https://github.com/godotengine/godot
· scanned 2026-06-05 05:40 UTC (10 hours, 36 minutes ago)
· 10 languages
413 findings (37 legacy + 376 scanner) 11/13 scanners ran 56th percentile · C · large (100-500K LoC) Scanner says 91 (lower by 26)
Last scanned 10 hours, 36 minutes ago · v2 · 225 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
75.0 | 0.15 | 11.25 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
0.0 | 0.20 | 0.00 |
documentation_score |
90.0 | 0.15 | 13.50 |
practices_score |
57.0 | 0.15 | 8.55 |
code_quality |
66.0 | 0.10 | 6.60 |
| Overall | 1.00 | 64.9 |
Top 10 actions, ranked by impact × ease. Severity drives impact; tag-based fix-clarity drives ease.
platform/web/js/libs/library_godot_javascript_singleton.js:355.github/workflows/static_checks.yml:35platform/android/java/editor/src/main/java/com/android/apksig/internal/apk/v1/V1SchemeVerifier.java:1155platform/android/java/editor/src/main/java/com/android/apksig/internal/apk/v1/V1SchemeSigner.java:119platform/android/java/editor/src/main/java/com/android/apksig/internal/apk/v1/DigestAlgorithm.java:26platform/android/java/editor/src/main/java/com/android/apksig/internal/oid/OidConstants.java:396platform/android/java/editor/src/main/java/com/android/apksig/internal/pkcs7/AlgorithmIdentifier.java:68platform/windows/detect.py:34editor/editor_builders.py:90Click "Find this gap" on any action above to jump to it on the Findings tab. Adjust the chip bar to filter by impact (severity), layer, or source.
This page is publicly accessible at:
https://repobility.com/scan/f2237c1f-9cc0-4d72-89e9-d822433e9470/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/f2237c1f-9cc0-4d72-89e9-d822433e9470/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.