Scan timing: clone 18.97s · analysis 20.52s · 49.8 MB · GitHub API rate-limit (preflight)
https://github.com/google/oss-fuzz
· scanned 2026-06-05 14:28 UTC (5 days, 4 hours ago)
· 10 languages
10219 raw signals (4417 security + 5802 graph) 11/13 scanners ran 41st percentile · Python · large (100-500K LoC) System graph score 54 (higher by 19)
Last scanned 5 days, 4 hours ago · v2 · 1638 actionable findings from 2 signal sources. 5654 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
46.0 | 0.20 | 9.20 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
79.0 | 0.15 | 11.85 |
code_quality |
61.0 | 0.10 | 6.10 |
| Overall | 1.00 | 73.1 |
Showing 1553 of 1638 actionable findings. 7292 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
infra/bisector.py:146
projects/multidict/fuzz_md.py:101
projects/msal/fuzz_tokencache.py:24, 26 (2 hits)infra/utils.py:202projects/flask/cors_fuzz_flask.py:115projects/gitdb/fuzz_gitdb.py:55projects/jinja2/fuzz_jinja_compile_templates.py:27projects/olefile/fuzz_reader.py:36projects/opencensus-python/fuzz_trace.py:52projects/oscrypto/fuzz_asymmetric_load.py:26projects/multidict/fuzz_md.py:101
projects/apache-commons-lang/SerializationUtilsFuzzer.java:38
.github/workflows/cflite_pr.yml:32, 46 (2 hits)projects/spring-security/InMemoryUserDetailsManagerChangePasswordFuzzer.java:34
projects/digest/fuzz_digest.py:29
infra/base-images/base-builder/install_rust.sh:18
infra/experimental/SystemSan/target.cpp:26
projects/github_scarecrow/shell_injection_poc_fuzzer.py:32
projects/g-api-secret-manager/fuzz_client.py:30
projects/g-api-resumable-media-python/fuzz_uploader.py:58
projects/g-api-resource-manager/fuzz_tag_values_client.py:54
projects/pyjwt/fuzz_jwt.py:25
projects/g-api-resource-manager/fuzz_tag_values_client.py:75
projects/glom/fuzz_reduction.py:23
projects/g-api-resource-manager/fuzz_tag_values_client.py:85
projects/g-api-resource-manager/fuzz_tag_values_client.py:35
projects/glom/fuzz_reduction.py:33
projects/g-api-resumable-media-python/fuzz_uploader.py:27
projects/httpretty/fuzz_httpretty_e2e.py:22
projects/tomlkit/fuzz_dumps.py:21
projects/g-api-resource-manager/fuzz_tag_values_client.py:98
projects/g-api-resumable-media-python/fuzz_uploader.py:23
projects/g-api-resource-manager/fuzz_tag_values_client.py:64
infra/experimental/mcp/client.py:204
.clusterfuzzlite/Dockerfile:14infra/build_fuzzers.Dockerfile:18infra/build_fuzzers.ubuntu-24-04.Dockerfile:18infra/run_fuzzers.Dockerfile:18infra/run_fuzzers.ubuntu-24-04.Dockerfile:18projects/angular/Dockerfile:16projects/cubefs/Dockerfile:16projects/dropbear/Dockerfile:16projects/suricata/Dockerfile:21, 22, 23, 25, 29 (5 hits)projects/libraw/Dockerfile:21, 23, 24 (3 hits)projects/ntopng/Dockerfile:36, 39, 41 (3 hits)projects/cairo/Dockerfile:26, 28 (2 hits)projects/dlplibs/Dockerfile:22, 30 (2 hits)projects/ecc-diff-fuzzer/Dockerfile:43projects/fuzzing-puzzles/Dockerfile:19projects/gonids/Dockerfile:19infra/base-images/base-runner/profraw_update.py:168projects/giflib/dgif_fuzz_common.cc:28projects/nfstream/pcap_fuzzer.py:26projects/apache-commons-jxpath/JXPathFuzzer.java:39projects/dom4j/DOMReaderFuzzer.java:36projects/hamcrest/HamcrestFuzzer.java:273projects/jackson-datatype-joda/JodaDeserializerFuzzer.java:117projects/jackson-datatypes-collections/EclipseCollectionsSerializerFuzzer.java:173projects/jackson-datatypes-collections/GuavaDeserializerFuzzer.java:121projects/cloud-custodian/Dockerfile:20projects/connectedhomeip/Dockerfile:27projects/cryptography/Dockerfile:22projects/jsch/Dockerfile:50projects/libcst/Dockerfile:20projects/nbclassic/Dockerfile:18projects/orjson/Dockerfile:25projects/unblob/Dockerfile:20.github/workflows/pr_helper.yml:19, 