Scan timing: clone 15.79s · analysis 8.77s · 24.0 MB · GitHub API rate-limit (preflight)
https://github.com/kptdev/kpt
· scanned 2026-06-05 13:20 UTC (5 days, 6 hours ago)
· 10 languages
148 raw signals (78 security + 70 graph) 69th percentile · Go · medium (20-100K LoC) System graph score 88 (lower by 15)
Last scanned 5 days, 6 hours ago · v2 · 51 actionable findings from 2 signal sources. 62 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
50.8 | 0.25 | 12.70 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
81.0 | 0.15 | 12.15 |
practices_score |
88.0 | 0.15 | 13.20 |
code_quality |
65.5 | 0.10 | 6.55 |
| Overall | 1.00 | 73.3 |
Showing 34 of 51 actionable findings. 113 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
pkg/fn/runtime/wasm.go:159
release/images/Dockerfile:14
.github/workflows/release.yml:48, 59, 83 (5 hits).github/workflows/e2eEnvironment.yml:50 (2 hits).github/workflows/live-e2e.yml:50 (2 hits).github/workflows/go.yml:53, 57, 75, 79 (8 hits).github/workflows/live-e2e.yml:38, 42, 46 (5 hits).github/workflows/e2eEnvironment.yml:39, 43 (4 hits).github/workflows/release.yml:31, 36 (4 hits).github/workflows/verifyContent.yml:34, 38 (4 hits).github/workflows/verifyDocumentation.yml:32, 35 (4 hits)go.modhealthcheck/go.modgo.modhealthcheck/go.modgo.modhealthcheck/go.modgo.modhealthcheck/go.modgo.modhealthcheck/go.modgo.modhealthcheck/go.moddocumentation/go.modgo.modhealthcheck/go.moddocumentation/go.modgo.modhealthcheck/go.moddocumentation/go.modgo.modhealthcheck/go.modcommands/alpha/wasm/pull/command.go:89
.dockerignore
CI/CD securitycontainers
release/images/Dockerfile:15
CI/CD securitycontainers
firebase/functions/package.json
firebase/functions/package.json
firebase/functions/package.json
.github/workflows/release.yml
CI/CD securitySupply chainGithub actions
commands/fn/render/cmdrender.go:56commands/pkg/get/cmdget.go:59commands/pkg/update/cmdupdate.go:57commands/live/destroy/cmddestroy.go:85, 89 (2 hits)commands/alpha/wasm/push/command.go:24commands/live/apply/cmdapply.go:132pkg/lib/runneroptions/imagepullpolicy.go:2pkg/lib/util/addmergecomment/addmergecomment.go:53thirdparty/cmdconfig/commands/runner/runner.go:56documentation/package.json
documentation/package.json
release/images/Dockerfile:14
containersPinned dependencies
documentation/package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/b7f85d24-e1ab-4fe3-ae8e-1bebaec5b884/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/b7f85d24-e1ab-4fe3-ae8e-1bebaec5b884/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.