https://github.com/rakheen-dama/b2b-strawman
· scanned 2026-06-15 23:47 UTC (2 months, 3 weeks ago)
258 raw signals (0 security + 258 graph)
Last scanned 2 months, 3 weeks ago · v1 · 236 actionable findings from 1 signal source. 22 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
Showing 112 of 236 actionable findings. 258 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
backend/src/main/java/io/b2mash/b2b/b2bstrawman/accessrequest/AccessRequestApprovalService.java:36
compose/scripts/keycloak-bootstrap.sh:254
compose/.env.keycloak
ConfigEnv fileRuntime env
frontend/.env.keycloak
ConfigEnv fileRuntime env
infra/CLAUDE.md:16
SecretsClaude instruction
.claude/ideas/branding-kazi-2026-03-22.md
VerificationClaude instruction
.claude/ideas/phase18-ideation-2026-02-20.md
VerificationClaude instruction
.claude/ideas/phase29-ideation-2026-02-27.md
VerificationClaude instruction
.claude/ideas/phase44-ideation-2026-03-10.md
VerificationClaude instruction
.claude/ideas/phase45-ideation-2026-03-12.md
VerificationClaude instruction
.claude/ideas/phase62-ideation-2026-04-04.md
VerificationClaude instruction
.claude/ideas/phase66-ideation-2026-04-17.md
VerificationClaude instruction
.claude/ideas/phase68-ideation-2026-04-18.md
VerificationClaude instruction
.claude/ideas/phase75-ideation-2026-05-27.md
VerificationClaude instruction
.claude/ideas/template-extraction-ideation-2026-03-29.md
VerificationClaude instruction
.claude/settings.json
VerificationClaude instruction
infra/CLAUDE.md
VerificationClaude instruction
.github/workflows/deploy-staging.yml:82, 120, 153, 186, 222, 258 (6 hits).github/workflows/deploy-prod.yml:73, 110, 148 (3 hits).github/workflows/qodana_code_quality.yml:27.github/workflows/seed-images.yml:91.github/workflows/ci.yml.github/workflows/deploy-prod.yml.github/workflows/deploy-staging.yml.github/workflows/qodana_code_quality.yml.github/workflows/rollback.yml.github/workflows/seed-images.yml.github/workflows/terraform.ymlcompose/mock-idp/src/index.ts:11
Cors wildcard
compose/keycloak/theme/src/login/pages/Error.tsx:39
Dangerous innerhtml
compose/keycloak/theme/src/login/pages/Info.tsx:29
Dangerous innerhtml
compose/keycloak/theme/src/login/pages/Login.tsx:26
Dangerous innerhtml
compose/keycloak/theme/src/login/pages/LoginPassword.tsx:26
Dangerous innerhtml
compose/keycloak/theme/src/login/pages/LoginResetPassword.tsx:31
Dangerous innerhtml
compose/keycloak/theme/src/login/pages/LoginUsername.tsx:26
Dangerous innerhtml
compose/keycloak/theme/src/login/pages/Register.tsx:29
Dangerous innerhtml
frontend/app/portal/(authenticated)/proposals/[id]/page.tsx:315
Dangerous innerhtml
portal/app/(authenticated)/proposals/[id]/page.tsx:278
Dangerous innerhtml
frontend/components/auth/mock-login-form.tsx:48
Local storage auth token
frontend/lib/auth/client/hooks.ts:88
Local storage auth token
portal/e2e/helpers/auth.ts:79
Local storage auth token
tools/claude-slack-bot/src/claudeRunner.ts:1
Node child process
backend/src/main/java/io/b2mash/b2b/b2bstrawman/billing/SubscriptionItnService.java:306
Weak hash
qa_cycle/_archive_2026-04-30_legal-clean-slate/checkpoint-results/day-02-conflict-check-clear.yml
Ports
compose/seed/Dockerfile:1
containersPinned dependencies
gateway/Dockerfile:2
containersPinned dependencies
backend/Dockerfile:2
containersPinned dependencies
gateway/Dockerfile:21
containersPinned dependencies
backend/Dockerfile:21
containersPinned dependencies
frontend/Dockerfile:6, 23, 59 (3 hits)portal/Dockerfile:6, 23, 51 (3 hits)compose/mock-idp/Dockerfile:1, 11 (2 hits).github/workflows/terraform.yml:68
CI/CD securitySupply chainGithub actions
docs/package.json
LockfileReproducibilityGenerated repo pattern
frontend/package.json
LockfileReproducibilityGenerated repo pattern
packages/ui/package.json
LockfileReproducibilityGenerated repo pattern
portal/package.json
LockfileReproducibilityGenerated repo pattern
This page is publicly accessible at:
https://repobility.com/scan/b2371094-847a-4423-90d1-d283421ed977/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/b2371094-847a-4423-90d1-d283421ed977/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.