21, 34, 49, 62 (9 hits).github/workflows/infra_tests.yml:21, 28, 34 (5 hits).github/workflows/check_base_os.yml:29, 45 (4 hits).github/workflows/index_build_tests.yml:21, 28 (3 hits).github/workflows/presubmit.yml:20, 28 (3 hits).github/workflows/project_tests.yml:56, 74 (3 hits).github/workflows/codeql-analysis.yml:26 (2 hits).github/workflows/ubuntu_version_sync.yml:32 (2 hits).github/workflows/codeql-analysis.yml:30, 41, 55 (6 hits).github/workflows/cflite_pr.yml:24, 37 (4 hits).github/workflows/infra_tests.yml:45infra/experimental/mcp/client.py:204
Sync io in asyncPerformance
projects/cloud-custodian/Dockerfile:20projects/connectedhomeip/Dockerfile:27projects/cryptography/Dockerfile:22projects/jsch/Dockerfile:50projects/libcst/Dockerfile:20projects/nbclassic/Dockerfile:18projects/orjson/Dockerfile:25projects/unblob/Dockerfile:20projects/flask/fuzz_json.py:35
securityAuth flask unauth route
projects/asteval/fuzz_eval.py:31
Eval used
infra/base-images/base-builder/sanitizers/pysecsan/pysecsan/yaml_deserialization.py:23infra/chronos/integrity_validator_check_replay.py:47projects/cloud-custodian/fuzz_query_parser.py:35projects/angular/compiler/fuzz_tests/fuzz_parse_template.js:27projects/angular/compiler/fuzz_tests/fuzz_parser.js:59projects/node-xml2js/fuzz_parseString.js:50infra/experimental/mcp/requirements.txt:3
projects/multidict/fuzz_md.py:101
projects/js-yaml/fuzz.js:28
infra/base-images/base-builder/python_coverage_helper.py:64infra/cifuzz/filestore/github_actions/__init__.py:133infra/cifuzz/http_utils.py:59projects/grpc-go/fuzz_hello.go:27
projects/fabric/persistence_fuzzer.go:36
infra/base-images/base-builder/make_build_replayable.py:59
projects/hsqldb/build.sh:19
infra/retry.py:81, 98 (2 hits)projects/flask-restx/fuzz_reqparse.py:30, 42 (2 hits)infra/pr_helper.py:54projects/aiohttp/fuzz_web_request.py:34projects/asttokens/fuzz_asttokens.py:26projects/decorator/fuzz_funcmarker.py:35projects/flask/cors_fuzz_flask.py:78projects/g-api-python-bigquery-storage/fuzz_avroparser.py:32.clusterfuzzlite/Dockerfile:15infra/base-images/base-builder-fuzzbench/Dockerfile:17infra/base-images/base-builder-go/Dockerfile:17infra/base-images/base-builder-javascript/Dockerfile:17infra/base-images/base-builder-jvm/Dockerfile:59infra/base-images/base-builder-python/Dockerfile:17infra/base-images/base-builder-ruby/Dockerfile:17infra/base-images/base-builder-rust/Dockerfile:17projects/suricata/Dockerfile:21, 22, 23, 25, 30 (5 hits)infra/base-images/base-builder/Dockerfile:193, 194, 195, 196 (4 hits)projects/ntopng/Dockerfile:37, 39, 41, 43 (4 hits)projects/gdk-pixbuf/Dockerfile:39, 40, 41 (3 hits)projects/libraw/Dockerfile:22, 23, 24 (3 hits)projects/zydis/Dockerfile:19, 21, 23 (3 hits)projects/cairo/Dockerfile:27, 28 (2 hits)projects/dlplibs/Dockerfile:22, 30 (2 hits)projects/joda-convert/Dockerfile:17
CI/CD securitycontainers
.clusterfuzzlite/Dockerfile:16infra/build/functions/trial_build/Dockerfile:20infra/cifuzz/test_data/external-project/.clusterfuzzlite/Dockerfile:20infra/experimental/SystemSan/PoEs/node-shell-quote-v1.7.3/Dockerfile:32infra/experimental/SystemSan/PoEs/pytorch-lightning-1.5.10/Dockerfile:29infra/indexer/Dockerfile:5projects/spring-boot/Dockerfile:32projects/spring-framework/Dockerfile:36infra/cifuzz/cifuzz-base/Dockerfile:39
CI/CD securitycontainers
infra/build/functions/trial_build/Dockerfile:21
