https://github.com/godotengine/godot
· scanned 2026-06-05 05:40 UTC (3 hours, 15 minutes ago)
· 10 languages
413 findings (37 legacy + 376 scanner) 11/13 scanners ran Scanner says 91 (lower by 26)
Last scanned 3 hours, 15 minutes ago · v2 · 225 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
75.0 | 0.15 | 11.25 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
0.0 | 0.20 | 0.00 |
documentation_score |
90.0 | 0.15 | 13.50 |
practices_score |
57.0 | 0.15 | 8.55 |
code_quality |
66.0 | 0.10 | 6.60 |
| Overall | 1.00 | 64.9 |
Showing 209 of 225 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
core/io/file_access_encrypted.cpp:111
qualitylegacy
core/crypto/crypto_core.h:118
qualitylegacy
core/crypto/crypto_core.cpp:239
qualitylegacy
core/core_builders.py:185
qualitylegacy
.github/workflows/android_builds.yml:48
dependencylegacy
.github/workflows/web_builds.yml:37
dependencylegacy
.github/workflows/macos_builds.yml:35
dependencylegacy
.github/workflows/windows_builds.yml:60
dependencylegacy
.github/workflows/ios_builds.yml:22
dependencylegacy
.github/workflows/static_checks.yml:23
dependencylegacy
.github/workflows/linux_builds.yml:122
dependencylegacy
.github/workflows/linux_builds.yml:166
dependencylegacy
.github/workflows/android_builds.yml:53
dependencylegacy
.github/workflows/web_builds.yml:42
dependencylegacy
.github/workflows/android_builds.yml:139
dependencylegacy
.github/workflows/android_builds.yml:145
dependencylegacy
.github/workflows/static_checks.yml:43
dependencylegacy
.github/workflows/linux_builds.yml:184
dependencylegacy
.github/workflows/static_checks.yml:35
dependencylegacy
platform/web/js/libs/library_godot_javascript_singleton.js:355
owaspeval_used
.github/workflows/static_checks.yml:35
supply-chaingithub-actionspinned-dependencies
core/extension/make_interface_header.py:161
qualitylegacy
.github/workflows/linux_builds.yml:184
supply-chaingithub-actionspinned-dependencies
.github/workflows/static_checks.yml:43
supply-chaingithub-actionspinned-dependencies
.github/workflows/web_builds.yml:42
supply-chaingithub-actionspinned-dependencies
.github/workflows/android_builds.yml:139
supply-chaingithub-actionspinned-dependencies
.github/workflows/android_builds.yml:145
supply-chaingithub-actionspinned-dependencies
editor/editor_builders.py:90
owaspsubprocess_shell_true
platform/windows/detect.py:34
owaspsubprocess_shell_true
platform/android/java/editor/src/main/java/com/android/apksig/internal/apk/v1/DigestAlgorithm.java:26
owaspweak_hash
platform/android/java/editor/src/main/java/com/android/apksig/internal/apk/v1/V1SchemeSigner.java:119
owaspweak_hash
platform/android/java/editor/src/main/java/com/android/apksig/internal/apk/v1/V1SchemeVerifier.java:1155
owaspweak_hash
platform/android/java/editor/src/main/java/com/android/apksig/internal/oid/OidConstants.java:396
owaspweak_hash
platform/android/java/editor/src/main/java/com/android/apksig/internal/pkcs7/AlgorithmIdentifier.java:68
owaspweak_hash
core/extension/make_wrappers.py:125
qualitylegacy
core/math/transform_interpolator.cpp:40
qualitylegacy
core/math/rect2i.h:16
qualitylegacy
core/math/rect2.cpp:18
qualitylegacy
core/math/geometry_3d.h:215
qualitylegacy
core/math/geometry_2d.h:180
qualitylegacy
core/math/face3.h:54
qualitylegacy
core/math/dynamic_bvh.h:79
qualitylegacy
core/math/a_star_grid_2d.h:48
qualitylegacy
core/math/a_star_grid_2d.cpp:401
qualitylegacy
core/io/file_access_encrypted.h:26
qualitylegacy
.github/workflows/linux_builds.yml:122
supply-chaingithub-actionspinned-dependencies
.github/workflows/linux_builds.yml:166
supply-chaingithub-actionspinned-dependencies
.github/workflows/static_checks.yml:23
supply-chaingithub-actionspinned-dependencies
.github/workflows/ios_builds.yml:22
supply-chaingithub-actionspinned-dependencies
.github/workflows/windows_builds.yml:60
supply-chaingithub-actionspinned-dependencies
.github/workflows/macos_builds.yml:35
supply-chaingithub-actionspinned-dependencies
.github/workflows/web_builds.yml:37
supply-chaingithub-actionspinned-dependencies
.github/workflows/android_builds.yml:48
supply-chaingithub-actionspinned-dependencies
.github/workflows/android_builds.yml:53
supply-chaingithub-actionspinned-dependencies
methods.py:589
dead-code
methods.py:595
dead-code
methods.py:583
dead-code
methods.py:79
dead-code
platform_methods.py:164
dead-code
methods.py:601
dead-code
methods.py:312
dead-code
methods.py:239
dead-code
methods.py:459
dead-code
methods.py:114
dead-code
methods.py:122
dead-code
methods.py:542
dead-code
platform_methods.py:381
dead-code
methods.py:406
dead-code
methods.py:424
dead-code
methods.py:577
dead-code
methods.py:919
dead-code
methods.py:950
dead-code
methods.py:963
dead-code
methods.py:852
dead-code
methods.py:953
dead-code
methods.py:87
dead-code
methods.py:30
dead-code
platform_methods.py:307
dead-code
methods.py:815
dead-code
methods.py:364
dead-code
methods.py:811
dead-code
This page is publicly accessible at:
https://repobility.com/scan/f2237c1f-9cc0-4d72-89e9-d822433e9470/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/f2237c1f-9cc0-4d72-89e9-d822433e9470/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.