Scan timing: clone 4.79s · analysis 19.54s · 101.0 MB · GitHub API rate-limit (preflight)
https://github.com/facebookincubator/Glean
· scanned 2026-06-05 16:45 UTC (4 days, 23 hours ago)
· 10 languages
205 raw signals (93 security + 112 graph) 11/13 scanners ran 100th percentile · Cpp · medium (20-100K LoC) System graph score 79 (higher by 3)
Last scanned 4 days, 23 hours ago · v2 · 76 actionable findings from 2 signal sources. 48 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
97.0 | 0.15 | 14.55 |
practices_score |
77.0 | 0.15 | 11.55 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 82.1 |
Showing 56 of 76 actionable findings. 124 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
glean/shell/Glean/Shell/Types.hs:15
glean/shell/Glean/Shell/Index.hs:42
glean/shell/Glean/Shell/Types.hs:15
glean/shell/Glean/Shell/Index.hs:42
glean/shell/Glean/Shell/Types.hs:15
glean/shell/Glean/Shell/Index.hs:42
Dockerfile:1, 42 (2 hits)Dockerfile:9
.github/workflows/ci.yml:19
.github/workflows/ci.yml:23, 47, 69, 79, 214, 216, 221 (14 hits).github/workflows/ci-aarch64.yml:20, 122, 124, 129 (8 hits).github/workflows/gh_pages.yml:18 (2 hits).github/workflows/glean-docker.yml:22 (2 hits).github/workflows/glean-docker.yml:26, 29, 36 (3 hits).github/workflows/gh_pages.yml:32 (2 hits)glean/lang/java-alpha/index_and_extract.py:40
glean/lang/java-alpha/debug.py:39
glean/db/Glean/Database/Env.hs:162
Dockerfile:43
CI/CD securitycontainers
Dockerfile:9
CI/CD securitycontainers
Dockerfile:1
CI/CD securitycontainers
.github/workflows/ci.yml:96
Dockerfile:1
containersPinned dependencies
Dockerfile:9
containersChecksum
glean/lang/java-alpha/sync_to_xplat.py:83
Weak hash
.dockerignore
CI/CD securitycontainers
Dockerfile:5, 50 (2 hits)glean/client/swift/GlassSwiftRemoteClient.cpp:11glean/lang/java-alpha/index_and_extract.py:12glean/lang/java-alpha/indexer/java/com/facebook/glean/descriptors/MethodDescriptor.java:37glean/rocksdb/container-impl.h:25glean/rocksdb/database-impl.cpp:4glean/rocksdb/database-impl.h:13glean/rts/lookup.h:65glean/rts/query.h:19Dockerfile:42
containersPinned dependencies
repo-level (3 hits)
This page is publicly accessible at:
https://repobility.com/scan/9f7b24e9-5493-41b2-9242-dd59f1f83a99/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/9f7b24e9-5493-41b2-9242-dd59f1f83a99/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.