Security: Nix Fleet

0
Vulnerabilities
25
Credential Leaks
FAIL
Quality Gate
B
OWASP Grade
89.9h
Tech Debt (D)
Elite
DORA Rating

AI Fix Prompts

Auto-generated prompts to fix every issue — copy into Claude, GPT, or any AI coder

View AI Prompts
Repobility · MCP-ready · https://repobility.com

Quality Gate: Default Gate

Same analyzer free for public repos: https://repobility.com
MetricCondition
overall_score0.0 >= 50
security_score0.0 >= 40
critical_vulnerabilities0.0 <= 0
critical_credentials0.0 <= 0
duplication_pct6.6 <= 20

DORA Metrics

Per-row analysis by Repobility · https://repobility.com
Deploy Frequencydaily (3.0/week)
Lead Time39.0 hours
MTTR0.0 hours
Change Failure Rate0.0%
Total Commits50
Overall RatingELITE

Credential Findings (25)

Data scored by Repobility · https://repobility.com
SeverityPatternFileLine
high[sast:aljefra/ssrf-requests] SSRF via HTTP Client with Variable URLagents/lib/gh-manifest-server.py67
high[sast:aljefra/taint-path-traversal] Path Traversal via Tainted Dataagents/lib/gh-manifest-server.py88
high[sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URLcmd/nixfleet/internal/server/ui/app.js23
high[sast:aljefra/xss-innerhtml] XSS via innerHTML Assignmentcmd/nixfleet/internal/server/ui/app.js37
high[sast:aljefra/xss-innerhtml] XSS via innerHTML Assignmentcmd/nixfleet/internal/server/ui/app.js53
high[sast:aljefra/xss-innerhtml] XSS via innerHTML Assignmentcmd/nixfleet/internal/server/ui/app.js57
high[sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URLcmd/nixfleet/internal/server/ui/app.js142
high[sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URLcmd/nixfleet/internal/server/ui/app.js163
high[sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URLcmd/nixfleet/internal/server/ui/app.js184
high[sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URLcmd/nixfleet/internal/server/ui/app.js202
high[sast:aljefra/xss-innerhtml] XSS via innerHTML Assignmentcmd/nixfleet/internal/server/ui/app.js227
high[sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URLcmd/nixfleet/internal/server/ui/app.js233
high[sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URLcmd/nixfleet/internal/server/ui/app.js234
high[sast:aljefra/xss-innerhtml] XSS via innerHTML Assignmentcmd/nixfleet/internal/server/ui/app.js368
high[sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URLcmd/nixfleet/internal/server/ui/app.js383
high[sast:aljefra/xss-innerhtml] XSS via innerHTML Assignmentcmd/nixfleet/internal/server/ui/app.js429
high[sast:aljefra/xss-innerhtml] XSS via innerHTML Assignmentcmd/nixfleet/internal/server/ui/app.js445
high[sast:aljefra/xss-innerhtml] XSS via innerHTML Assignmentcmd/nixfleet/internal/server/ui/app.js460
high[sast:aljefra/xss-innerhtml] XSS via innerHTML Assignmentcmd/nixfleet/internal/server/ui/app.js462
high[sast:aljefra/xss-innerhtml] XSS via innerHTML Assignmentcmd/nixfleet/internal/server/ui/app.js472
high[sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URLcmd/nixfleet/internal/server/ui/app.js501
high[sast:aljefra/xss-innerhtml] XSS via innerHTML Assignmentcmd/nixfleet/internal/server/ui/app.js549
high[sast:aljefra/xss-innerhtml] XSS via innerHTML Assignmentcmd/nixfleet/internal/server/ui/app.js553
highPassword Assignmentnetboot/common.nix37
highPassword Assignmentnetboot/common.nix42