Scan timing: clone 29.89s · analysis 7.95s · 41.6 MB · GitHub API rate-limit (preflight)
https://github.com/sartography/spiff-arena
· scanned 2026-06-05 19:16 UTC (4 days, 17 hours ago)
· 10 languages
660 raw signals (216 security + 444 graph) 11/13 scanners ran 86th percentile · Python · large (100-500K LoC) System graph score 57 (higher by 30)
Last scanned 4 days, 17 hours ago · v2 · 234 actionable findings from 2 signal sources. 179 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
76.0 | 0.15 | 11.40 |
practices_score |
94.0 | 0.15 | 14.10 |
code_quality |
71.0 | 0.10 | 7.10 |
| Overall | 1.00 | 86.6 |
Top 10 actions, ranked by impact × ease. Severity drives impact; tag-based fix-clarity drives ease.
spiffworkflow-backend/src/spiffworkflow_backend/services/process_instance_processor.py:203spiffworkflow-backend/src/spiffworkflow_backend/services/process_instance_processor.py:215spiffworkflow-backend/src/spiffworkflow_backend/api.ymlspiffworkflow-backend/src/spiffworkflow_backend/api.ymlspiffworkflow-backend/src/spiffworkflow_backend/api.ymlspiffworkflow-backend/src/spiffworkflow_backend/api.ymlspiffworkflow-backend/src/spiffworkflow_backend/api.yml.github/workflows/renovate.yml.github/workflows/container_retention_policy.ymlClick "Find this gap" on any action above to jump to it on the Findings tab. Adjust the chip bar to filter by impact (severity), layer, or source.
This page is publicly accessible at:
https://repobility.com/scan/dcdaf7ef-267f-49f9-92a1-e14f4851e3ce/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/dcdaf7ef-267f-49f9-92a1-e14f4851e3ce/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.