Scan timing: clone 9.15s · analysis 16.04s · 62.4 MB · GitHub API rate-limit (preflight)
https://github.com/facebook/openzl
· scanned 2026-06-05 23:57 UTC (4 days, 2 hours ago)
· 10 languages
324 raw signals (136 security + 188 graph) 11/13 scanners ran 95th percentile · C · large (100-500K LoC) System graph score 84 (higher by 3)
Last scanned 4 days, 2 hours ago · v2 · 104 actionable findings from 2 signal sources. 101 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
98.0 | 0.15 | 14.70 |
practices_score |
70.0 | 0.15 | 10.50 |
code_quality |
66.0 | 0.10 | 6.60 |
| Overall | 1.00 | 86.5 |
Showing 64 of 104 actionable findings. 205 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
examples/zs2_struct.c:199
examples/zs2_pipeline.c:136
.github/workflows/dev-ci.yml:42, 67, 126, 157, 176, 185, 194, 196, +4 more (14 hits).github/workflows/deploy-docs.yml:32, 36, 48, 58, 72 (6 hits).github/workflows/test-deploy-docs.yml:18, 22, 34 (6 hits).github/workflows/cmake-ci.yml:76, 144, 153 (3 hits).github/workflows/release-binaries.yml:36, 65, 124 (3 hits).github/workflows/windows-ci.yml:62, 162 (2 hits).github/workflows/cross-platform-ci.yml:64.github/workflows/openzl-demo-wheels.yml:61tools/compressor_serialization/to_cbor.py:70
Eval used
contrib/reproducibility/dataset_manager/requirements.txt:1, 2, 4, 6, 7 (5 hits)contrib/reproducibility/dataset_manager/dataset_utils.py:60, 104, 153, 272, 316, 393, 461 (7 hits)tests/round_trip/generate_sddl2_parse_test_data.py:116, 176 (2 hits)contrib/reproducibility/dataset_manager/dataset_manager.py:133.github/workflows/windows-ci.yml:65, 165 (4 hits).github/workflows/release-binaries.yml:68.github/workflows/deploy-docs.yml
CI/CD securitySupply chainGithub actions
.github/workflows/release-binaries.yml
CI/CD securitySupply chainGithub actions
benchmark/runner/local_compare.py:160
Subprocess shell true
contrib/reproducibility/dataset_manager/dataset_utils.py:452
Subprocess shell true
cli/commands/cmd_decompress.cpp:8contrib/lz-research/codecs/VarByte.cpp:77contrib/reproducibility/watermark/analysis.cpp:26cpp/include/openzl/cpp/Compressor.hpp:40cpp/include/openzl/cpp/CustomEncoder.hpp:38cpp/include/openzl/cpp/DCtx.hpp:45cpp/include/openzl/cpp/FunctionGraph.hpp:84cpp/src/openzl/cpp/experimental/trace/CompressTracer.hpp:19repo-level (14 hits)doc/mkdocs/mkdocstrings-zstd/src/mkdocstrings_handlers/zstd/rendering.py:45
doc/mkdocs/mkdocstrings-zstd/src/mkdocstrings_handlers/zstd/rendering.py:75
examples/py/parsing.py:76
contrib/reproducibility/dataset_manager/dataset_manager.py:38
examples/py/parsing.py:82
benchmark/runner/zstrong_gbenchmarks.py:49
benchmark/unitBench/scripts/sparse_num_bench.py:74
benchmark/unitBench/scripts/sparse_num_bench.py:70
benchmark/runner/phabricator_utils.py:72
benchmark/runner/phabricator_utils.py:88
benchmark/runner/quiet_cpu_utils.py:55
tools/compressor_serialization/to_cbor.py:19
examples/py/quick_start.py:185
benchmark/runner/zstrong_gbenchmarks.py:236
This page is publicly accessible at:
https://repobility.com/scan/3fc8ff8f-9c8b-4248-99e0-1154e8f1198b/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/3fc8ff8f-9c8b-4248-99e0-1154e8f1198b/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.