Scan timing: clone 18.58s · analysis 20.65s · 62.3 MB · GitHub API rate-limit (preflight)
https://github.com/oracle/graalvm-reachability-metadata
· scanned 2026-06-05 20:44 UTC (4 days, 12 hours ago)
· 10 languages
396 raw signals (122 security + 274 graph) 11/13 scanners ran 57th percentile · Java · large (100-500K LoC) System graph score 84 (lower by 7)
Last scanned 4 days, 12 hours ago · v2 · 166 actionable findings from 2 signal sources. 93 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
90.0 | 0.20 | 18.00 |
documentation_score |
75.0 | 0.15 | 11.25 |
practices_score |
74.0 | 0.15 | 11.10 |
code_quality |
56.0 | 0.10 | 5.60 |
| Overall | 1.00 | 76.9 |
Showing 121 of 166 actionable findings. 259 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
forge/utility_scripts/shutdown_signal.py:33
forge/utility_scripts/gradle_environment.py:63
forge/forge_metadata.py:921, 922, 924, 929, 941, 950, 955, 962, +16 more (24 hits)forge/utility_scripts/fixture_github.py:156gradle/wrapper/gradle-wrapper.jar:1
forge/requirements.txt:1, 2, 3 (3 hits)forge/forge_metadata.py:1606, 1620, 2440, 2577, 2785, 3419, 3555, 3919, +17 more (25 hits)docs/support/index.html:472
.github/workflows/create-scheduled-release.yml.github/workflows/publish-scheduled-coverage.yml.github/workflows/sync-docker-images.yml.github/workflows/verify-new-library-version-compatibility.ymlforge/ai_workflows/core/workflow_strategy.py:158
Subprocess shell true
forge/ai_workflows/drivers/add_new_library_support.py:293
Subprocess shell true
forge/ai_workflows/drivers/java_fail_workflow.py:237
Subprocess shell true
metadata/com.diffplug.spotless/spotless-lib-extra/2.45.0/reachability-metadata.json:181
Weak hash
metadata/com.diffplug.spotless/spotless-lib-extra/3.0.0/reachability-metadata.json:206
Weak hash
metadata/com.github.mwiede/jsch/2.27.7/reachability-metadata.json:319
Weak hash
metadata/io.netty/netty-common/4.1.115.Final/reachability-metadata.json:5275
Weak hash
metadata/io.netty/netty-common/4.1.80.Final/reachability-metadata.json:5220
Weak hash
metadata/org.apache.avro/avro-ipc/1.10.2/reachability-metadata.json:145
Weak hash
metadata/org.apache.directory.server/apacheds-kerberos-codec/2.0.0-M15/reachability-metadata.json:37
Weak hash
metadata/org.apache.maven.resolver/maven-resolver-util/1.9.25/reachability-metadata.json:7
Weak hash
metadata/org.apache.maven.resolver/maven-resolver-util/2.0.0/reachability-metadata.json:7
Weak hash
metadata/org.apache.maven.wagon/wagon-ssh/1.0/reachability-metadata.json:307
Weak hash
metadata/org.bouncycastle/bcpkix-jdk15on/1.70/reachability-metadata.json:307
Weak hash
metadata/org.bouncycastle/bcpkix-jdk15to18/1.77/reachability-metadata.json:391
Weak hash
metadata/org.bouncycastle/bcpkix-jdk18on/1.77/reachability-metadata.json:391
Weak hash
metadata/org.eclipse.jgit/org.eclipse.jgit/6.5.0.202303070854-r/reachability-metadata.json:132
Weak hash
metadata/org.eclipse.jgit/org.eclipse.jgit/7.4.0.202509020913-r/reachability-metadata.json:180
Weak hash
metadata/org.hibernate.orm/hibernate-core/6.1.1.Final/reachability-metadata.json:10293
Weak hash
metadata/org.hibernate/hibernate-core/6.0.0.Final/reachability-metadata.json:3128
Weak hash
metadata/org.liquibase/liquibase-core/4.17.0/reachability-metadata.json:1125
Weak hash
metadata/org.liquibase/liquibase-core/4.20.0/reachability-metadata.json:1137
Weak hash
metadata/org.liquibase/liquibase-core/4.25.0/reachability-metadata.json:8862
Weak hash
metadata/org.liquibase/liquibase-core/4.27.0/reachability-metadata.json:6884
Weak hash
metadata/org.liquibase/liquibase-core/5.0.1/reachability-metadata.json:7850
Weak hash
metadata/org.opengauss/opengauss-jdbc/3.1.0-og/reachability-metadata.json:124
Weak hash
metadata/org.sonatype.aether/aether-util/1.12/reachability-metadata.json:7
Weak hash
metadata/org.sonatype.aether/aether-util/1.8/reachability-metadata.json:7
Weak hash
metadata/org.web3j/core/4.10.0/reachability-metadata.json:307
Weak hash
metadata/org.web3j/core/4.11.0/reachability-metadata.json:307
Weak hash
metadata/software.amazon.awssdk/s3/2.25.3/reachability-metadata.json:43
Weak hash
forge/fixture_github_issues/library-new-request-dynamic-access.yaml
Ports
forge/fixture_github_issues/fails-native-image-run.yaml
Ports
forge/git_scripts/make_pr_java_run_fix.py:1
forge/ai_workflows/drivers/java_fail_workflow.py:79, 80 (2 hits)forge/git_scripts/make_pr_new_library_support.py:314, 440 (2 hits)forge/git_scripts/make_pr_ni_run_fix.py:223, 225 (2 hits)forge/ai_workflows/agents/pi_agent.py:44forge/ai_workflows/agents/pi_rpc_client.py:29forge/ai_workflows/core/java_fix_iterative_strategy.py:88forge/ai_workflows/core/optimistic_dynamic_access_strategy.py:167forge/ai_workflows/drivers/fix_ni_run.py:25forge/git_scripts/make_pr_java_run_fix.py:1forge/git_scripts/make_pr_javac_fix.py:1forge/git_scripts/make_pr_ni_run_fix.py:1repo-level (12 hits)repo-level (8 hits)forge/utility_scripts/fixture_github.py:276
forge/utility_scripts/metrics_writer.py:866
forge/ai_workflows/agents/pi_agent.py:140
forge/ai_workflows/agents/codex_agent.py:234
forge/ai_workflows/agents/codex_app_server.py:70
forge/ai_workflows/agents/agent.py:39
forge/ai_workflows/core/workflow_strategy.py:84
forge/utility_scripts/repo_path_resolver.py:66
forge/forge_metadata.py:5890
forge/forge_metadata.py:6088
forge/forge_metadata.py:2461
forge/utility_scripts/strategy_loader.py:65
forge/ai_workflows/drivers/improve_library_coverage.py:303
forge/utility_scripts/native_image_artifact.py:219
forge/utility_scripts/fixture_github.py:284
forge/git_scripts/common_git.py:589
forge/ai_workflows/agents/codex_app_server.py:58
forge/utility_scripts/fixture_github.py:272
forge/utility_scripts/fixture_github.py:265
forge/ai_workflows/agents/codex_app_server.py:52
forge/utility_scripts/schema_validator.py:72
forge/forge_metadata.py:4250
forge/forge_metadata.py:4258
forge/utility_scripts/schema_validator.py:77
This page is publicly accessible at:
https://repobility.com/scan/bcbb13c9-a034-4744-989c-05436b288eb4/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/bcbb13c9-a034-4744-989c-05436b288eb4/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.