Scan timing: clone 2.6s · analysis 19.71s · 22.3 MB · GitHub API rate-limit (preflight)
https://github.com/controlplaneio-fluxcd/flux-operator
· scanned 2026-06-05 21:09 UTC (4 days, 11 hours ago)
· 10 languages
313 raw signals (155 security + 158 graph) 45th percentile · Go · large (100-500K LoC) System graph score 77 (lower by 5)
Last scanned 4 days, 11 hours ago · v2 · 171 actionable findings from 2 signal sources. 63 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
47.6 | 0.25 | 11.90 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
76.0 | 0.15 | 11.40 |
practices_score |
94.0 | 0.15 | 14.10 |
code_quality |
47.6 | 0.10 | 4.76 |
| Overall | 1.00 | 71.9 |
Showing 135 of 171 actionable findings. 234 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
docs/web/web-sso-microsoft.md:30, 71 (2 hits)cmd/mcp/toolbox/library/index.gob:7988, 13803, 13873 (3 hits)internal/lkm/fetch.go:27, 35 (2 hits)internal/lkm/jwt_test.go:65, 255 (2 hits)internal/controller/resourcesetinputprovider_controller_git_test.go:708web/src/mock/resource.js:4002
web/src/mock/resource.js:3904
cmd/mcp/toolbox/library/index.gob:5595, 20390 (2 hits)cmd/cli/create_secret_sops_test.go:201docs/api/v1/resourcesetinputprovider.md:467internal/controller/testdata/rsa-private-key.pem:1cmd/mcp/toolbox/library/index.gob:124, 12939 (2 hits)web/package-lock.json
internal/lkm/fetch.go:131
config/olm/test/opm.Dockerfile:1, 14 (2 hits)Dockerfile:29cmd/cli/Dockerfile:36cmd/mcp/Dockerfile:25.github/workflows/release.yaml:194 (2 hits)go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
go.mod
.github/workflows/e2e-cli.yaml:16
cmd/cli/skills_install.go:48
web/src/components/auth/LoginPage.jsx:74
web/package-lock.json
web/package-lock.json
.dockerignore
CI/CD securitycontainers
web/src/utils/version.js:38
web/package.json
web/package.json
cmd/cli/skills_update.go:1
web/package-lock.json
.github/workflows/e2e-cli.yaml.github/workflows/e2e-olm.yaml.github/workflows/preview.yaml.github/workflows/push-manifests.yaml.github/workflows/release.yamlweb/src/components/dashboards/common/yaml.jsx:69
Dangerous innerhtml
web/src/components/user/ProfilePage.jsx:153
Dangerous innerhtml
cmd/cli/create_secret_web_config.go:101cmd/cli/debug_web_cookie.go:70cmd/cli/distro_decrypt_manifests.go:128cmd/mcp/toolbox/suspend_reconciliation.go:24, 28, 31 (3 hits)cmd/cli/tree_resourceset.go:27, 64 (2 hits)cmd/mcp/toolbox/resume_reconciliation.go:28, 31 (2 hits)api/v1/resourcesetinputprovider_types.go:128cmd/cli/build_resourceset.go:55cmd/cli/create_secret_githubapp.go:102cmd/cli/create_secret_proxy.go:87cmd/cli/create_secret_registry.go:87web/package.json
web/package.json
web/package.json
web/package.json
web/package.json
web/package.json
cmd/cli/Dockerfile:36
containersPinned dependencies
Dockerfile:29
containersPinned dependencies
cmd/mcp/Dockerfile:25
containersPinned dependencies
Dockerfile:2cmd/cli/Dockerfile:7cmd/mcp/Dockerfile:2
This page is publicly accessible at:
https://repobility.com/scan/f104ae14-dc29-43fb-b60b-d9c0168d1d86/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/f104ae14-dc29-43fb-b60b-d9c0168d1d86/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.