Scan timing: clone 2.9s · analysis 9.38s · 10.1 MB · GitHub API rate-limit (preflight)
https://github.com/syncthing/syncthing
· scanned 2026-06-05 07:18 UTC (5 days, 22 hours ago)
· 10 languages
317 raw signals (191 security + 126 graph) 30th percentile · Go · large (100-500K LoC) System graph score 74 (lower by 5)
Last scanned 5 days, 22 hours ago · v2 · 133 actionable findings from 2 signal sources. 121 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
21.6 | 0.25 | 5.40 |
testing_score |
90.0 | 0.20 | 18.00 |
documentation_score |
76.0 | 0.15 | 11.40 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
61.2 | 0.10 | 6.12 |
| Overall | 1.00 | 68.7 |
Showing 110 of 133 actionable findings. 254 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
lib/rc/rc.go:37
lib/api/testdata/config/https-key.pem:1test/h1/https-key.pem:1test/h1/key.pem:1test/h2/https-key.pem:1test/h2/key.pem:1test/h3/https-key.pem:1test/h3/key.pem:1test/h4/https-key.pem:1.github/workflows/build-syncthing.yaml:146, 147, 148, 258, 259, 260, 261, 262, +17 more (25 hits)lib/api/api_auth.go:186
lib/rc/rc.go:37
cmd/syncthing/cli/client.go:60
cmd/strelaysrv/main.go:178
cmd/dev/stvanity/main.go:21
script/next-version.go:123
Dockerfile:16Dockerfile.stdiscosrv:8Dockerfile.strelaysrv:8.github/workflows/build-syncthing.yaml:59, 63, 123, 125, 176, 191, 192, 199, +24 more (37 hits).github/workflows/build-infra-dockers.yaml:33, 36 (2 hits).github/workflows/release-syncthing.yaml:18, 23 (2 hits).github/workflows/trigger-nightly.yaml:18go.mod
go.mod
go.mod:108, 111, 114 (3 hits)go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
gui/default/syncthing/folder/editFolderModalView.html:100, 101 (2 hits)gui/default/syncthing/device/editDeviceModalView.html:102.dockerignore
CI/CD securitycontainers
Dockerfile:29Dockerfile.builder:2Dockerfile.stcrashreceiver:1Dockerfile.stdiscosrv:16Dockerfile.strelaypoolsrv:1Dockerfile.strelaysrv:16Dockerfile.stupgrades:1Dockerfile.ursrv:1go.mod
go.mod
gui/default/syncthing/core/syncthingController.js:34
internal/db/sqlite/folderdb_update.go:1
Dockerfile:28
containersPinned dependencies
.github/workflows/build-infra-dockers.yaml.github/workflows/build-syncthing.yaml.github/workflows/release-syncthing.yaml.github/workflows/trigger-nightly.yaml.github/workflows/update-docs-translations.yamlcmd/infra/stcrashreceiver/diskstore.go:82cmd/infra/stcrashreceiver/util.go:51cmd/infra/stupgrades/main.go:155test/util.go:34, 230 (2 hits)cmd/dev/stwatchfile/main.go:63cmd/stdiscosrv/apisrv.go:380cmd/syncthing/cli/operations.go:55lib/fs/copyrangemethod.go:2lib/relay/client/methods.go:129script/weblatedl.go:1internal/db/sqlite/folderdb_update.go:1
internal/db/sqlite/db_update.go:1
Dockerfile:9
containersPinned dependencies
This page is publicly accessible at:
https://repobility.com/scan/e2d7c0f7-b692-4ec4-b108-3322fb43d091/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/e2d7c0f7-b692-4ec4-b108-3322fb43d091/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.