https://github.com/inngest/inngest
· scanned 2026-06-05 14:18 UTC (5 days, 4 hours ago)
· 10 languages
664 raw signals (128 security + 536 graph) 11/13 scanners ran 61st percentile · Go · large (100-500K LoC) System graph score 68 (higher by 16)
Last scanned 5 days, 4 hours ago · v2 · 281 actionable findings from 2 signal sources. 114 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
63.0 | 0.15 | 9.45 |
practices_score |
82.0 | 0.15 | 12.30 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 83.5 |
Showing 167 of 281 actionable findings. 395 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/e2e.yml:93, 187, 275, 361, 390 (5 hits).github/workflows/go.yaml:86pkg/api/apiv1/apiv1.go:171
pkg/coreapi/coreapi.go:117
pkg/connect/rest/v0/v0.go:94
pkg/connect/rest/v0/v0.go:95
pkg/api/apiv1/apiv1.go:168
pkg/api/apiv1/apiv1.go:169
pkg/api/apiv1/apiv1.go:170
pkg/coreapi/coreapi.go:120
pkg/coreapi/coreapi.go:119
pkg/api/api.go:78
Dockerfile:10
.devcontainer/Dockerfile:5
npm/postinstall.ts:183
vendor/github.com/pelletier/go-toml/Dockerfile:3
CI/CD securitycontainers
Dockerfile:5
CI/CD securitycontainers
.devcontainer/Dockerfile:15
CI/CD securitycontainers
.github/workflows/e2e.yml:43, 91, 185, 273, 359, 388 (6 hits).github/workflows/go.yaml:34, 47, 84 (5 hits).github/workflows/release.yml:25, 39, 50, 108 (4 hits).github/workflows/security.yaml:22, 28 (4 hits).github/workflows/dispatch_upstream.yml:13 (2 hits).github/workflows/components_test.yml:17.github/workflows/dev_server_ui.yml:19.github/workflows/npm_test.yml:37.github/workflows/e2e.yml:34, 84, 115, 178, 206, 266, 293, 352, +1 more (9 hits).github/workflows/prerelease.yml:23, 29, 89, 98 (8 hits).github/workflows/go.yaml:24, 29, 43, 65, 70 (7 hits).github/workflows/release.yml:30, 35, 126, 131 (4 hits).github/workflows/components_test.yml:16, 20 (2 hits).github/workflows/dev_server_ui.yml:18, 22 (2 hits).github/workflows/npm_test.yml:29, 32 (2 hits).github/workflows/release-pr.yml:43, 49 (2 hits).github/workflows/go.yaml:46
CI/CD securitySupply chainGitHub Actions
.devcontainer/Dockerfile:15
containersRemote installer
pkg/expressions/cel.go:87
Eval used
pkg/expressions/expressions.go:281
Eval used
pkg/coreapi/coreapi.go:117
pkg/authn/authn.go:30
pkg/api/apiv1/apiv1.go:167
pkg/api/apiv1/apiv1.go:168
pkg/api/apiv1/apiv1.go:169
pkg/api/apiv1/apiv1.go:170
pkg/coreapi/coreapi.go:120
pkg/coreapi/coreapi.go:119
pkg/api/apiv1/apiv1.go:165
pkg/coreapi/coreapi.go:121
.dockerignore
CI/CD securitycontainers
Dockerfile:11
CI/CD securitycontainers
.devcontainer/Dockerfile:8
CI/CD securitycontainers
docs/api-docs/src/routeTree.gen.ts:45, 46, 56, 64, 73, 83, 85, 93, +4 more (12 hits)docs/api-docs/src/routes/api/search.ts:10pkg/connect/gateway_msg_status_update.go:1
pkg/connect/gateway_msg_status_update.go:1
.github/workflows/prerelease.yml.github/workflows/release-pr.yml.github/workflows/release-tag.yml.github/workflows/release.yml.github/workflows/vendor-inngestgo.ymlui/apps/dashboard/src/components/ActiveBanners/ActiveBannerItem.tsx:54
Dangerous innerhtml
cmd/devserver/devserver.go:136cmd/doctor/healthcheck/cmd.go:106cmd/start/start.go:55pkg/coreapi/graph/resolvers/runs_v2.go:48, 149 (2 hits)cmd/debug/batch/info.go:15cmd/debug/batch/run.go:14cmd/debug/debounce/info.go:16cmd/debug/debounce/run.go:15cmd/debug/pause/peek.go:17cmd/debug/singleton/delete.go:2cmd/debug/singleton/info.go:15Dockerfile:10
containersPinned dependencies
Dockerfile:1
containersPinned dependencies
.devcontainer/Dockerfile:5
containersPinned dependencies
docs/api-docs/package.jsonnpm/package.jsonui/apps/dashboard/package.jsonui/apps/dev-server-ui/package.jsonui/package.json
This page is publicly accessible at:
https://repobility.com/scan/dff1705c-35ea-414c-a352-2231a387a0c4/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/dff1705c-35ea-414c-a352-2231a387a0c4/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.