https://github.com/nocodb/nocodb
· scanned 2026-06-05 09:04 UTC (5 days, 17 hours ago)
· 10 languages
1640 raw signals (130 security + 1510 graph) 10/13 scanners ran 5th percentile · Typescript · huge (>500K LoC) System graph score 55 (higher by 15)
Last scanned 5 days, 17 hours ago · v2 · 800 actionable findings from 2 signal sources. 85 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
37.0 | 0.20 | 7.40 |
documentation_score |
64.0 | 0.15 | 9.60 |
practices_score |
74.0 | 0.15 | 11.10 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 70.1 |
Showing 377 of 800 actionable findings. 885 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/nc-gui/components/smartsheet/grid/PaginationV2.vue:414
docker-compose/nginx-proxy-manager/docker-compose.yml:33
CI/CD securitycontainers
docker-compose/2_pg/docker-compose.yml:14
CI/CD securitycontainers
docker-compose/3_traefik/docker-compose.yml:42, 84 (2 hits)packages/nc-gui/middleware/03.auth.global.ts:185
packages/nc-gui/utils/baseCreateUtils.ts:119, 126, 133, 140 (4 hits)packages/nc-secret-mgr/src/nocodb/cli.js:2 (3 hits)packages/noco-integrations/nocodb-sdk-reference.ts:145
packages/nocodb-sdk/src/lib/formBuilder/index.ts:9
packages/nocodb-sdk/src/lib/XcUIBuilder.ts:42
packages/nocodb/src/modules/auth/ui/auth/resetPassword.ts:89
packages/nocodb/src/services/base-users/ui/auth/resetPassword.ts:89
packages/nocodb/src/types/nc-plugin/common/XcUIBuilder.ts:46
packages/nocodb/src/controllers/notifications.controller.ts:103, 119 (2 hits)packages/nocodb/src/controllers/workspace-users.controller.ts:49
packages/nocodb/src/controllers/workspace-users.controller.ts:30
packages/nocodb/src/controllers/view-columns.controller.ts:90, 124 (2 hits)packages/nocodb/src/controllers/datas.controller.ts:98
packages/nocodb/src/controllers/datas.controller.ts:81
packages/nocodb/src/controllers/view-row-color.controller.ts:76, 106 (2 hits)package.json:1packages/nc-gui/package.json:1packages/noco-integrations/core/package.json:1packages/nocodb/package.json:1packages/nc-gui/store/base.ts:43
packages/nc-gui/composables/useUserSorts.ts:81
packages/nocodb/src/controllers/attachments.controller.ts:214
packages/nocodb/src/controllers/attachments-secure.controller.ts:151
.github/workflows/docker-readme-publish.yml:14 (2 hits).github/workflows/jest-unit-test.yml:28 (2 hits).github/workflows/on-event-issue-closed.yml:14 (2 hits).github/workflows/bats-test.yml:17, 34 (4 hits).github/workflows/dependency-review.yml:23, 26 (4 hits).github/workflows/jest-unit-test.yml:24, 32 (4 hits).github/workflows/ci-cd.yml:34 (2 hits).github/workflows/cleanup-caches-by-branch.yml:11 (2 hits).github/workflows/docker-readme-publish.yml:12 (2 hits).github/workflows/dispatch-oss.yml:12.github/workflows/dco-check.yml:20, 24 (2 hits).github/workflows/dco-check.yml:20, 24 (2 hits)scripts/installLocalSdk.js:7
Exec used
packages/nocodb/src/controllers/views.controller.ts:32, 61, 90, 193 (4 hits)packages/nocodb/src/controllers/extensions.controller.ts:26, 76 (2 hits)packages/nocodb/src/controllers/integrations.controller.ts:31, 82 (2 hits)packages/nocodb/src/controllers/kanbans.controller.ts:25packages/nocodb/src/controllers/view-columns.controller.ts:33packages/nc-gui/composables/useDialog/index.ts:111packages/nc-gui/composables/useProvideChatwoot.ts:55packages/nc-gui/utils/validation.ts:359packages/nc-gui/utils/generateName.ts:7
packages/nc-gui/utils/aliasUtils.ts:5
packages/nc-gui/composables/useUserSync.ts:33
docker-compose/2_pg/docker-compose.yml:2docker-compose/3_traefik/docker-compose.yml:5docker-compose/nginx-proxy-manager/docker-compose.yml:20docker-compose/nginx/docker-compose.yml:20docker-compose/nginx/docker-compose.yml:37
CI/CD securitycontainers
.dockerignore
CI/CD securitycontainers
docker-compose/nginx/docker-compose.yml:37
CI/CD securitycontainers
packages/nc-gui/components/account/UserList.vue:29, 100 (2 hits)packages/nc-gui/components/dashboard/TreeView/Project/ActionMenu.vue:134, 142 (2 hits)packages/nc-gui/components/account/UsersModal.vue:151packages/nc-gui/components/dashboard/settings/base/Migrate.vue:25packages/nc-gui/components/dlg/QuickImport.vue:252packages/nc-gui/components/smartsheet/details/Api.vue:77packages/nc-secret-mgr/src/nocodb/cli.js:2packages/nc-gui/utils/cryptoUtils.ts:5
Weak hash
packages/nc-gui/utils/dataUtils.ts:74
Weak hash
docker-compose/2_pg/docker-compose.yml:2
CI/CD securitycontainers
docker-compose/2_pg/docker-compose.yml:2
CI/CD securitycontainers
docker-compose/nginx/docker-compose.yml:37
CI/CD securitycontainers
docker-compose/3_traefik/docker-compose.yml:100
CI/CD securitycontainers
package.jsonpackages/nc-gui/package.jsonpackages/nocodb-sdk/package.jsonShowing first 300 of 377. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/ac9bfbed-85b8-40b6-bc96-88903626f9c2/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/ac9bfbed-85b8-40b6-bc96-88903626f9c2/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.