https://github.com/ggml-org/llama.cpp
· scanned 2026-06-05 05:22 UTC (2 hours, 29 minutes ago)
· 10 languages
925 findings (233 legacy + 692 scanner) 11/13 scanners ran Scanner says 72 (higher by 6)
Last scanned 2 hours, 29 minutes ago · v2 · 579 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
53.0 | 0.20 | 10.60 |
documentation_score |
77.0 | 0.15 | 11.55 |
practices_score |
94.0 | 0.15 | 14.10 |
code_quality |
45.0 | 0.10 | 4.50 |
| Overall | 1.00 | 78.5 |
Showing 486 of 579 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
ggml/src/ggml-hexagon/htp/worker-pool.c:93
qualitylegacy
ggml/src/ggml-hexagon/htp-opnode.h:137
qualitylegacy
gguf-py/gguf/quants.py:169
qualitylegacy
scripts/snapdragon/qdc/run_qdc_jobs.py:636
qualitylegacy
gguf-py/gguf/metadata.py:237
qualitylegacy
examples/pydantic_models_to_grammar.py:1021
qualitylegacy
.github/workflows/release.yml:53
dependencylegacy
scripts/apple/validate-ios.sh:699
secrets
scripts/apple/validate-macos.sh:696
secrets
scripts/apple/validate-tvos.sh:692
secrets
scripts/apple/validate-visionos.sh:690
secrets
conversion/kimi_linear.py:26
qualitylegacy
gguf-py/gguf/scripts/gguf_hash.py:31
qualitylegacy
examples/gguf-hash/deps/sha1/sha1.h:43
qualitylegacy
examples/gguf-hash/deps/sha1/sha1.c:282
qualitylegacy
ggml/src/ggml-cuda/mmf.cu:87
qualitylegacy
ggml/src/ggml-cuda/cumsum.cu:209
qualitylegacy
ggml/src/ggml-cuda/argsort.cu:41
qualitylegacy
app/llama.cpp:31
qualitylegacy
app/llama.cpp:29
qualitylegacy
conversion/internlm.py:35
qualitylegacy
conversion/arctic.py:31
qualitylegacy
ggml/src/ggml-webgpu/wgsl-shaders/embed_wgsl.py:15
qualitylegacy
examples/model-conversion/scripts/utils/semantic_check.py:46
qualitylegacy
conversion/wavtokenizer.py:29
qualitylegacy
convert_llama_ggml_to_gguf.py:234
qualitylegacy
convert_llama_ggml_to_gguf.py:238
qualitylegacy
convert_llama_ggml_to_gguf.py:235
qualitylegacy
convert_lora_to_gguf.py:460
qualitylegacy
convert_lora_to_gguf.py:440
qualitylegacy
convert_lora_to_gguf.py:422
qualitylegacy
conversion/wavtokenizer.py:34
qualitylegacy
conversion/wavtokenizer.py:33
qualitylegacy
convert_lora_to_gguf.py:418
qualitylegacy
convert_lora_to_gguf.py:417
qualitylegacy
conversion/wavtokenizer.py:33
qualitylegacy
convert_lora_to_gguf.py:455
qualitylegacy
convert_lora_to_gguf.py:185
qualitylegacy
convert_lora_to_gguf.py:163
qualitylegacy
convert_lora_to_gguf.py:166
qualitylegacy
convert_lora_to_gguf.py:66
qualitylegacy
convert_lora_to_gguf.py:169
qualitylegacy
convert_lora_to_gguf.py:141
qualitylegacy
convert_lora_to_gguf.py:128
qualitylegacy
convert_lora_to_gguf.py:191
qualitylegacy
convert_lora_to_gguf.py:182
qualitylegacy
convert_lora_to_gguf.py:188
qualitylegacy
convert_llama_ggml_to_gguf.py:185
qualitylegacy
convert_llama_ggml_to_gguf.py:181
qualitylegacy
.github/workflows/build-cuda-windows.yml:108
dependencylegacy
.github/workflows/ui-build.yml:14
dependencylegacy
.github/workflows/build-cmake-pkg.yml:10
dependencylegacy
.github/workflows/build-cuda-windows.yml:98
dependencylegacy
.github/workflows/build-cuda-windows.yml:37
dependencylegacy
.github/workflows/update-ops-docs.yml:23
dependencylegacy
.github/workflows/ai-issues.yml:18
dependencylegacy
.github/workflows/check-vendor.yml:26
dependencylegacy
.github/workflows/build-3rd-party.yml:36
dependencylegacy
.github/workflows/pre-tokenizer-hashes.yml:19
dependencylegacy
.github/workflows/build-rpc.yml:45
dependencylegacy
.github/workflows/build-openvino.yml:52
dependencylegacy
.github/workflows/build-android.yml:104
dependencylegacy
.github/workflows/build-android.yml:71
dependencylegacy
.github/workflows/build-android.yml:40
dependencylegacy
.github/workflows/build-msys.yml:35
dependencylegacy
.github/workflows/build-android.yml:120
dependencylegacy
.github/workflows/build-android.yml:46
dependencylegacy
.github/workflows/ui-build.yml:17
dependencylegacy
.github/workflows/update-ops-docs.yml:26
dependencylegacy
.github/workflows/check-vendor.yml:31
dependencylegacy
.github/workflows/pre-tokenizer-hashes.yml:22
dependencylegacy
.github/workflows/build-android.yml:90
dependencylegacy
.github/workflows/build-cuda-windows.yml:132
dependencylegacy
.github/workflows/build-cuda-windows.yml:40
dependencylegacy
.devops/llama-cli-cann.Dockerfile:33
dependencylegacy
.devops/llama-cli-cann.Dockerfile:5
dependencylegacy
.devops/intel.Dockerfile:44
dependencylegacy
.devops/intel.Dockerfile:7
dependencylegacy
.github/workflows/build-android.yml:64
dependencylegacy
.github/workflows/build-cuda-ubuntu.yml:109
dependencylegacy
.github/workflows/build-cuda-ubuntu.yml:41
dependencylegacy
.github/workflows/build-cuda-ubuntu.yml:77
