.go:52cmd/admin_user_create.go:134cmd/doctor.go:153cmd/migrate_storage.go:195models/issues/issue_list.go:133models/packages/package_version.go:197modules/git/commit_info_nogogit.go:47modules/git/pipeline/revlist.go:26build:1
llms.txt
humans.txt
sitemap.xml
public/.well-known/security.txt
web_src/js/features/repo-new.ts:1
services/packages/package_update.go:1
Dockerfile:46
containersPinned dependencies
Dockerfile:3, 12 (2 hits)
This page is publicly accessible at:
https://repobility.com/scan/9ddf74f5-e0e0-4f6b-a0b9-76c2b098dce1/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/9ddf74f5-e0e0-4f6b-a0b9-76c2b098dce1/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.