CRIT
MINED013
[MINED013] Password In Url: https://user:password@host — leaks creds via logs, referrer, …
components/konflux-operator/ci/openshif…:119
CRIT
MINED107
Missing import: `platform` used but not imported
hack/kueue-vm-quotas/update-kueue-vm-qu…:99
CRIT
kubernetes-secret-yaml
Possible Kubernetes Secret detected, posing a risk of leaking credentials/tokens from you…
hack/new-cluster/templates/kubearchive/…:991
CRIT
kubernetes-secret-yaml
Possible Kubernetes Secret detected, posing a risk of leaking credentials/tokens from you…
hack/new-cluster/templates/kubearchive/…:970
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
hack/new-cluster/templates/kubearchive/…:973
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
components/pipeline-service/production/…:1730
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
components/pipeline-service/production/…:1540
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
components/pipeline-service/production/…:1294
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
components/pipeline-service/production/…:1104
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
components/pipeline-service/development…:1315
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
components/pipeline-service/development…:1119
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
components/pipeline-service/production/…:1715
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
components/pipeline-service/production/…:1525
CRIT
kubernetes-secret-yaml
Possible Kubernetes Secret detected, posing a risk of leaking credentials/tokens from you…
components/kubearchive/production/kflux…:980
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
components/kubearchive/production/kflux…:983
CRIT
kubernetes-secret-yaml
Possible Kubernetes Secret detected, posing a risk of leaking credentials/tokens from you…
components/pipeline-service/development…:136
HIGH
MINED016
[MINED016] Go Error Ignored: _, err := fn() with err not checked. Go anti-pattern.
infra-tools/internal/github/labels.go:128
HIGH
MINED016
[MINED016] Go Error Ignored: _, err := fn() with err not checked. Go anti-pattern.
infra-tools/internal/github/comments.go:65
HIGH
SEC093
[SEC093] Go: exec.Command with non-literal: exec.Command(<var>) — variable command name a…
infra-tools/internal/git/git.go:16
HIGH
SEC093
[SEC093] Go: exec.Command with non-literal: exec.Command(<var>) — variable command name a…
infra-tools/cmd/render-diff/files.go:102
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
infra-tools/internal/deptree/resolve.go:98
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
infra-tools/cmd/render-diff/ci.go:124
HIGH
SEC113
[SEC113] SSH host-key verification disabled (MITM): Accepting any SSH host key on first c…
hack/quickcluster/setup-nfs-quickcluste…:22
HIGH
SEC078
[SEC078] Python: requests without timeout: requests.get/post without a timeout will hang …
hack/new-cluster/tasks/github/github-ap…:94
HIGH
SEC021
[SEC021] Shell Trace Around Secret Handling: Shell xtrace is enabled near secret handling…
components/multi-platform-controller/ba…:3
HIGH
MINED108
`self.end_headers` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:89
HIGH
MINED108
`self.send_header` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:88
HIGH
MINED108
`self.send_response` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:87
HIGH
MINED108
`self.manifest` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:79
HIGH
MINED108
`self.wfile` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:84
HIGH
MINED108
`self.organization` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:70
HIGH
MINED108
`self.end_headers` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:69
HIGH
MINED108
`self.send_header` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:68
HIGH
MINED108
`self.send_response` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:67
HIGH
MINED108
`self.wfile` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:59
HIGH
MINED108
`self.handle_redirect_from_github` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:64
HIGH
MINED108
`self.end_headers` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:57
HIGH
MINED108
`self.send_header` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:56
HIGH
MINED108
`self.send_response` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:55
HIGH
MINED108
`self.path` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:48
HIGH
MINED108
