https://github.com/dotnet/runtime
· scanned 2026-06-05 19:50 UTC (1 week, 2 days ago)
· 10 languages
859 raw signals (293 security + 566 graph) 11/13 scanners ran 50th percentile · Csharp · huge (>500K LoC) System graph score 76 (higher by 3)
Last scanned 1 week, 2 days ago · v2 · 326 actionable findings from 2 signal sources. 247 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
96.0 | 0.15 | 14.40 |
practices_score |
77.0 | 0.15 | 11.55 |
code_quality |
25.0 | 0.10 | 2.50 |
| Overall | 1.00 | 79.2 |
Showing 179 of 326 actionable findings. 573 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/inter-branch-merge-flow.yml:13
CI/CD securitySupply chainGithub actions
.github/workflows/backport.yml:18
CI/CD securitySupply chainGithub actions
src/mono/browser/runtime/rollup.config.js:284
Eval used
.github/workflows/aspnetcore-sync.yml.github/workflows/backport.yml.github/workflows/bump-chrome-version.yml.github/workflows/ci-failure-scan-feedback.lock.yml.github/workflows/ci-failure-scan.lock.yml.github/workflows/inter-branch-merge-flow.ymleng/common/cross/install-debs.py:236
Subprocess shell true
eng/pipelines/coreclr/crossgen2-gcstress.yml
Ports
eng/pipelines/runtime-llvm.yml
Ports
eng/pipelines/coreclr/runtime-nativeaot-outerloop.yml
Ports
eng/pipelines/common/templates/pipeline-with-resources.yml
Ports
.github/workflows/labeler-cache-retention.yml
Ports
src/native/external/libunwind/.github/workflows/codeql-analysis.yml
Ports
eng/pipelines/common/templates/pipeline-with-resources.yml
Ports
eng/pipelines/coreclr/ci.yml
Ports
eng/pipelines/runtime-llvm.yml
Ports
eng/pipelines/coreclr/runtime-nativeaot-outerloop.yml
Ports
eng/pipelines/common/templates/pipeline-with-resources.yml
Ports
src/native/external/libunwind/.github/workflows/codeql-analysis.yml
Ports
eng/pipelines/libraries/helix-queues-setup.yml
Ports
eng/pipelines/coreclr/jitstress-isas-x86.yml
Ports
eng/pipelines/coreclr/templates/helix-queues-setup.yml
Ports
eng/pipelines/libraries/helix-queues-setup.yml
Ports
.github/workflows/labeler-cache-retention.yml
Ports
eng/pipelines/common/templates/pipeline-with-resources.yml
Ports
eng/pipelines/libraries/helix-queues-setup.yml
Ports
eng/pipelines/common/templates/pipeline-with-resources.yml
Ports
eng/pipelines/common/templates/pipeline-with-resources.yml
Ports
eng/pipelines/common/templates/pipeline-with-resources.yml
Ports
eng/pipelines/common/templates/pipeline-with-resources.yml
Ports
eng/pipelines/libraries/helix-queues-setup.yml
Ports
.devcontainer/Dockerfile:5.devcontainer/android/Dockerfile:2.devcontainer/wasm-multiThreaded/Dockerfile:5.devcontainer/wasm/Dockerfile:5src/libraries/Common/tests/System/Net/EnterpriseTests/setup/apacheweb/Dockerfile:1src/libraries/Common/tests/System/Net/EnterpriseTests/setup/kdc/Dockerfile:1src/libraries/Common/tests/System/Net/EnterpriseTests/setup/linuxclient/Dockerfile:1repo-level (13 hits)repo-level (4 hits)src/coreclr/scripts/coreclr_arguments.py:239
src/coreclr/scripts/coreclr_arguments.py:251
src/coreclr/scripts/coreclr_arguments.py:228
src/coreclr/scripts/superpmi.py:511
src/coreclr/scripts/coreclr_arguments.py:225
src/coreclr/scripts/coreclr_arguments.py:76
src/coreclr/scripts/superpmi.py:505
src/coreclr/scripts/coreclr_arguments.py:222
src/coreclr/scripts/superpmi.py:2344
src/coreclr/scripts/superpmi.py:2748
src/coreclr/scripts/jitutil.py:659
src/coreclr/scripts/superpmi.py:901
src/coreclr/scripts/superpmi.py:1223
src/coreclr/scripts/jitutil.py:360
src/coreclr/scripts/genEventing.py:302
src/coreclr/scripts/superpmi.py:2770
src/coreclr/scripts/superpmi.py:1231
src/coreclr/scripts/superpmi_replay_setup.py:66
src/coreclr/scripts/superpmi_diffs_setup.py:127
src/coreclr/scripts/superpmi_asmdiffs_checked_release_setup.py:70
src/coreclr/scripts/superpmi_diffs_setup.py:147
src/coreclr/scripts/superpmi_asmdiffs_checked_release_setup.py:84
src/coreclr/scripts/superpmi.py:1049
src/coreclr/scripts/superpmi.py:1187
src/coreclr/scripts/superpmi.py:968
src/coreclr/scripts/superpmi.py:5034
src/coreclr/scripts/superpmi.py:5023
src/coreclr/scripts/superpmi.py:5029
src/coreclr/scripts/superpmi.py:4966
src/coreclr/scripts/jitutil.py:163
This page is publicly accessible at:
https://repobility.com/scan/c11c5d9d-29cd-45bc-ad93-25084caec83e/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/c11c5d9d-29cd-45bc-ad93-25084caec83e/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.