Scan timing: clone 4.63s · analysis 4.63s · 2.8 MB · GitHub preflight 418ms
https://github.com/headlesshq/headlessmc
· scanned 2026-05-21 20:49 UTC (2 weeks ago)
· 10 languages
154 findings (76 legacy + 78 scanner) 50th percentile · Java · medium (20-100K LoC) Scanner says 80 (lower by 9)
Last scanned 2 weeks ago · v2 · 115 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
78.2 | 0.25 | 19.55 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
64.0 | 0.15 | 9.60 |
practices_score |
80.0 | 0.15 | 12.00 |
code_quality |
78.7 | 0.10 | 7.87 |
| Overall | 1.00 | 71.0 |
Showing 84 of 115 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
headlessmc-launcher/src/main/java/io/github/headlesshq/headlessmc/launcher/mods/files/PaperModFileReader.java:35
qualitylegacy
headlessmc-launcher/src/main/java/io/github/headlesshq/headlessmc/launcher/mods/files/PaperModFileReader.java:35
qualitylegacy
headlessmc-launcher/src/main/java/io/github/headlesshq/headlessmc/launcher/mods/files/PaperModFileReader.java:35
deserializationlegacy
.github/workflows/lifecycle.yml:747
dependencylegacy
.github/workflows/lifecycle.yml:684
dependencylegacy
.github/workflows/lifecycle.yml:746
dependencylegacy
.github/workflows/lifecycle.yml:683
dependencylegacy
headlessmc-launcher/src/main/java/io/github/headlesshq/headlessmc/launcher/version/LibraryImpl.java:22
qualitylegacy
headlessmc-launcher/src/main/java/io/github/headlesshq/headlessmc/launcher/version/LibraryFactory.java:52
qualitylegacy
headlessmc-launcher/src/main/java/io/github/headlesshq/headlessmc/launcher/mods/modrinth/ModrinthFile.java:21
qualitylegacy
buildSrc/src/main/groovy/io/github/headlesshq/headlessmc/gradle/GenerateModuleTask.groovy:14
qualitylegacy
buildSrc/src/main/groovy/io/github/headlesshq/headlessmc/gradle/Extension2ClassWriterAdapter.groovy:15
qualitylegacy
.github/workflows/lifecycle.yml:148
dependencylegacy
.github/workflows/lifecycle.yml:216
dependencylegacy
.github/workflows/lifecycle.yml:61
dependencylegacy
.github/workflows/lifecycle.yml:31
dependencylegacy
.github/workflows/run-matrix-in-memory.yml:17
dependencylegacy
.github/workflows/lifecycle.yml:204
dependencylegacy
.github/workflows/lifecycle.yml:196
dependencylegacy
.github/workflows/run-matrix-in-memory.yml:106
dependencylegacy
.github/workflows/lifecycle.yml:62
dependencylegacy
.github/workflows/lifecycle.yml:32
dependencylegacy
.github/workflows/run-matrix-in-memory.yml:102
dependencylegacy
.github/workflows/run-matrix-in-memory.yml:18
dependencylegacy
.github/workflows/lifecycle.yml:143
dependencylegacy
.github/workflows/lifecycle.yml:125
dependencylegacy
.github/workflows/lifecycle.yml:50
dependencylegacy
.github/workflows/run-matrix-in-memory.yml:40
dependencylegacy
.github/workflows/lifecycle.yml:182
dependencylegacy
.github/workflows/lifecycle.yml:217
dependencylegacy
.github/workflows/run-matrix-in-memory.yml:113
dependencylegacy
.github/workflows/lifecycle.yml:75
dependencylegacy
gradle/wrapper/gradle-wrapper.jar:1
dependencylegacy
Dockerfile:5
dockerlegacy
Fast.Dockerfile:12
dependencylegacy
Dockerfile:16
dependencylegacy
Fast.Dockerfile:6
dependencylegacy
Dockerfile:3
dependencylegacy
Fast.Dockerfile:13
dependencylegacy
Dockerfile:17
dependencylegacy
Fast.Dockerfile:10
dependencylegacy
Dockerfile:14
dependencylegacy
headlessmc-launcher/src/main/java/io/github/headlesshq/headlessmc/launcher/mods/files/PaperModFileReader.java:35
deserializationlegacy
headlessmc-java/src/main/java/io/github/headlesshq/headlessmc/java/download/ArchiveExtractor.java:43
path_traversallegacy
.dockerignore
dockerlegacy
Dockerfile:17
dockerlegacy
.github/workflows/run-matrix-in-memory.yml:113
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:75
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:381
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:466
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:536
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:664
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:669
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:672
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:681
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml
supply-chaingithub-actionsleast-privilege
headlessmc-auth/src/main/java/io/github/headlesshq/headlessmc/auth/AbstractLoginCommand.java:261
qualitylegacy
headlessmc-api/src/main/java/io/github/headlesshq/headlessmc/api/command/impl/MemoryCommand.java:39
qualitylegacy
headlessmc-api/src/main/java/io/github/headlesshq/headlessmc/api/classloading/ApiClassloadingHelper.java:46
qualitylegacy
headlessmc-launcher/src/main/java/io/github/headlesshq/headlessmc/launcher/server/downloader/ModLauncherCommandDownloader.java:29
qualitylegacy
headlessmc-launcher/src/main/java/io/github/headlesshq/headlessmc/launcher/server/downloader/ForgeDownloader.java:43
qualitylegacy
Dockerfile:16
supply-chaindockerpinned-dependencies
Dockerfile:3
supply-chaindockerpinned-dependencies
Dockerfile:17
supply-chaindockerpinned-dependencies
Dockerfile:14
supply-chaindockerpinned-dependencies
.github/workflows/run-matrix-in-memory.yml:40
supply-chaingithub-actionspinned-dependencies
.github/workflows/run-matrix-in-memory.yml:102
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:50
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:125
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:182
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:204
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:224
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:276
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:306
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:368
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:453
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:513
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:563
supply-chaingithub-actionspinned-dependencies
.github/workflows/lifecycle.yml:610
supply-chaingithub-actionspinned-dependencies
headlessmc-scripts/version.py:9
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/aacccc06-97b5-40f6-a398-8d90565325f3/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/aacccc06-97b5-40f6-a398-8d90565325f3/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.