dependencylegacy
.github/workflows/hip-quality-check.yml:38
dependencylegacy
.github/workflows/docker.yml:157
dependencylegacy
.pre-commit-config.yaml:5
dependencylegacy
.pre-commit-config.yaml:12
dependencylegacy
examples/llama.android/gradle/wrapper/gradle-wrapper.jar:1
dependencylegacy
tools/results/results.cpp:110
path_traversallegacy
scripts/compare-logprobs.py:116
path_traversallegacy
ggml/src/ggml-webgpu/wgsl-shaders/embed_wgsl.py:15
path_traversallegacy
ggml/src/ggml-webgpu/wgsl-shaders/embed_wgsl.py:15
path_traversallegacy
examples/model-conversion/requirements.txt
supply-chainpypidependency-confusion
tools/mtmd/requirements.txt
supply-chainpypidependency-confusion
conversion/kimi_linear.py:26
error_handlinglegacy
scripts/tool_bench.py:244
qualitylegacy
examples/model-conversion/scripts/utils/check-nmse.py:44
qualitylegacy
examples/model-conversion/scripts/utils/check-nmse.py:172
qualitylegacy
examples/model-conversion/scripts/utils/hf-create-collection.py:56
qualitylegacy
examples/model-conversion/scripts/utils/hf-upload-gguf-model.py:44
qualitylegacy
examples/model-conversion/scripts/utils/semantic_check.py:142
qualitylegacy
examples/model-conversion/scripts/utils/hf-add-model-to-collection.py:31
qualitylegacy
examples/model-conversion/scripts/utils/hf-add-model-to-collection.py:49
qualitylegacy
examples/model-conversion/scripts/embedding/run-original-model.py:127
qualitylegacy
examples/llama-eval/llama-server-simulator.py:295
qualitylegacy
examples/llama-eval/llama-eval.py:1235
qualitylegacy
examples/llama-eval/llama-eval.py:1137
qualitylegacy
examples/llama-eval/llama-eval.py:1097
qualitylegacy
examples/llama-eval/llama-eval.py:1055
qualitylegacy
gguf-py/gguf/scripts/gguf_editor_gui.py:1588
qualitylegacy
gguf-py/gguf/scripts/gguf_editor_gui.py:923
qualitylegacy
scripts/sync_vendor.py:38
qualitylegacy
conversion/mpt.py:18
qualitylegacy
examples/model-conversion/requirements.txt:6
dependencylegacy
tools/server/bench/speed-bench/requirements.txt:1
dependencylegacy
examples/model-conversion/requirements.txt:5
dependencylegacy
scripts/jinja/requirements.txt:2
dependencylegacy
tools/server/bench/requirements.txt:1
dependencylegacy
scripts/jinja/requirements.txt:1
dependencylegacy
tools/server/bench/speed-bench/requirements.txt:2
dependencylegacy
tools/server/bench/requirements.txt:2
dependencylegacy
examples/model-conversion/requirements.txt:7
dependencylegacy
examples/model-conversion/requirements.txt:2
dependencylegacy
examples/model-conversion/requirements.txt:3
dependencylegacy
tools/server/bench/speed-bench/requirements.txt:3
dependencylegacy
examples/model-conversion/requirements.txt:4
dependencylegacy
tools/mtmd/legacy-models/minicpmv-surgery.py:41
llm_injectionlegacy
tools/mtmd/legacy-models/minicpmv-surgery.py:41
llm_injectionlegacy
convert_hf_to_gguf_update.py:1
qualitylegacy
convert_hf_to_gguf_update.py:1
qualitylegacy
.github/workflows/build-cuda-windows.yml:40
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cuda-windows.yml:132
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-opencl.yml:47
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yml:209
supply-chaingithub-actionspinned-dependencies
.github/workflows/copilot-setup-steps.yml:32
supply-chaingithub-actionspinned-dependencies
.github/workflows/hip-quality-check.yml:51
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cuda-ubuntu.yml:56
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cuda-ubuntu.yml:91
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cuda-ubuntu.yml:123
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-vulkan.yml:56
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-vulkan.yml:111
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-apple.yml:49
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-apple.yml:85
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-apple.yml:120
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-apple.yml:169
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-apple.yml:203
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-apple.yml:242
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:105
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:190
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:276
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:442
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cpu.yml:64
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cpu.yml:148
supply-chaingithub-actionspinned-dependencies
.github/workflows/server.yml:83
supply-chaingithub-actionspinned-dependencies
.github/workflows/server.yml:143
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-webgpu.yml:47
