https://github.com/xsmurphy/punto-legacy
· scanned 2026-06-16 01:03 UTC (2 months, 1 week ago)
175 raw signals (0 security + 175 graph)
Last scanned 2 months, 1 week ago · v1 · 163 actionable findings from 1 signal source. 12 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
Showing 106 of 163 actionable findings. 175 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
app/scripts/sign-message.js:41
Private key in repo
app/scripts/sign-message.js:41
.claude/agents/context-updater.md
VerificationClaude instruction
.claude/launch.json
VerificationClaude instruction
.claude/settings.json
VerificationClaude instruction
Dockerfile:52
containersChecksum
.github/workflows/ci.yml:28, 136 (2 hits)panel-next/components/ui/chart.tsx:95
Dangerous innerhtml
app/scripts/confettiKit.min.js:1
Direct innerhtml assignment
app/scripts/enjoyhint.min.js:2
Direct innerhtml assignment
panel/admin/scripts/companies.js:81
Direct innerhtml assignment
panel/admin/scripts/users.js:55
Direct innerhtml assignment
panel/scripts/a_settings.js:143
Direct innerhtml assignment
panel/scripts/initials.js:7
Direct innerhtml assignment
screens/scripts/kds.js:408
Direct innerhtml assignment
Dockerfile:25app/Dockerfile:16panel/Dockerfile:20ws-server/Dockerfile:1app-next/Dockerfile:16, 29, 52 (3 hits)panel-next/Dockerfile:14, 27, 51 (3 hits)Dockerfile:47api/Dockerfile:17app/Dockerfile:37panel/Dockerfile:43.github/workflows/ci.yml:85
CI/CD securitySupply chainGithub actions
This page is publicly accessible at:
https://repobility.com/scan/e4046f88-1841-45d0-a53d-5d118ad8647e/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/e4046f88-1841-45d0-a53d-5d118ad8647e/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.