Scan timing: clone 3.39s · analysis 21.94s · 5.4 MB · GitHub preflight 484ms
https://github.com/apache/maven-resolver
· scanned 2026-06-05 14:17 UTC (5 days, 4 hours ago)
· 10 languages
80 raw signals (54 security + 26 graph) 50th percentile · Java · large (100-500K LoC)
Last scanned 5 days, 4 hours ago · v2 · 23 actionable findings from 2 signal sources. 44 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
71.5 | 0.25 | 17.88 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
73.0 | 0.15 | 10.95 |
practices_score |
67.0 | 0.15 | 10.05 |
code_quality |
60.7 | 0.10 | 6.07 |
| Overall | 1.00 | 73.7 |
Showing 8 of 23 actionable findings. 67 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
maven-resolver-api/src/main/java/org/eclipse/aether/repository/AuthenticationContext.java:71
maven-resolver-demos/maven-resolver-demo-snippets/src/main/data/demo.jar:1
.github/workflows/maven-verify.yml:27 (2 hits).github/workflows/pr-automation.yml:27 (2 hits).github/workflows/release-drafter.yml:27 (2 hits).github/workflows/stale.yml:28maven-resolver-api/src/main/java/org/eclipse/aether/repository/AuthenticationDigest.java:94
Weak hash
maven-resolver-transport-jetty/src/main/java/org/eclipse/aether/transport/jetty/JettyTransporter.java:86, 188 (2 hits)maven-resolver-util/src/main/java/org/eclipse/aether/util/graph/manager/TransitiveDependencyManager.java:17, 29 (2 hits)maven-resolver-api/src/main/java/org/eclipse/aether/installation/InstallResult.java:52maven-resolver-api/src/main/java/org/eclipse/aether/metadata/AbstractMetadata.java:39maven-resolver-generator-sigstore/src/main/java/org/eclipse/aether/generator/sigstore/SigstoreSignatureArtifactGenerator.java:112maven-resolver-impl/src/main/java/org/eclipse/aether/impl/scope/CommonBuilds.java:80maven-resolver-impl/src/main/java/org/eclipse/aether/internal/impl/DefaultFileProcessor.java:97maven-resolver-impl/src/main/java/org/eclipse/aether/internal/impl/DefaultInstaller.java:81
This page is publicly accessible at:
https://repobility.com/scan/eec27b17-d946-4a29-9c69-3fe3b79f0ce6/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/eec27b17-d946-4a29-9c69-3fe3b79f0ce6/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.