https://github.com/flutter/flutter
· scanned 2026-06-05 04:37 UTC (4 hours, 25 minutes ago)
· 10 languages
290 findings (114 legacy + 176 scanner) 11/13 scanners ran
Last scanned 4 hours, 25 minutes ago · v2 · 202 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
92.0 | 0.15 | 13.80 |
practices_score |
68.0 | 0.15 | 10.20 |
code_quality |
71.0 | 0.10 | 7.10 |
| Overall | 1.00 | 79.1 |
Showing 101 of 202 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
engine/src/flutter/impeller/renderer/backend/metal/allocator_mtl.mm:57
qualitylegacy
engine/src/flutter/impeller/renderer/shader_key.cc:16
qualitylegacy
engine/src/flutter/tools/fuchsia/toolchain/copy.py:40
qualitylegacy
engine/src/flutter/shell/platform/android/io/flutter/embedding/engine/systemchannels/SettingsChannel.java:30
secrets
dev/bots/custom_rules/render_box_intrinsics.dart:69
qualitylegacy
dev/bots/custom_rules/protect_public_state_subtypes.dart:76
qualitylegacy
engine/src/flutter/impeller/playground/backend/metal/playground_impl_mtl.mm:115
qualitylegacy
dev/benchmarks/platform_channels_benchmarks/android/app/src/main/kotlin/com/example/platform_channels_benchmarks/MainActivity.kt:34
qualitylegacy
engine/src/flutter/ci/scan_deps.py:153
qualitylegacy
engine/src/flutter/.github/workflows/third_party_scan.yml:34
dependencylegacy
.github/workflows/freeze.yml:27
dependencylegacy
engine/src/flutter/.github/workflows/engine-cp.yml:11
dependencylegacy
engine/src/flutter/ci/scan_deps.py:66
qualitylegacy
engine/src/flutter/ci/scan_deps.py:66
owaspexec_used
engine/src/tools/dart/create_updated_flutter_deps.py:53
owaspexec_used
engine/src/flutter/tools/fuchsia/with_envs.py:51
qualitylegacy
engine/src/flutter/ci/scan_deps.py:153
injectionlegacy
engine/src/flutter/shell/platform/embedder/embedder_semantics_update.h:1
qualitylegacy
engine/src/flutter/.github/workflows/third_party_scan.yml:44
supply-chaingithub-actionspinned-dependencies
.github/workflows/freeze.yml:27
supply-chaingithub-actionspinned-dependencies
engine/src/flutter/.github/workflows/engine-cp.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/merge-changelog.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/cut-release-branch.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/roll-dart-dependencies.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/sync-engine-version.yml
supply-chaingithub-actionsleast-privilege
engine/src/flutter/ci/scan_deps.py:156
owaspsubprocess_shell_true
engine/src/flutter/lib/ui/semantics/semantics_update.h:1
qualitylegacy
dev/bots/unpublish_package.dart:346
qualitylegacy
dev/bots/unpublish_package.dart:69
qualitylegacy
dev/a11y_assessments/lib/use_cases/card.dart:10
qualitylegacy
.agents/skills/analyze-github-flake/SKILL.md
qualitylegacy
engine/src/flutter/shell/platform/embedder/embedder_semantics_update.h:1
qualitylegacy
engine/src/flutter/lib/ui/semantics/semantics_update.h:1
qualitylegacy
dev/bots/prepare_package/transactional_update.dart:1
qualitylegacy
engine/src/flutter/.github/workflows/third_party_scan.yml:34
supply-chaingithub-actionspinned-dependencies
engine/src/flutter/tools/fuchsia/make_build_info.py:35
dead-code
engine/src/tools/dart/create_updated_flutter_deps.py:57
dead-code
engine/src/flutter/tools/fuchsia/build_fuchsia_artifacts.py:48
dead-code
engine/src/tools/dart/create_updated_flutter_deps.py:30
dead-code
engine/src/flutter/ci/scan_deps.py:44
dead-code
engine/src/flutter/tools/download_fuchsia_sdk.py:81
dead-code
engine/src/flutter/impeller/renderer/backend/metal/surface_mtl.mm:230
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/c3e85ec5-2e36-4677-a1e8-7af65f6cee90/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/c3e85ec5-2e36-4677-a1e8-7af65f6cee90/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.