Scan timing: clone 15.72s · analysis 32.49s · 44.2 MB · GitHub API rate-limit (preflight)
https://github.com/openai/codex
· scanned 2026-06-05 07:00 UTC (5 days, 21 hours ago)
· 10 languages
691 raw signals (159 security + 532 graph) 11/13 scanners ran 38th percentile · Rust · huge (>500K LoC) System graph score 86 (lower by 7)
Last scanned 5 days, 21 hours ago · v2 · 299 actionable findings from 2 signal sources. 116 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
73.0 | 0.20 | 14.60 |
documentation_score |
83.0 | 0.15 | 12.45 |
practices_score |
84.0 | 0.15 | 12.60 |
code_quality |
50.0 | 0.10 | 5.00 |
| Overall | 1.00 | 78.7 |
Showing 263 of 299 actionable findings. 415 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
codex-rs/feedback/src/feedback_diagnostics.rs:103
.github/workflows/bazel.yml:86, 182, 284, 371, 464, 509 (6 hits).github/workflows/v8-canary.yml:182, 216 (2 hits).github/workflows/rust-ci.yml:203.github/workflows/sdk.yml:82scripts/mock_responses_websocket_server.py:203
codex-rs/windows-sandbox-rs/sandbox_smoketests.py:152, 153, 154, 155, 156, 160, 162, 165, +6 more (14 hits)scripts/codex_package/targets.py:26.devcontainer/Dockerfile:1.devcontainer/Dockerfile.secure:1.github/workflows/Dockerfile.bazel:1.github/workflows/rust-release-zsh.yml:25, 30 (2 hits)codex-rs/linux-sandbox/src/launcher.rs:41
codex-rs/exec-server/src/client/reqwest_http_client.rs:125
codex-rs/aws-auth/src/signing.rs:38
.devcontainer/Dockerfile.secure:53, 80 (2 hits).devcontainer/Dockerfile:21codex-rs/.github/workflows/cargo-audit.yml:22 (2 hits)codex-rs/.github/workflows/cargo-audit.yml:19
CI/CD securitySupply chainGitHub Actions
.devcontainer/Dockerfile:21
containersRemote installer
codex-rs/core/src/exec.rs:523
Exec used
codex-rs/skills/src/assets/samples/skill-installer/scripts/install-skill-from-github.py:112
sdk/python/src/openai_codex/client.py:263, 589, 650 (3 hits)codex-rs/windows-sandbox-rs/sandbox_smoketests.py:176sdk/python/src/openai_codex/retry.py:31.dockerignore
CI/CD securitycontainers
.dockerignore
CI/CD securitycontainers
codex-rs/app-server-daemon/README.md:39
README.md:19
.github/workflows/cla.yml.github/workflows/python-runtime-release.yml.github/workflows/python-sdk-release.yml.github/workflows/rust-release-prepare.yml.github/workflows/rust-release-windows.yml.github/workflows/rust-release.yml.github/workflows/rusty-v8-release.yml.devcontainer/Dockerfile:5
CI/CD securitycontainers
codex-rs/config/src/mcp_types_tests.rs:392, 394, 396 (3 hits)codex-rs/codex-api/src/endpoint/models.rs:115, 120 (2 hits)codex-rs/codex-api/src/endpoint/realtime_call.rs:244, 250 (2 hits)codex-rs/app-server-protocol/src/protocol/v2/turn.rs:53codex-rs/app-server/src/request_processors/catalog_processor.rs:196codex-rs/app-server/src/request_processors/mcp_processor.rs:83codex-rs/app-server/src/transport_tests.rs:402codex-rs/codex-api/src/endpoint/memories.rs:87.github/workflows/rust-release-prepare.yml
codex-rs/tui/src/config_update.rs:1
codex-rs/tui/src/clipboard_copy.rs:1
.devcontainer/Dockerfile:1
containersPinned dependencies
repo-level (19 hits)sdk/typescript/package.json
CI/CD securitySupply chainNpm
sdk/python/scripts/update_sdk_artifacts.py:68
sdk/python/src/openai_codex/client.py:693
scripts/mock_responses_websocket_server.py:143
scripts/stage_npm_packages.py:386
scripts/stage_npm_packages.py:335
sdk/python/src/openai_codex/api.py:356
sdk/python/src/openai_codex/api.py:366
sdk/python/src/openai_codex/client.py:327
sdk/python/src/openai_codex/async_client.py:247
sdk/python/src/openai_codex/client.py:501
sdk/python/src/openai_codex/async_client.py:226
scripts/format.py:118
This page is publicly accessible at:
https://repobility.com/scan/b7c96c67-6e17-4d8d-a15d-4ce30aa2a226/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/b7c96c67-6e17-4d8d-a15d-4ce30aa2a226/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.