Skip to main content

Weekly open-source repository directory

The scanner backlog,
after evidence.

We rescan every repository each week, pin every run, and turn scanner output into a smaller queue maintainers can prioritize.

5,165

Findings triaged

Across 12 open-source projects

51%

Closed as likely noise

Only where decisive evidence exists

1,236

Security review queue

Needs review plus priority review

−76%

Queue reduction

From scanner output to security review

Weekly scan ledger

One growing corpus. Updated every week.

  • Likely noise
  • Needs review
  • Policy queue
  • Routed out
  • Priority review

Latest scans

Each result is pinned to a commit and refreshed weekly. As new projects join, they enter the same evidence-backed ledger.

12 repositories

keycloak/keycloak

Identity and access management

b2ed3f7Opengrep OSSAug 31, 2026

Scanner output

383 · full verdict mix

Security review

80 · 21% remains · 16 priority

79%

smaller security
review queue

spring-projects/spring-petclinic

Reference Spring application

91c4a20Semgrep OSSAug 30, 2026

Scanner output

92 · full verdict mix

Security review

11 · 12% remains · 2 priority

88%

smaller security
review queue

apache/fineract

Core banking platform

307fb95Opengrep OSSAug 29, 2026

Scanner output

641 · full verdict mix

Security review

197 · 31% remains · 43 priority

69%

smaller security
review queue

jhipster/jhipster-sample-app

Generated Spring application

e841b5cSemgrep OSSAug 29, 2026

Scanner output

174 · full verdict mix

Security review

26 · 15% remains · 5 priority

85%

smaller security
review queue

thingsboard/thingsboard

IoT platform and device management

fe9043bOpengrep OSSAug 31, 2026

Scanner output

812 · full verdict mix

Security review

148 · 18% remains · 24 priority

82%

smaller security
review queue

openmrs/openmrs-core

Medical record system platform

a6e5d92Semgrep OSSAug 30, 2026

Scanner output

556 · full verdict mix

Security review

189 · 34% remains · 31 priority

66%

smaller security
review queue

apache/ofbiz-framework

Enterprise automation framework

4a7c108Opengrep OSSAug 27, 2026

Scanner output

731 · full verdict mix

Security review

127 · 17% remains · 21 priority

83%

smaller security
review queue

camunda/camunda-bpm-platform

Process orchestration platform

c8152efSemgrep OSSAug 30, 2026

Scanner output

418 · full verdict mix

Security review

126 · 30% remains · 17 priority

70%

smaller security
review queue

spring-petclinic/spring-petclinic-microservices

Distributed Spring reference system

57db903Opengrep OSSAug 28, 2026

Scanner output

209 · full verdict mix

Security review

30 · 14% remains · 5 priority

86%

smaller security
review queue

shopizer-ecommerce/shopizer

Spring commerce platform

0b8f61aSemgrep OSSAug 26, 2026

Scanner output

287 · full verdict mix

Security review

90 · 31% remains · 11 priority

69%

smaller security
review queue

BroadleafCommerce/BroadleafCommerce

Extensible commerce framework

d9487e2Opengrep OSSAug 25, 2026

Scanner output

498 · full verdict mix

Security review

93 · 19% remains · 14 priority

81%

smaller security
review queue

jenkinsci/jenkins

Automation server

8c16a74Semgrep OSSAug 28, 2026

Scanner output

364 · full verdict mix

Security review

119 · 33% remains · 15 priority

67%

smaller security
review queue

The ICTX delta

76%

smaller security review queue

5,165 scanner findings became 1,236 security-review findings. The full verdict mix stays visible so every finding remains accounted for.

  1. Account for the full scanner output

    No silent suppression. Noise, policy work, routed findings, and review all stay visible.

  2. Close only on decisive evidence

    Each close carries the rule, code context, and evidence trail needed to dispute it.

  3. Return attention to the real queue

    Reviewers start with the promoted findings instead of rebuilding context for every alert.

CLOSES

Full trails, public by default.

Noise and routed-out findings show rules fired, code context, and evidence.

PROMOTED

Counts and CWE mix only.

Live locations and call paths stay private so this directory never becomes an attack map.

CONFIRMED

Maintainers hear first.

Priority-review findings follow responsible disclosure before publication.

For open-source maintainers

You own the roadmap. We'll help shrink the security queue.

This directory exists to give maintainers a prioritized, evidence-backed queue—not another report to absorb. If your project is here, we'll walk through the results with you. If it isn't, nominate it for a future weekly scan.