Code-quality scan: hcengineering/platform
Score: 70/100 (B) · 98 findings · scanned 2026-05-20 01:59 UTC · 60,404 LOC
| Severity |
Count |
| CRITICAL |
28 |
| HIGH |
34 |
| MEDIUM |
6 |
| LOW |
13 |
📊 Full filterable report · 
Top findings
- CRITICAL
MINED018 — Unsafe Deserialization Pickle
dev/import-tool/src/index.ts:184 · CWE-502 · ✓ Repobility
- CRITICAL
SEC116 — Ruby YAML.load / Marshal.load on untrusted input
dev/import-tool/src/index.ts:184 · A08:2021 Software & Data Integrity Failures
- CRITICAL
SEC079 — Python: yaml.load without SafeLoader
dev/import-tool/src/index.ts:184 · A05:2021 Security Misconfiguration
- CRITICAL
MINED116 — Workflow uses secrets.R2_SECRET_ACCESS_KEY on a pull_request trigger
.github/workflows/main.yml:921 · ✓ Repobility
- CRITICAL
MINED116 — Workflow uses secrets.R2_ACCESS_KEY_ID on a pull_request trigger
.github/workflows/main.yml:920 · ✓ Repobility
Security note: this issue is public. If any flagged finding is a real, exploitable vulnerability, please redirect to your SECURITY.md policy or open a private security advisory instead. We're happy to close this and re-submit privately.
Filed automatically. Close this issue if not useful — we won't refile. Full report: https://repobility.com/scan/1a8155c4-002f-4a0f-bd44-ca3a6ed02b15/
Code-quality scan:
hcengineering/platformScore: 70/100 (B) · 98 findings · scanned 2026-05-20 01:59 UTC · 60,404 LOC
📊 Full filterable report ·
Top findings
MINED018— Unsafe Deserialization Pickledev/import-tool/src/index.ts:184· CWE-502 · ✓ RepobilitySEC116— Ruby YAML.load / Marshal.load on untrusted inputdev/import-tool/src/index.ts:184· A08:2021 Software & Data Integrity FailuresSEC079— Python: yaml.load without SafeLoaderdev/import-tool/src/index.ts:184· A05:2021 Security MisconfigurationMINED116— Workflow usessecrets.R2_SECRET_ACCESS_KEYon apull_requesttrigger.github/workflows/main.yml:921· ✓ RepobilityMINED116— Workflow usessecrets.R2_ACCESS_KEY_IDon apull_requesttrigger.github/workflows/main.yml:920· ✓ RepobilitySecurity note: this issue is public. If any flagged finding is a real, exploitable vulnerability, please redirect to your
SECURITY.mdpolicy or open a private security advisory instead. We're happy to close this and re-submit privately.Filed automatically. Close this issue if not useful — we won't refile. Full report: https://repobility.com/scan/1a8155c4-002f-4a0f-bd44-ca3a6ed02b15/