Scan timing: clone 3.07s · analysis 24.25s · 6.1 MB · GitHub API rate-limit (preflight)
https://github.com/airlift/airlift
· scanned 2026-06-06 01:11 UTC (3 days, 23 hours ago)
· 10 languages
84 raw signals (46 security + 38 graph) 36th percentile · Java · large (100-500K LoC) System graph score 72 (lower by 3)
Last scanned 3 days, 23 hours ago · v2 · 27 actionable findings from 2 signal sources. 35 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
55.0 | 0.25 | 13.75 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
60.0 | 0.15 | 9.00 |
practices_score |
67.0 | 0.15 | 10.05 |
code_quality |
70.3 | 0.10 | 7.03 |
| Overall | 1.00 | 68.6 |
Showing 10 of 27 actionable findings. 62 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
http-server/src/test/resources/clientcert-pem/server.pem:31security/src/test/resources/dsa.client.pkcs1.pem:55security/src/test/resources/ec.client.pkcs1.key:1security/src/test/resources/ec.client.pkcs1.pem:23security/src/test/resources/rsa.client.pkcs1.pem:61http-client/src/main/java/io/airlift/http/client/HttpClientConfig.java:66, 68 (2 hits).github/workflows/release.yml:41, 95 (4 hits).github/workflows/ci.yml:18, 19, 32, 33 (4 hits).github/workflows/release.yml:22, 27 (4 hits).github/workflows/snapshot-release.yml:17, 23 (4 hits).github/workflows/release.yml
CI/CD securitySupply chainGithub actions
http-client/src/main/java/io/airlift/http/client/HttpClientConfig.java:102
Weak hash
api/src/main/java/io/airlift/api/model/ModelServiceMetadata.java:20api/src/main/java/io/airlift/api/validation/DeprecationValidator.java:32configuration/src/main/java/io/airlift/configuration/ConfigurationFactory.java:641configuration/src/main/java/io/airlift/configuration/secrets/ThreadContextClassLoader.java:4discovery/src/main/java/io/airlift/discovery/client/HttpDiscoveryLookupClient.java:146discovery/src/main/java/io/airlift/discovery/client/ServiceDescriptor.java:68discovery/src/main/java/io/airlift/discovery/client/testing/SimpleServiceSelector.java:32discovery/src/main/java/io/airlift/discovery/client/testing/StaticServiceSelector.java:40
This page is publicly accessible at:
https://repobility.com/scan/de2414e5-24ff-4da0-bad1-f1bce218faa1/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/de2414e5-24ff-4da0-bad1-f1bce218faa1/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.