Scan timing: clone 2.7s · analysis 1.74s · 0.9 MB · GitHub API rate-limit (preflight)
https://github.com/sherlock-project/sherlock
· scanned 2026-06-05 07:19 UTC (5 days, 22 hours ago)
· 10 languages
127 raw signals (65 security + 62 graph) 78th percentile · Python · small (2-20K LoC)
Last scanned 5 days, 22 hours ago · v2 · 42 actionable findings from 2 signal sources. 54 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
75.0 | 0.15 | 11.25 |
security_score |
84.8 | 0.25 | 21.20 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
38.0 | 0.15 | 5.70 |
practices_score |
92.0 | 0.15 | 13.80 |
code_quality |
73.8 | 0.10 | 7.38 |
| Overall | 1.00 | 79.3 |
Showing 27 of 42 actionable findings. 96 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.actor/README.md:31
sherlock_project/notify.py:189, 192, 193, 197, 203, 205, 207, 215, +7 more (15 hits)sherlock_project/result.py:28Dockerfile:6, 11 (2 hits).actor/Dockerfile:1.github/workflows/regression.yml:33, 35, 64, 66, 80 (8 hits).github/workflows/validate_modified_targets.yml:18, 26, 112 (6 hits).github/workflows/exclusions.yml:14, 17 (4 hits).github/workflows/update-site-list.yml:20, 27 (4 hits).github/workflows/exclusions.yml:22 (2 hits).github/workflows/validate_modified_targets.yml:31 (2 hits).github/workflows/regression.yml:82.github/workflows/update-site-list.yml:36
CI/CD securitySupply chainGitHub Actions
.github/workflows/update-site-list.yml:36
CI/CD securitySupply chainGithub actions
sherlock_project/resources/data.json:1485
sherlock_project/sherlock.py:373, 377, 714, 768 (4 hits)sherlock_project/sites.py:179Dockerfile:12
CI/CD securitycontainers
.actor/Dockerfile:1
CI/CD securitycontainers
sherlock_project/sites.py:79, 208 (2 hits).dockerignore
CI/CD securitycontainers
.actor/Dockerfile:4, 8, 14 (3 hits).actor/Dockerfile:4, 8, 14 (3 hits)Dockerfile:6, 11 (2 hits)repo-level (3 hits)sherlock_project/sherlock.py:533
sherlock_project/sherlock.py:75
sherlock_project/sites.py:226
sherlock_project/sherlock.py:508
This page is publicly accessible at:
https://repobility.com/scan/b8f0703e-54ea-453f-a23e-c3a6fc92b520/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/b8f0703e-54ea-453f-a23e-c3a6fc92b520/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.