`self.handle_redirect_to_github` used but never assigned in __init__
hack/new-cluster/tasks/github/github-ap…:52
HIGH
MINED108
`self.validate_mutation_result` used but never assigned in __init__
hack/test-tekton-kueue-config.py:1608
HIGH
MINED108
`self.assertDictEqual` used but never assigned in __init__
hack/test-tekton-kueue-config.py:1599
HIGH
MINED108
`self.assertDictEqual` used but never assigned in __init__
hack/test-tekton-kueue-config.py:1589
HIGH
MINED108
`self.run_mutation_test` used but never assigned in __init__
hack/test-tekton-kueue-config.py:1574
HIGH
MINED108
`self.processed_configs` used but never assigned in __init__
hack/test-tekton-kueue-config.py:1571
HIGH
MINED108
`self.subTest` used but never assigned in __init__
hack/test-tekton-kueue-config.py:1568
HIGH
MINED108
`self.fail` used but never assigned in __init__
hack/test-tekton-kueue-config.py:1562
HIGH
MINED108
`self.fail` used but never assigned in __init__
hack/test-tekton-kueue-config.py:1556
HIGH
MINED108
`self.processed_configs` used but never assigned in __init__
hack/test-tekton-kueue-config.py:1515
HIGH
MINED106
Phantom test coverage: test_all_mutations
hack/test-tekton-kueue-config.py:1605
HIGH
MINED134
Binary file `hack/kueue-vm-quotas/__pycache__/update-kueue-vm-quotas.cpython-313.pyc` com…
hack/kueue-vm-quotas/__pycache__/update…:1
HIGH
MINED117
Workflow declares `permissions: write-all`
.github/workflows/kube-linter.yaml:12
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/verify-pipelines-conf…:23
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v3`
.github/workflows/validate-banner.yaml:20
HIGH
MINED115
Action `multani/action-setup-kustomize` pinned to mutable ref `@v1`
.github/workflows/enforce-ring-deployme…:41
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v5`
.github/workflows/enforce-ring-deployme…:32
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/enforce-ring-deployme…:28
HIGH
MINED115
Action `multani/action-setup-kustomize` pinned to mutable ref `@v1`
.github/workflows/forbid-clusterpolicie…:20
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/forbid-clusterpolicie…:17
HIGH
MINED115
Action `actions/setup-python` pinned to mutable ref `@v4`
.github/workflows/verify-kueue-queue-co…:21
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/verify-kueue-queue-co…:18
HIGH
MINED115
Action `codecov/codecov-action` pinned to mutable ref `@v5`
.github/workflows/codecov.yaml:78
HIGH
MINED115
Action `actions/setup-python` pinned to mutable ref `@v4`
.github/workflows/codecov.yaml:45
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/codecov.yaml:42
HIGH
MINED115
Action `codecov/codecov-action` pinned to mutable ref `@v5`
.github/workflows/codecov.yaml:31
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v5`
.github/workflows/codecov.yaml:16
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/codecov.yaml:13
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/yamllint.yaml:13
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v5`
.github/workflows/operator-changelog.ya…:23
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/operator-changelog.ya…:22
HIGH
MINED115
Action `actions/setup-python` pinned to mutable ref `@v4`
.github/workflows/test-tekton-kueue-con…:20
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/test-tekton-kueue-con…:17
HIGH
MINED115
Action `kyverno/action-install-cli` pinned to mutable ref `@v0.2.0`
.github/workflows/kyverno-policies-test…:19
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/kyverno-policies-test…:16
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v4`
.github/workflows/pr-render-diff.yaml:68
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v5`
.github/workflows/pr-render-diff.yaml:18
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/pr-render-diff.yaml:15
HIGH
GO-2026-5039
stdlib: GO-2026-5039
infra-tools/go.mod
HIGH
GO-2026-5038
stdlib: GO-2026-5038
infra-tools/go.mod
HIGH
GO-2026-5037
stdlib: GO-2026-5037
infra-tools/go.mod
HIGH
GO-2026-4986
stdlib: GO-2026-4986
infra-tools/go.mod
HIGH
GO-2026-4982
stdlib: GO-2026-4982
infra-tools/go.mod
HIGH
GO-2026-4981
stdlib: GO-2026-4981
infra-tools/go.mod
HIGH
GO-2026-4980
stdlib: GO-2026-4980
infra-tools/go.mod
HIGH
GO-2026-4977
stdlib: GO-2026-4977
infra-tools/go.mod
HIGH
GO-2026-4976
stdlib: GO-2026-4976
infra-tools/go.mod
HIGH
GO-2026-4971
stdlib: GO-2026-4971
infra-tools/go.mod
HIGH
GO-2026-4947
stdlib: GO-2026-4947
infra-tools/go.mod
HIGH
GO-2026-4946