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-webgpu.yml:88
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-webgpu.yml:141
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
tools/server/bench/bench.py:228
owaspsubprocess_shell_true
.github/workflows/server-sanitize.yml:7
owaspweak_hash
.github/workflows/server-self-hosted.yml:7
owaspweak_hash
.github/workflows/server.yml:7
owaspweak_hash
.github/workflows/ui-self-hosted.yml:11
owaspweak_hash
.github/workflows/ui.yml:7
owaspweak_hash
.github/workflows/build-cross.yml
securityports
.github/workflows/build-cross.yml
securityports
tools/mtmd/legacy-models/minicpmv-surgery.py:29
race_conditionlegacy
tools/mtmd/legacy-models/llava_surgery.py:30
race_conditionlegacy
tools/mtmd/legacy-models/glmedge-surgery.py:27
race_conditionlegacy
conversion/phi.py:83
qualitylegacy
conversion/phi.py:41
qualitylegacy
conversion/olmo.py:58
qualitylegacy
conversion/olmo.py:53
qualitylegacy
conversion/olmo.py:50
qualitylegacy
conversion/mimo.py:147
qualitylegacy
conversion/mimo.py:138
qualitylegacy
conversion/mimo.py:136
qualitylegacy
conversion/mellum.py:30
qualitylegacy
conversion/mellum.py:25
qualitylegacy
conversion/mellum.py:22
qualitylegacy
conversion/llama.py:139
qualitylegacy
conversion/llama.py:130
qualitylegacy
conversion/llama.py:110
qualitylegacy
conversion/llada.py:95
qualitylegacy
conversion/llada.py:90
qualitylegacy
conversion/llada.py:11
qualitylegacy
conversion/kimi_linear.py:13
qualitylegacy
conversion/hunyuan.py:84
qualitylegacy
conversion/hunyuan.py:82
qualitylegacy
conversion/hunyuan.py:29
qualitylegacy
conversion/grovemoe.py:48
qualitylegacy
conversion/grovemoe.py:43
qualitylegacy
conversion/glm.py:124
qualitylegacy
conversion/glm.py:122
qualitylegacy
conversion/exaone.py:136
qualitylegacy
conversion/exaone.py:24
qualitylegacy
conversion/ernie.py:92
qualitylegacy
conversion/deepseek.py:120
qualitylegacy
conversion/bert.py:112
qualitylegacy
ggml/src/ggml-hexagon/htp/hvx-copy.h:1
qualitylegacy
.github/workflows/build-msys.yml:35
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-android.yml:40
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-android.yml:46
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-android.yml:71
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-android.yml:90
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-android.yml:104
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-android.yml:120
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-openvino.yml:52
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-rpc.yml:45
supply-chaingithub-actionspinned-dependencies
.github/workflows/pre-tokenizer-hashes.yml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/pre-tokenizer-hashes.yml:22
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-3rd-party.yml:36
supply-chaingithub-actionspinned-dependencies
.github/workflows/check-vendor.yml:26
supply-chaingithub-actionspinned-dependencies
.github/workflows/check-vendor.yml:31
supply-chaingithub-actionspinned-dependencies
.github/workflows/ai-issues.yml:18
supply-chaingithub-actionspinned-dependencies
.github/workflows/update-ops-docs.yml:23
supply-chaingithub-actionspinned-dependencies
.github/workflows/update-ops-docs.yml:26
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cuda-windows.yml:37
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cuda-windows.yml:98
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cuda-windows.yml:108
supply-chaingithub-actionspinned-dependencies
.github/workflows/ui-build.yml:14
supply-chaingithub-actionspinned-dependencies
.github/workflows/ui-build.yml:17
supply-chaingithub-actionspinned-dependencies
.github/workflows/ui-build.yml:39
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cache.yml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cache.yml:27
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cache.yml:77
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cache.yml:80
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cache.yml:104
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-cache.yml:107
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-opencl.yml:44
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-ibm.yml:44
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-ibm.yml:103
supply-chaingithub-actionspinned-dependencies
Showing first 300 of 486. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/66068b6a-6304-4731-a390-59c7a48d3b50/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/66068b6a-6304-4731-a390-59c7a48d3b50/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.