Scan timing: clone 7.71s · analysis 34.6s · 24.2 MB · GitHub API rate-limit (preflight)
https://github.com/home-assistant/frontend
· scanned 2026-05-21 18:12 UTC (2 weeks ago)
· 10 languages
461 findings (103 legacy + 358 scanner) 10/13 scanners ran 17th percentile · Typescript · huge (>500K LoC) Scanner says 70 (higher by 6)
Last scanned 2 weeks ago · v2 · 282 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
39.0 | 0.20 | 7.80 |
documentation_score |
75.0 | 0.15 | 11.25 |
practices_score |
76.0 | 0.15 | 11.40 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 76.2 |
Showing 235 of 282 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
build-scripts/gulp/gallery.js:50
qualitylegacy
build-scripts/gulp/entry-html.js:107
qualitylegacy
.github/workflows/design_preview.yaml:51
dependencylegacy
.github/workflows/design_preview.yaml:52
dependencylegacy
build-scripts/gulp/gallery.js:50
qualitylegacy
build-scripts/gulp/gallery.js:50
deserializationlegacy
gallery/src/pages/components/ha-form.ts:268
secrets
gallery/src/pages/components/ha-form.ts:442
secrets
build-scripts/gulp/translations.js:195
qualitylegacy
.devcontainer/Dockerfile:1
dependencylegacy
src/dialogs/more-info/components/lights/light-color-temp-picker.ts:44
xsslegacy
src/data/selector/format_selector_value.ts:25
xsslegacy
build-scripts/gulp/entry-html.js:111
xsslegacy
src/common/string/slugify.ts:6
qualitylegacy
src/common/string/is_date.ts:4
qualitylegacy
src/components/ha-markdown-element.ts:138
qualitylegacy
src/components/ha-ansi-to-html.ts:185
qualitylegacy
build-scripts/gulp/fetch-nightly-translations.js:78
authlegacy
script/version_bump.js:78
owaspexec_used
src/panels/config/ha-panel-config.ts:110
authlegacy
gallery/src/pages/components/ha-list.ts:320
authlegacy
src/panels/config/ha-panel-config.ts:85
authlegacy
src/data/quick_bar.ts:163
authlegacy
src/panels/config/ha-panel-config.ts:77
authlegacy
src/panels/config/ha-panel-config.ts:69
authlegacy
src/panels/config/ha-panel-config.ts:61
authlegacy
src/panels/config/ha-panel-config.ts:93
authlegacy
src/panels/config/ha-panel-config.ts:101
authlegacy
src/panels/config/ha-panel-config.ts:128
authlegacy
src/panels/climate/ha-panel-climate.ts:152
authlegacy
src/panels/config/voice-assistants/ha-config-voice-assistants.ts:15
authlegacy
src/panels/energy/ha-panel-energy.ts:97
authlegacy
src/panels/home/ha-panel-home.ts:351
authlegacy
src/fake_data/demo_panels.ts:9
authlegacy
src/panels/maintenance/ha-panel-maintenance.ts:154
authlegacy
src/panels/profile/ha-panel-profile.ts:13
authlegacy
src/panels/config/entities/entity-registry-settings.ts:74
error_handlinglegacy
build-scripts/gulp/gallery.js:50
deserializationlegacy
gallery/src/ha-gallery.ts:117
securitylegacy
demo/src/custom-cards/ha-demo-card.ts:57
securitylegacy
cast/src/launcher/layout/hc-layout.ts:32
securitylegacy
src/panels/config/automation/ha-automation-sortable-list-mixin.ts:51
qualitylegacy
src/components/entity/ha-entity-states-picker.ts:42
qualitylegacy
demo/src/custom-cards/card-tools.js:149
qualitylegacy
gallery/src/pages/more-info/update.ts:21
qualitylegacy
gallery/src/pages/components/ha-faded.ts:9
qualitylegacy
src/common/auth/token_storage.ts:67
authlegacy
src/common/auth/token_storage.ts:44
authlegacy
.dockerignore
dockerlegacy
.devcontainer/Dockerfile:1
dockerlegacy
src/data/file_upload.ts:6
qualitylegacy
src/data/error_log.ts:19
qualitylegacy
src/data/error_log.ts:18
qualitylegacy
src/data/diagnostics.ts:33
qualitylegacy
src/data/diagnostics.ts:28
qualitylegacy
src/data/camera.ts:104
qualitylegacy
src/data/camera.ts:82
qualitylegacy
src/components/ha-addon-picker.ts:106
qualitylegacy
gallery/src/pages/lovelace/picture-elements-card.ts:33
qualitylegacy
gallery/src/pages/lovelace/glance-card.ts:39
qualitylegacy
gallery/src/data/demo_states.js:552
qualitylegacy
gallery/src/data/demo_states.js:396
qualitylegacy
gallery/src/data/demo_states.js:372
qualitylegacy
gallery/src/data/demo_states.js:348
qualitylegacy
gallery/src/data/demo_states.js:324
qualitylegacy
src/auth/ha-authorize.ts:326
qualitylegacy
landing-page/src/ha-landing-page.ts:200
qualitylegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
public/robots.txt
qualitylegacy
.github/workflows/release.yaml
supply-chaingithub-actionsleast-privilege
.github/workflows/nightly.yaml
supply-chaingithub-actionsleast-privilege
.github/workflows/release-drafter.yaml
supply-chaingithub-actionsleast-privilege
src/resources/jinja_ha_completions.ts:1213
owaspweak_hash
llms.txt
qualitylegacy
humans.txt
qualitylegacy
sitemap.xml
qualitylegacy
public/robots.txt
qualitylegacy
.devcontainer/Dockerfile:1
supply-chaindockerpinned-dependencies
package.json
supply-chainnpminstall-scripts
public/__init__.py:5
dead-code
gallery/src/pages/lovelace/markdown-card.ts:163
qualitylegacy
gallery/src/pages/lovelace/entities-card.ts:408
qualitylegacy
cast/src/launcher/layout/hc-connect.ts:43
qualitylegacy
gallery/src/components/demo-black-white-row.ts:56
qualitylegacy
demo/src/ha-demo.ts:46
qualitylegacy
cast/src/launcher/layout/hc-connect.ts:83
qualitylegacy
build-scripts/gulp/fetch-nightly-translations.js:69
qualitylegacy
demo/src/ha-demo.ts:36
qualitylegacy
demo/src/custom-cards/ha-demo-card.ts:122
qualitylegacy
cast/src/receiver/layout/hc-lovelace.ts:14
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/c5fbe1f2-2dac-4c77-947a-f406588dcb31/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/c5fbe1f2-2dac-4c77-947a-f406588dcb31/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.