https://github.com/django/django
· scanned 2026-05-16 16:20 UTC (1 day, 1 hour ago)
· 10 languages
549 findings (48 legacy + 501 scanner) 8/10 scanners ran 57th percentile · Python · huge (>500K LoC) Scanner says 73 (higher by 8)
Last scanned 1 day, 1 hour ago · v1 · 549 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Showing 526 of 549 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
django/db/backends/oracle/creation.py:292
credential_exposurelegacy
django/contrib/auth/management/commands/changepassword.py:17
secrets
django/db/backends/oracle/creation.py:292
secrets
django/core/files/storage/filesystem.py:48
ssrflegacy
django/core/files/storage/base.py:174
ssrflegacy
django/core/cache/backends/redis.py:87
ssrflegacy
django/views/i18n.py:56
open_redirectlegacy
django/middleware/csrf.py:258
injectionlegacy
django/db/migrations/questioner.py:168
owaspeval_used
scripts/manage_translations.py:403
owaspeval_used
django/core/management/commands/shell.py:88
owaspexec_used
django/apps/config.py:112
error_handlinglegacy
django/utils/http.py:146
error_handlinglegacy
django/http/response.py:336
error_handlinglegacy
django/utils/version.py:90
injectionlegacy
django/core/cache/backends/locmem.py:43
deserializationlegacy
django/core/cache/backends/filebased.py:38
deserializationlegacy
django/core/cache/backends/db.py:96
deserializationlegacy
.well-known/security.txt
qualitylegacy
django/views/generic/edit.py:185
authauth.django.unauth_view
django/views/generic/edit.py:165
authauth.django.unauth_view
django/views/generic/edit.py:137
authauth.django.unauth_view
django/views/generic/base.py:231
authauth.django.unauth_view
django/views/generic/base.py:221
authauth.django.unauth_view
django/views/generic/edit.py:209
authauth.django.unauth_view
django/contrib/gis/views.py:5
authowaspauth.django.unauth_view
django/contrib/flatpages/views.py:22
authowaspauth.django.unauth_view
django/contrib/gis/sitemaps/views.py:10
authowaspauth.django.unauth_view
django/contrib/gis/sitemaps/views.py:61
authowaspauth.django.unauth_view
django/contrib/flatpages/views.py:49
authowaspauth.django.unauth_view
django/contrib/staticfiles/views.py:16
authowaspauth.django.unauth_view
django/contrib/contenttypes/views.py:9
authowaspauth.django.unauth_view
.github/workflows/linters.yml:71
supply-chaingithub-actionspinned-dependencies
django/utils/version.py:93
owaspsubprocess_shell_true
scripts/manage_translations.py:201
owaspsubprocess_shell_true
django/db/backends/sqlite3/_functions.py:72
owaspweak_hash
django/db/models/functions/__init__.py:55
owaspweak_hash
django/db/models/functions/text.py:216
owaspweak_hash
scripts/verify_release.sh:63
owaspweak_hash
django/contrib/contenttypes/views.py:57
integrityn-plus-oneperformance
django/contrib/contenttypes/views.py:73
integrityn-plus-oneperformance
django/conf/locale/sr/formats.py:16
qualitylegacy
django/conf/locale/sk/formats.py:8
qualitylegacy
django/conf/locale/ru/formats.py:5
qualitylegacy
django/conf/locale/pt/formats.py:11
qualitylegacy
django/conf/locale/nn/formats.py:11
qualitylegacy
django/conf/locale/nn/formats.py:1
qualitylegacy
django/conf/locale/nb/formats.py:11
qualitylegacy
django/conf/locale/ms/formats.py:17
qualitylegacy
django/conf/locale/ms/formats.py:11
qualitylegacy
django/conf/locale/ml/formats.py:13
qualitylegacy
django/conf/locale/lv/formats.py:8
qualitylegacy
django/conf/locale/ky/formats.py:9
qualitylegacy
django/conf/locale/ig/formats.py:4
qualitylegacy
django/conf/locale/ht/formats.py:9
qualitylegacy
django/conf/locale/ht/formats.py:8
qualitylegacy
django/conf/locale/fr_CH/formats.py:1
qualitylegacy
django/conf/locale/fr_CA/formats.py:9
qualitylegacy
django/conf/locale/es_PR/formats.py:12
qualitylegacy
django/conf/locale/es_PR/formats.py:9
qualitylegacy
django/conf/locale/es_NI/formats.py:9
qualitylegacy
django/conf/locale/es_NI/formats.py:1
qualitylegacy
django/conf/locale/es_MX/formats.py:9
qualitylegacy
django/conf/locale/es_CO/formats.py:13
qualitylegacy
django/conf/locale/es_AR/formats.py:9
qualitylegacy
django/conf/locale/es/formats.py:8
qualitylegacy
django/conf/locale/en_IE/formats.py:16
qualitylegacy
django/conf/locale/en_GB/formats.py:9
qualitylegacy
django/conf/locale/en_AU/formats.py:9
qualitylegacy
django/conf/locale/en/formats.py:9
