Scan timing: clone 4.46s · analysis 18.07s · 5.3 MB · GitHub API rate-limit (preflight)
https://github.com/Fission-AI/OpenSpec
· scanned 2026-06-05 11:21 UTC (5 days, 12 hours ago)
· 10 languages
334 raw signals (118 security + 216 graph) 65th percentile · Typescript · medium (20-100K LoC) System graph score 59 (higher by 16)
Last scanned 5 days, 12 hours ago · v2 · 136 actionable findings from 2 signal sources. 90 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
50.0 | 0.25 | 12.50 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
78.0 | 0.15 | 11.70 |
practices_score |
82.0 | 0.15 | 12.30 |
code_quality |
54.5 | 0.10 | 5.45 |
| Overall | 1.00 | 74.7 |
Showing 123 of 136 actionable findings. 226 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/telemetry/index.ts:17
src/telemetry/index.ts:17
src/core/templates/workflows/feedback.ts:75
package-lock.jsonpnpm-lock.yamlsrc/telemetry/index.ts:17
package-lock.jsonpnpm-lock.yamlpackage-lock.jsonpnpm-lock.yaml.github/workflows/ci.yml:31, 56, 112, 151, 195, 198, 272 (14 hits).github/workflows/release-prepare.yml:35, 51 (3 hits).github/workflows/ci.yml:28, 51, 61, 76, 107, 117, 137, 148, +4 more (24 hits).github/workflows/release-prepare.yml:26, 30, 39 (4 hits)package-lock.jsonpnpm-lock.yamlpackage-lock.jsonpnpm-lock.yamlpackage-lock.jsonpnpm-lock.yamlpackage-lock.jsonpnpm-lock.yamlpackage-lock.jsonpnpm-lock.yamlpnpm-lock.yaml
package-lock.jsonpnpm-lock.yamlpackage-lock.json
pnpm-lock.yaml
package-lock.jsonpnpm-lock.yamlpnpm-lock.yaml
package.json
package.json
package.json
package.json
package.json
package-lock.jsonpnpm-lock.yamlpackage-lock.jsonpnpm-lock.yamlpackage-lock.jsonpnpm-lock.yamlpnpm-lock.yaml
package-lock.jsonpnpm-lock.yaml.github/workflows/release-prepare.yml
CI/CD securitySupply chainGithub actions
src/core/workspace/registry.ts:24, 39, 44 (3 hits)src/core/completions/installers/powershell-installer.ts:67, 170 (2 hits)src/core/workspace/foundation.ts:81, 181 (2 hits)src/core/workspace/legacy-state.ts:83, 88 (2 hits)src/commands/workflow/status.ts:42src/commands/workspace/open-view.ts:134src/core/command-generation/adapters/lingma.ts:7src/core/command-generation/adapters/qoder.ts:7package.json
package.json
package.json
package.json
pnpm-lock.yaml
pnpm-lock.yaml
pnpm-lock.yaml
package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/d086c264-63cb-47c5-a5b4-d20dc58a8c1f/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/d086c264-63cb-47c5-a5b4-d20dc58a8c1f/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.