Scan timing: clone 7.09s · analysis 22.61s · 14.6 MB · GitHub API rate-limit (preflight)
https://github.com/jdx/mise
· scanned 2026-06-05 23:58 UTC (4 days, 2 hours ago)
· 10 languages
256 raw signals (154 security + 102 graph) 19th percentile · Rust · large (100-500K LoC) System graph score 71 (lower by 13)
Last scanned 4 days, 2 hours ago · v2 · 96 actionable findings from 2 signal sources. 109 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
30.0 | 0.25 | 7.50 |
testing_score |
20.0 | 0.20 | 4.00 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
97.0 | 0.15 | 14.55 |
code_quality |
42.3 | 0.10 | 4.23 |
| Overall | 1.00 | 58.0 |
Showing 74 of 96 actionable findings. 205 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
crates/vfox/embedded-plugins/vfox-azure-functions-core-tools/hooks/post_install.lua:11crates/vfox/embedded-plugins/vfox-chicken/hooks/post_install.lua:47crates/vfox/embedded-plugins/vfox-leiningen/hooks/post_install.lua:63scripts/release-alpine.sh:22
src/gitlab.rs:456, 534 (2 hits)docs/.vitepress/config.ts:256e2e/cli/test_token_forgejo:56e2e/env/test_env_cache:7e2e/env/test_env_cache_fresh:9e2e/env/test_env_cache_venv:24.github/workflows/release.yml:22, 23, 24, 33, 34, 77, 78, 90, +5 more (13 hits).github/workflows/registry.yml:21, 58, 197, 355 (4 hits).github/workflows/test.yml:21, 22, 23, 244 (4 hits).github/workflows/docs.yml:41, 58, 59 (3 hits).github/workflows/hyperfine.yml:16src/tokens.rs:205
src/sops.rs:219
e2e/helpers/scripts/tool_stub_test_server.py:17, 18, 19, 20, 21, 22, 23, 24, +5 more (13 hits)e2e/fixtures/mock-github-oauth.py:22, 23, 26, 34, 35, 37, 38, 42, +4 more (12 hits)Cargo.lock
bun.lock
Cargo.lock
Cargo.lock
.github/workflows/copr-publish.yml:27
crates/aqua-registry/src/types.rs:451
Eval used
crates/vfox/src/plugin.rs:269
Eval used
src/backend/version_list.rs:158
Eval used
src/shell/elvish.rs:26
Eval used
src/git.rs:125
Exec used
e2e/helpers/scripts/git_http_backend_server.py:102
Error handlingquality
Dockerfile:12packaging/alpine/Dockerfile:1packaging/copr/Dockerfile:1packaging/deb/Dockerfile:1packaging/e2e/Dockerfile:1packaging/mise/Dockerfile:12packaging/rpm/Dockerfile:1packaging/mise/Dockerfile:9
CI/CD securitycontainers
Dockerfile:9
CI/CD securitycontainers
packaging/mise/Dockerfile:10
CI/CD securitycontainers
Dockerfile:10
CI/CD securitycontainers
.github/workflows/cloudflare-deploy.yml:36Cross.toml:23README.md:70docs/continuous-integration.md:12docs/dev-tools/backends/cargo.md:14docs/index.md:103docs/mise-cookbook/docker.md:26bun.lock
.github/workflows/docker.yml.github/workflows/npm-publish.yml.github/workflows/release-plz.yml.github/workflows/release.ymlpackaging/deb/generate-release.sh:33
Weak hash
packaging/mise/Dockerfile
Ports
.dockerignore
CI/CD securitycontainers
packaging/deb/Dockerfile:4
CI/CD securitycontainers
src/gitlab.rs:47, 186 (2 hits)crates/aqua-registry/src/compiled.rs:150src/backend/s3.rs:54src/cli/deps/remove.rs:11src/cli/plugins/update.rs:44src/cli/self_update_stub.rs:22src/cli/settings/unset.rs:22src/cli/sync/ruby.rs:19package.json
package.json
package.json
package.json
package.json
src/cli/self_update.rs:1
e2e/helpers/scripts/git_http_backend_server.py:21
e2e/fixtures/mock-github-oauth.py:21
e2e/helpers/scripts/git_http_backend_server.py:24
e2e/helpers/scripts/git_http_backend_server.py:152
e2e/fixtures/mock-github-oauth.py:72
This page is publicly accessible at:
https://repobility.com/scan/a5fdea63-240b-4284-a302-db36a2a52933/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/a5fdea63-240b-4284-a302-db36a2a52933/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.