stdlib: GO-2026-4946
infra-tools/go.mod
HIGH
GO-2026-4918
stdlib: GO-2026-4918
infra-tools/go.mod
HIGH
GO-2026-4870
stdlib: GO-2026-4870
infra-tools/go.mod
HIGH
GO-2026-4869
stdlib: GO-2026-4869
infra-tools/go.mod
HIGH
GO-2026-4865
stdlib: GO-2026-4865
infra-tools/go.mod
HIGH
GO-2026-4864
stdlib: GO-2026-4864
infra-tools/go.mod
HIGH
GO-2026-4603
stdlib: GO-2026-4603
infra-tools/go.mod
HIGH
GO-2026-4602
stdlib: GO-2026-4602
infra-tools/go.mod
HIGH
GO-2026-4601
stdlib: GO-2026-4601
infra-tools/go.mod
HIGH
GO-2026-4342
stdlib: GO-2026-4342
infra-tools/go.mod
HIGH
GO-2026-4341
stdlib: GO-2026-4341
infra-tools/go.mod
HIGH
GO-2026-4340
stdlib: GO-2026-4340
infra-tools/go.mod
HIGH
GO-2026-4337
stdlib: GO-2026-4337
infra-tools/go.mod
HIGH
GO-2025-4175
stdlib: GO-2025-4175
infra-tools/go.mod
HIGH
GO-2025-4155
stdlib: GO-2025-4155
infra-tools/go.mod
HIGH
GO-2025-4015
stdlib: GO-2025-4015
infra-tools/go.mod
HIGH
GO-2025-4014
stdlib: GO-2025-4014
infra-tools/go.mod
HIGH
GO-2025-4013
stdlib: GO-2025-4013
infra-tools/go.mod
HIGH
GO-2025-4012
stdlib: GO-2025-4012
infra-tools/go.mod
HIGH
GO-2025-4011
stdlib: GO-2025-4011
infra-tools/go.mod
HIGH
GO-2025-4010
stdlib: GO-2025-4010
infra-tools/go.mod
HIGH
GO-2025-4009
stdlib: GO-2025-4009
infra-tools/go.mod
HIGH
GO-2025-4008
stdlib: GO-2025-4008
infra-tools/go.mod
HIGH
GO-2025-4007
stdlib: GO-2025-4007
infra-tools/go.mod
HIGH
GO-2025-4006
stdlib: GO-2025-4006
infra-tools/go.mod
HIGH
GO-2025-3956
stdlib: GO-2025-3956
infra-tools/go.mod
HIGH
GO-2025-3849
stdlib: GO-2025-3849
infra-tools/go.mod
HIGH
GO-2026-5024
golang.org/x/sys: GO-2026-5024
infra-tools/go.mod
HIGH
GO-2026-5030
golang.org/x/net: GO-2026-5030
infra-tools/go.mod
HIGH
GO-2026-5029
golang.org/x/net: GO-2026-5029
infra-tools/go.mod
HIGH
GO-2026-5028
golang.org/x/net: GO-2026-5028
infra-tools/go.mod
HIGH
GO-2026-5027
golang.org/x/net: GO-2026-5027
infra-tools/go.mod
HIGH
GO-2026-5026
golang.org/x/net: GO-2026-5026
infra-tools/go.mod
HIGH
GO-2026-5025
golang.org/x/net: GO-2026-5025
infra-tools/go.mod
HIGH
GO-2026-4918
golang.org/x/net: GO-2026-4918
infra-tools/go.mod
HIGH
SEC013
[SEC013] Path Traversal — User Input in File Path: User-controlled input used in file pat…
components/image-controller/production/…:43
MED
SEC112
[SEC112] Go html/template bypass — text/template used for HTML output, or template.HTML o…
infra-tools/cmd/env-detector/main.go:368
MED
MINED111
Bare except continues silently
hack/new-cluster/tasks/github/github-ap…:114
MED
MINED111
Bare except continues silently
hack/test-tekton-kueue-config.py:1626
MED
COMP001
[COMP001] High cognitive complexity: Function `remove_tags` has cognitive complexity 23 (…
components/image-controller/production/…:114
MED
DKR007
Docker build context has no .dockerignore
.dockerignore
MED
WEB003
Public web service has no security.txt
.well-known/security.txt
MED
WEB015
Public web app has no Content Security Policy
index.html
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
infra-tools/internal/git/git.go:87
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
infra-tools/cmd/render-diff/ci.go:69
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
infra-tools/cmd/env-detector/main.go:217
LOW
COMP001
[COMP001] High cognitive complexity: Function `remove_leftover_tags` has cognitive comple…
components/image-controller/production/…:97
LOW
COMP001
[COMP001] High cognitive complexity: Function `get_quay_tags` has cognitive complexity 12…
components/image-controller/production/…:28
LOW
AIC003
Duplicated implementation block across source files
infra-tools/internal/logging/logging.go:33
LOW
WEB001
Public web app has no robots.txt
robots.txt
LOW
WEB002
Public web app has no sitemap
sitemap.xml
LOW
WEB008
Public docs site has no llms.txt
llms.txt
LOW
WEB011
Public web app has no humans.txt
humans.txt
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
infra-tools/internal/deptree/resolve.go:354
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
infra-tools/cmd/render-diff/main.go:68
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
infra-tools/cmd/env-detector/main.go:59
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
infra-tools/cmd/changelog-generator/mai…:38
INFO
MINED067
[MINED067] Python Requests No Timeout: requests.get/post/etc. without timeout= can hang f…
hack/new-cluster/tasks/github/github-ap…:94
INFO
MINED055
[MINED055] Npm Install No Lockfile: Production image runs npm install (resolves new versi…
hack/hac/installHac.sh:64