https://github.com/kubernetes/kubernetes
· scanned 2026-06-05 05:10 UTC (9 hours, 33 minutes ago)
· 10 languages
1074 findings (178 legacy + 896 scanner) 11/13 scanners ran 50th percentile · Go · huge (>500K LoC)
Last scanned 9 hours, 33 minutes ago · v2 · 626 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
98.0 | 0.15 | 14.70 |
practices_score |
42.0 | 0.15 | 6.30 |
code_quality |
69.0 | 0.10 | 6.90 |
| Overall | 1.00 | 82.7 |
Showing 422 of 626 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
cmd/kubeadm/app/util/users/users_linux.go:83
secrets
staging/src/k8s.io/cli-runtime/pkg/genericclioptions/config_flags.go:58
secrets
staging/src/k8s.io/client-go/rest/config.go:205
secrets
staging/src/k8s.io/client-go/tools/clientcmd/overrides.go:163
secrets
staging/src/k8s.io/apiserver/pkg/authentication/cel/mapper.go:62
owaspeval_used
staging/src/k8s.io/client-go/tools/cache/synctrack/lazy.go:52
owaspeval_used
staging/src/k8s.io/kubectl/pkg/cmd/exec/exec.go:90
owaspexec_used
staging/src/k8s.io/kms/internal/plugins/_mock/Dockerfile:31
supply-chaindockerpinned-dependencies
staging/src/k8s.io/client-go/examples/in-cluster-client-configuration/Dockerfile:14
supply-chaindockerpinned-dependencies
staging/src/k8s.io/kube-aggregator/artifacts/simple-image/Dockerfile:14
supply-chaindockerpinned-dependencies
staging/src/k8s.io/sample-apiserver/artifacts/simple-image/Dockerfile:14
supply-chaindockerpinned-dependencies
staging/src/k8s.io/apiextensions-apiserver/artifacts/simple-image/Dockerfile:14
supply-chaindockerpinned-dependencies
staging/src/k8s.io/pod-security-admission/webhook/Dockerfile:14
supply-chaindockerpinned-dependencies
cluster/images/etcd-version-monitor/Dockerfile:14
supply-chaindockerpinned-dependencies
hack/tools/instrumentation/documentation/documentation-list.yaml:1507
owaspweak_hash
staging/src/k8s.io/apiserver/pkg/util/webhook/metrics.go:42
owaspweak_hash
staging/src/k8s.io/kube-aggregator/pkg/apiserver/metrics.go:42
owaspweak_hash
cluster/gce/gci/configure-helper.sh
securityports
cluster/addons/calico-policy-controller/felixconfigurations-crd.yaml
securityports
cluster/gce/gci/configure-helper.sh
securityports
cluster/gce/gci/configure-helper.sh
securityports
cluster/images/kubemark/Dockerfile:22
supply-chaindockerpinned-dependencies
cluster/gce/gci/mounter/Dockerfile:14
supply-chaindockerpinned-dependencies
staging/src/k8s.io/kubectl/pkg/util/i18n/translations/extract.py:44
dead-code
staging/src/k8s.io/kubectl/pkg/util/i18n/translations/extract.py:62
dead-code
staging/src/k8s.io/kubectl/pkg/util/i18n/translations/extract.py:37
dead-code
staging/src/k8s.io/kubectl/pkg/util/i18n/translations/extract.py:54
dead-code
Showing first 300 of 422. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/ff9a7d79-b095-4271-96e0-6710ec3d6b0f/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/ff9a7d79-b095-4271-96e0-6710ec3d6b0f/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.