qualitylegacy
django/conf/locale/de_CH/formats.py:1
qualitylegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
.github/workflows/python_matrix.yml:26
supply-chaingithub-actionspinned-dependencies
.github/workflows/python_matrix.yml:43
supply-chaingithub-actionspinned-dependencies
.github/workflows/python_matrix.yml:47
supply-chaingithub-actionspinned-dependencies
.github/workflows/postgis.yml:42
supply-chaingithub-actionspinned-dependencies
.github/workflows/postgis.yml:46
supply-chaingithub-actionspinned-dependencies
.github/workflows/selenium.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/selenium.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/selenium.yml:64
supply-chaingithub-actionspinned-dependencies
.github/workflows/selenium.yml:68
supply-chaingithub-actionspinned-dependencies
.github/workflows/coverage_comment.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/coverage_comment.yml:39
supply-chaingithub-actionspinned-dependencies
.github/workflows/check-migrations.yml:44
supply-chaingithub-actionspinned-dependencies
.github/workflows/check-migrations.yml:49
supply-chaingithub-actionspinned-dependencies
.github/workflows/docs.yml:31
supply-chaingithub-actionspinned-dependencies
.github/workflows/docs.yml:35
supply-chaingithub-actionspinned-dependencies
.github/workflows/check_pr_quality.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/check_pr_quality.yml:32
supply-chaingithub-actionspinned-dependencies
.github/workflows/labels.yml:25
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:17
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:31
supply-chaingithub-actionspinned-dependencies
.github/workflows/linters.yml:27
supply-chaingithub-actionspinned-dependencies
.github/workflows/linters.yml:31
supply-chaingithub-actionspinned-dependencies
.github/workflows/linters.yml:47
supply-chaingithub-actionspinned-dependencies
.github/workflows/linters.yml:51
supply-chaingithub-actionspinned-dependencies
.github/workflows/linters.yml:67
supply-chaingithub-actionspinned-dependencies
.github/workflows/linters.yml:78
supply-chaingithub-actionspinned-dependencies
.github/workflows/linters.yml:92
supply-chaingithub-actionspinned-dependencies
.github/workflows/linters.yml:96
supply-chaingithub-actionspinned-dependencies
.github/workflows/screenshots.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/screenshots.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/screenshots.yml:46
supply-chaingithub-actionspinned-dependencies
.github/workflows/screenshots.yml:63
supply-chaingithub-actionspinned-dependencies
django/views/debug.py:29
owaspdebug_true
docs/_ext/djangodocs.py:396
dead-code
docs/_ext/djangodocs.py:244
dead-code
docs/_ext/djangodocs.py:148
dead-code
docs/_ext/djangodocs.py:123
dead-code
docs/_ext/djangodocs.py:172
dead-code
docs/lint.py:20
dead-code
django/utils/dateformat.py:114
dead-code
django/utils/dateformat.py:118
dead-code
django/utils/dateformat.py:122
dead-code
docs/_ext/djangodocs.py:386
dead-code
django/utils/dateformat.py:126
dead-code
docs/lint.py:62
dead-code
django/utils/dateformat.py:130
dead-code
django/utils/dateformat.py:145
dead-code
docs/_ext/djangodocs.py:184
dead-code
django/utils/dateformat.py:158
dead-code
django/utils/dateformat.py:162
dead-code
django/utils/dateformat.py:173
dead-code
docs/conf.py:453
dead-code
docs/_ext/github_links.py:30
dead-code
docs/_ext/djangodocs.py:239
dead-code
docs/_ext/djangodocs.py:249
dead-code
docs/_ext/djangodocs.py:128
dead-code
docs/_ext/github_links.py:27
dead-code
docs/_ext/github_links.py:33
dead-code
docs/_ext/djangodocs.py:116
dead-code
docs/_ext/djangodocs.py:165
dead-code
docs/_ext/djangodocs.py:277
dead-code
Showing first 300 of 526. Refine filters or use the legacy findings page for deep search.
{# ── 2026-05-17 Round 14: AI-agent bridge footer ────────────────────── Discoverability: the /agents/voting/ guide + MCP manifest exist but aren't linked from anywhere users actually land. Small, opt-in footer. #}
This page is publicly accessible at:
https://repobility.com/scan/ae0fafd5-ca42-4d82-9dcd-8a318ddbf0a9/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/ae0fafd5-ca42-4d82-9dcd-8a318ddbf0a9/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.