Scan timing: clone 3.68s · analysis 10.34s · 10.2 MB · GitHub API rate-limit (preflight)
https://github.com/typst/typst
· scanned 2026-06-05 10:30 UTC (5 days, 12 hours ago)
· 10 languages
120 raw signals (52 security + 68 graph) 35th percentile · Rust · large (100-500K LoC) System graph score 82 (lower by 18)
Last scanned 5 days, 12 hours ago · v2 · 60 actionable findings from 2 signal sources. 26 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
67.8 | 0.25 | 16.95 |
testing_score |
22.0 | 0.20 | 4.40 |
documentation_score |
88.0 | 0.15 | 13.20 |
practices_score |
97.0 | 0.15 | 14.55 |
code_quality |
61.6 | 0.10 | 6.16 |
| Overall | 1.00 | 64.3 |
Showing 45 of 60 actionable findings. 86 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
crates/typst-cli/src/deps.rs:68
Cargo.lock
Dockerfile:7
CI/CD securitycontainers
Dockerfile:26
Cargo.lock
Cargo.lock
Cargo.lock
crates/typst-cli/src/main.rs:75
Eval used
crates/typst-eval/src/access.rs:22
Eval used
crates/typst-layout/src/inline/deco.rs:114
Eval used
crates/typst/src/lib.rs:123
Eval used
.dockerignore
CI/CD securitycontainers
Dockerfile:27
CI/CD securitycontainers
Dockerfile:27
CI/CD securitycontainers
Dockerfile:9
CI/CD securitycontainers
Cargo.lock
Cargo.lock
Dockerfile:26
containersPinned dependencies
Dockerfile:1
containersPinned dependencies
.github/workflows/docker-image.yml:58
CI/CD securitySupply chainGithub actions
.github/workflows/docker-image.yml
CI/CD securitySupply chainGithub actions
.github/workflows/release.yml
CI/CD securitySupply chainGithub actions
crates/typst-layout/src/introspect.rs:53, 66 (2 hits)tests/src/output.rs:208, 225 (2 hits)crates/typst-cli/src/query.rs:38crates/typst-html/src/introspect.rs:45crates/typst-layout/src/inline/box.rs:27crates/typst-library/src/layout/ratio.rs:8crates/typst-library/src/model/table.rs:21crates/typst-library/src/text/mod.rs:263Dockerfile:2
containersPinned dependencies
This page is publicly accessible at:
https://repobility.com/scan/a505d54a-f679-46d4-852f-a0873e69bc1d/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/a505d54a-f679-46d4-852f-a0873e69bc1d/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.