Scan timing: clone 7.71s · analysis 34.6s · 24.2 MB · GitHub API rate-limit (preflight)
https://github.com/home-assistant/frontend
· scanned 2026-05-21 18:12 UTC (2 weeks ago)
· 10 languages
461 findings (103 legacy + 358 scanner) 10/13 scanners ran 22nd percentile · Typescript · huge (>500K LoC) Scanner says 70 (higher by 6)
Last scanned 2 weeks ago · v2 · 282 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
39.0 | 0.20 | 7.80 |
documentation_score |
75.0 | 0.15 | 11.25 |
practices_score |
76.0 | 0.15 | 11.40 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 76.2 |
Bug-class explainers. Each card groups findings of the same shape — these are the patterns most likely to ship to prod and reappear in future scans unless you systematically fix the cause, not just the instance.
public/robots.txt
.well-known/security.txt
index.html
src/data/file_upload.ts:6
src/data/error_log.ts:19
src/data/error_log.ts:18
src/data/diagnostics.ts:33
src/data/diagnostics.ts:28
src/data/camera.ts:104
src/data/camera.ts:82
src/components/ha-addon-picker.ts:106
gallery/src/pages/lovelace/picture-elements-card.…:33
src/panels/config/voice-assistants/ha-config-voic…:15
src/panels/config/ha-panel-config.ts:128
src/panels/config/ha-panel-config.ts:110
src/panels/config/ha-panel-config.ts:101
src/panels/config/ha-panel-config.ts:93
src/panels/config/ha-panel-config.ts:85
src/panels/config/ha-panel-config.ts:77
src/panels/config/ha-panel-config.ts:69
src/panels/config/ha-panel-config.ts:61
src/data/quick_bar.ts:163
This page is publicly accessible at:
https://repobility.com/scan/c5fbe1f2-2dac-4c77-947a-f406588dcb31/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/c5fbe1f2-2dac-4c77-947a-f406588dcb31/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.