CI/CD securitycontainers
infra/uploader/Dockerfile:3projects/bincode/Dockerfile:17projects/cloud-hypervisor/Dockerfile:19projects/envoy/Dockerfile:23projects/esp-v2/Dockerfile:21projects/inih/Dockerfile:17projects/iroha/Dockerfile:19projects/jetty/Dockerfile:43.well-known/security.txt
projects/bignum-fuzzer/build.sh:19
infra/base-images/base-builder/install_rust.sh:18
infra/experimental/chronos/Dockerfile:16
containersPinned dependencies
infra/base-images/base-builder-fuzzbench/Dockerfile:16infra/base-images/base-builder-go/Dockerfile:16infra/base-images/base-builder-javascript/Dockerfile:16infra/base-images/base-builder-jvm/Dockerfile:16infra/base-images/base-builder-python/Dockerfile:16infra/base-images/base-builder-ruby/Dockerfile:16infra/base-images/base-builder-rust/Dockerfile:16infra/base-images/base-builder-swift/Dockerfile:16projects/atomic/Dockerfile:16projects/blackfriday/Dockerfile:16projects/boringssl/Dockerfile:16projects/burntsushi-toml/Dockerfile:16projects/caddy/Dockerfile:16projects/cascadia/Dockerfile:16projects/cel-go/Dockerfile:16projects/cert-manager/Dockerfile:16projects/angular/Dockerfile:16projects/canvg/Dockerfile:16projects/closure-library/Dockerfile:16projects/d3/Dockerfile:16projects/fast-xml-parser/Dockerfile:16projects/fastify/Dockerfile:16projects/javascript-example/Dockerfile:16projects/jimp/Dockerfile:16projects/angus-mail/Dockerfile:16projects/antlr3-java/Dockerfile:16projects/antlr4-java/Dockerfile:16projects/apache-axis2/Dockerfile:16projects/apache-commons-bcel/Dockerfile:16projects/apache-commons-beanutils/Dockerfile:16projects/apache-commons-cli/Dockerfile:16projects/apache-commons-codec/Dockerfile:16projects/joda-convert/Dockerfile:16
containersPinned dependencies
infra/experimental/SystemSan/PoEs/pytorch-lightning-1.5.10/Dockerfile:16projects/abseil-py/Dockerfile:15projects/adal/Dockerfile:16projects/aiohttp/Dockerfile:16projects/airflow/Dockerfile:16projects/aniso8601/Dockerfile:15projects/argcomplete/Dockerfile:15projects/arrow-py/Dockerfile:16projects/ox-ruby/Dockerfile:16
containersPinned dependencies
infra/base-images/base-runner/Dockerfile:26
containersPinned dependencies
projects/anise/Dockerfile:16projects/askama/Dockerfile:16projects/bincode/Dockerfile:16projects/bls-signatures/Dockerfile:16projects/bson-rust/Dockerfile:16projects/chrono/Dockerfile:16projects/clamav/Dockerfile:16projects/cloud-hypervisor/Dockerfile:16infra/base-images/base-builder/Dockerfile:16
containersPinned dependencies
infra/base-images/base-runner/Dockerfile:25
containersPinned dependencies
infra/indexer/Dockerfile:1
containersPinned dependencies
infra/base-images/base-runner/Dockerfile:19, 34 (2 hits)infra/base-images/base-clang/Dockerfile:18infra/base-images/base-runner-debug/Dockerfile:16
containersPinned dependencies
infra/cifuzz/cifuzz-base/Dockerfile:16
containersPinned dependencies
projects/suricata/Dockerfile:21, 22, 23, 25, 29 (5 hits)infra/base-images/base-builder/Dockerfile:193, 194, 195, 196 (4 hits)projects/ntopng/Dockerfile:36, 39, 41, 43 (4 hits)projects/gdk-pixbuf/Dockerfile:38, 40, 41 (3 hits)projects/libraw/Dockerfile:21, 23, 24 (3 hits)projects/zydis/Dockerfile:18, 21, 23 (3 hits)projects/cairo/Dockerfile:26, 28 (2 hits)projects/dlplibs/Dockerfile:22, 30 (2 hits)Showing first 300 of 1553. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/22b9aba9-65f4-441a-acc2-731e6f06fa5a/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/22b9aba9-65f4-441a-acc2-731e6f06fa5a/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.