Scan timing: clone 5.54s · analysis 11.22s · 1.4 MB · GitHub API rate-limit (preflight)
https://github.com/nektos/act
· scanned 2026-06-05 08:30 UTC (5 days, 19 hours ago)
· 10 languages
294 raw signals (150 security + 144 graph) 50th percentile · Go · medium (20-100K LoC)
Last scanned 5 days, 19 hours ago · v2 · 152 actionable findings from 2 signal sources. 70 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
30.0 | 0.25 | 7.50 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
77.0 | 0.15 | 11.55 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
65.5 | 0.10 | 6.55 |
| Overall | 1.00 | 69.3 |
Showing 121 of 152 actionable findings. 222 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
pkg/gh/gh.go:20
pkg/container/host_environment.go:301
.github/actions/choco/Dockerfile:1pkg/runner/testdata/actions-environment-and-context-tests/docker/Dockerfile:1pkg/runner/testdata/actions/action1/Dockerfile:1pkg/runner/testdata/actions/docker-local-noargs/Dockerfile:2pkg/runner/testdata/actions/docker-local/Dockerfile:2pkg/runner/testdata/docker-action-host-env/action/Dockerfile:1pkg/runner/testdata/localdockerimagetest_/Dockerfile:1.github/workflows/checks.yml:18, 21, 39, 44, 74, 77, 93, 94, +12 more (32 hits).github/workflows/release.yml:17, 20, 43 (3 hits).github/workflows/codespell.yml:21 (2 hits).github/workflows/promote.yml:13, 24 (2 hits)go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
pkg/common/executor.go:136
Exec used
pkg/container/host_environment.go:285
Exec used
.dockerignore
CI/CD securitycontainers
.github/actions/choco/Dockerfile:1pkg/runner/testdata/actions-environment-and-context-tests/docker/Dockerfile:1pkg/runner/testdata/actions/action1/Dockerfile:1pkg/runner/testdata/actions/docker-local-noargs/Dockerfile:2pkg/runner/testdata/actions/docker-local/Dockerfile:2pkg/runner/testdata/docker-action-host-env/action/Dockerfile:1pkg/runner/testdata/localdockerimagetest_/Dockerfile:1go.mod
go.mod
go.mod
.github/workflows/release.yml
CI/CD securitySupply chainGithub actions
pkg/artifactcache/storage.go:51pkg/common/file.go:29pkg/model/planner.go:129pkg/container/host_environment.go:85pkg/runner/job_executor.go:160pkg/runner/local_repository_cache.go:44pkg/runner/step_run.go:114pkg/runner/testdata/actions/node16/index.js:1pkg/runner/testdata/uses-composite-check-for-input-shadowing/action-with-pre-and-post/main.js:1pkg/runner/testdata/uses-composite-check-for-input-shadowing/action-with-pre-and-post/post.js:1go.mod
pkg/runner/testdata/actions/node12/package.jsonpkg/runner/testdata/actions/node16/package.jsonpkg/runner/testdata/actions/node20/package.json.github/actions/choco/Dockerfile:1
containersPinned dependencies
This page is publicly accessible at:
https://repobility.com/scan/aac9bb52-1a7d-4860-b0f2-e656ed715089/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/aac9bb52-1a7d-4860-b0f2-e656ed715089/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.