Scan timing: clone 27.44s · analysis 17.79s · 28.9 MB · GitHub API rate-limit (preflight)
https://github.com/moby/moby
· scanned 2026-06-05 08:19 UTC (5 days, 19 hours ago)
· 10 languages
389 raw signals (185 security + 204 graph) 11/13 scanners ran 88th percentile · Go · large (100-500K LoC) System graph score 75 (higher by 15)
Last scanned 5 days, 19 hours ago · v2 · 138 actionable findings from 2 signal sources. 149 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
85.0 | 0.15 | 12.75 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 89.5 |
Showing 107 of 138 actionable findings. 287 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/arm64.yml:139, 251 (2 hits).github/workflows/bin-image.yml:71, 72 (2 hits).github/workflows/test.yml:90, 99 (2 hits).github/workflows/windows-2025.yml:38daemon/volume/local/local.go:460
daemon/volume/local/local_unix.go:170
Dockerfile:78, 410, 412, 413, 635 (5 hits)daemon/libnetwork/cmd/diagnostic/Dockerfile.dind:1daemon/libnetwork/cmd/ssd/Dockerfile:1daemon/libnetwork/support/Dockerfile:1Dockerfile:112, 131, 146, 186, 196, 205, 252, 294, +3 more (11 hits)contrib/busybox/Dockerfile:22hack/dockerfiles/govulncheck.Dockerfile:11daemon/attach.go:27
daemon/builder/dockerfile/buildargs.go:1daemon/builder/dockerfile/builder_windows.go:1daemon/builder/dockerfile/containerbackend.go:1pkg/plugins/plugins.go:117
daemon/internal/quota/testhelpers.go:61daemon/internal/usergroup/add_linux.go:88daemon/internal/usergroup/lookup_unix.go:105daemon/libnetwork/iptables/iptables.go:489
Exec used
contrib/otel/compose.yaml:4, 18 (2 hits)Dockerfile:644Dockerfile.simple:13Dockerfile.windows:159api/Dockerfile:23contrib/busybox/Dockerfile:18contrib/nnp-test/Dockerfile:5contrib/syscall-test/Dockerfile:5daemon/libnetwork/cmd/diagnostic/Dockerfile.client:1Dockerfile:68, 112, 131, 146, 186, 196, 205, 252, +4 more (12 hits)vendor/github.com/moby/policy-helpers/Dockerfile:11, 26 (2 hits)Dockerfile.simple:40contrib/busybox/Dockerfile:22Dockerfile:629, 645 (2 hits)Dockerfile.simple:61Dockerfile.windows:312contrib/nnp-test/Dockerfile:8contrib/syscall-test/Dockerfile:8man/vendor/github.com/cpuguy83/go-md2man/v2/Dockerfile:4vendor/github.com/pelletier/go-toml/Dockerfile:3cmd/dockerd/winresources/Dockerfile:15
CI/CD securitycontainers
.dockerignore
CI/CD securitycontainers
Dockerfile:50
containersPinned dependencies
Dockerfile:182
containersPinned dependencies
Dockerfile:411
containersPinned dependencies
Dockerfile:410
containersPinned dependencies
Dockerfile:126
containersPinned dependencies
Dockerfile:466
containersPinned dependencies
Dockerfile:458
containersPinned dependencies
Dockerfile:360
containersPinned dependencies
Dockerfile:286
containersPinned dependencies
Dockerfile:320
containersPinned dependencies
Dockerfile:68, 112, 131, 146, 186, 196, 205, 252, +4 more (12 hits)contrib/busybox/Dockerfile:22.github/workflows/bin-image.yml
CI/CD securitySupply chainGithub actions
api/docs/v1.32.yaml:4096
Weak hash
api/docs/v1.33.yaml:4100
Weak hash
api/docs/v1.34.yaml:4128
Weak hash
api/docs/v1.35.yaml:4132
Weak hash
api/docs/v1.36.yaml:4153
Weak hash
api/docs/v1.37.yaml:4173
Weak hash
api/docs/v1.38.yaml:4219
Weak hash
api/docs/v1.39.yaml:5502
Weak hash
api/docs/v1.40.yaml:5646
Weak hash
api/docs/v1.41.yaml:5900
Weak hash
api/docs/v1.42.yaml:5893
Weak hash
api/docs/v1.43.yaml:5926
Weak hash
api/docs/v1.44.yaml:6065
Weak hash
api/docs/v1.45.yaml:6051
Weak hash
api/docs/v1.46.yaml:6162
Weak hash
api/docs/v1.47.yaml:6184
Weak hash
api/docs/v1.48.yaml:7220
Weak hash
api/docs/v1.49.yaml:7227
Weak hash
api/docs/v1.50.yaml:7057
Weak hash
api/docs/v1.51.yaml:7078
Weak hash
api/docs/v1.52.yaml:7368
Weak hash
api/docs/v1.53.yaml:7616
Weak hash
api/docs/v1.54.yaml:7616
Weak hash
api/swagger.yaml:7616
Weak hash
Dockerfile
Ports
Dockerfile
Ports
Dockerfile
Ports
.dockerignore
CI/CD securitycontainers
client/container_wait.go:80client/hijack.go:56client/internal/jsonmessages.go:54daemon/builder/dockerfile/buildargs.go:1daemon/builder/dockerfile/builder_windows.go:1daemon/builder/dockerfile/containerbackend.go:1daemon/builder/dockerfile/evaluator.go:110
CI/CD securitycontainers
contrib/otel/compose.yaml:4, 10, 18 (3 hits)contrib/otel/compose.yaml:4, 10, 18 (3 hits)daemon/libnetwork/cmd/ssd/Dockerfile:22, 33 (2 hits)Dockerfile:64, 69, 85, 151, 257, 298, 331, 365, +5 more (13 hits)contrib/nnp-test/Dockerfile:6contrib/syscall-test/Dockerfile:6api/types/container/hostconfig_windows.go:21client/internal/jsonmessages.go:75client/pkg/streamformatter/streamformatter.go:103client/service_create.go:30client/service_logs.go:25contrib/syscall-test/userns.c:1daemon/container_operations_windows.go:44daemon/graphdriver/overlay2/overlay.go:101.github/copilot-instructions.md:1
client/config_update.go:1client/container_copy.go:1client/node_update.go:1client/secret_update.go:1client/service_update.go:1client/swarm_update.go:1client/volume_update.go:1daemon/volume/mounts/volume_copy.go:1daemon/libnetwork/cmd/ssd/Dockerfile:1
containersPinned dependencies
Dockerfile:84
containersPinned dependencies
cmd/dockerd/winresources/Dockerfile:11
containersPinned dependencies
Dockerfile:78
containersPinned dependencies
Dockerfile:412
containersPinned dependencies
Dockerfile:413
containersPinned dependencies
daemon/libnetwork/support/Dockerfile:1
containersPinned dependencies
Dockerfile:635
containersPinned dependencies
api/Dockerfile:4
containersPinned dependencies
Dockerfile:46
containersPinned dependencies
cmd/dockerd/winresources/Dockerfile:10
containersPinned dependencies
This page is publicly accessible at:
https://repobility.com/scan/fb0932ce-efa0-403b-a495-6413b4e72fc7/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/fb0932ce-efa0-403b-a495-6413b4e72fc7/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.