Scan timing: clone 12.06s · analysis 37.09s · 40.9 MB · GitHub API rate-limit (preflight)
https://github.com/tinygrad/tinygrad
· scanned 2026-06-04 21:59 UTC (16 hours, 45 minutes ago)
· 10 languages
1021 findings (255 legacy + 766 scanner) 11/13 scanners ran 49th percentile · Python · large (100-500K LoC) Scanner says 61 (higher by 13)
Last scanned 16 hours, 42 minutes ago · v2 · 639 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
82.0 | 0.20 | 16.40 |
documentation_score |
63.0 | 0.15 | 9.45 |
practices_score |
75.0 | 0.15 | 11.25 |
code_quality |
28.0 | 0.10 | 2.80 |
| Overall | 1.00 | 73.9 |
Showing 313 of 639 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
extra/thunder/tiny/visualize_tile.py:123
qualitylegacy
examples/qwq.py:114
qualitylegacy
examples/gpt2.py:254
qualitylegacy
extra/usbgpu/patch.py:16
qualitylegacy
extra/hevc/decode.py:53
qualitylegacy
extra/datasets/wikipedia_download.py:30
qualitylegacy
tinygrad/uop/upat.py:167
qualitylegacy
tinygrad/runtime/ops_cpu.py:59
qualitylegacy
examples/anthropic_challenge.py:147
qualitylegacy
extra/datasets/__init__.py:39
deserializationlegacy
examples/openpilot/load_pickle.py:10
deserializationlegacy
examples/openpilot/compile3.py:139
deserializationlegacy
examples/vgg7.py:93
qualitylegacy
extra/dsp/Dockerfile:25
dockerlegacy
extra/dsp/Dockerfile:5
dockerlegacy
extra/dsp/Dockerfile:5
dockerlegacy
extra/dsp/Dockerfile:2
supply-chaindockerpinned-dependencies
.github/workflows/benchmark_search.yml:17
supply-chaingithub-actionspinned-dependencies
.github/workflows/mlperf.yml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/python-publish.yml:17
supply-chaingithub-actionspinned-dependencies
.github/workflows/autogen.yml:31
supply-chaingithub-actionspinned-dependencies
.github/workflows/autogen.yml:70
supply-chaingithub-actionspinned-dependencies
.github/workflows/autogen.yml:81
supply-chaingithub-actionspinned-dependencies
.github/workflows/autogen.yml:101
supply-chaingithub-actionspinned-dependencies
.github/workflows/autogen.yml:112
supply-chaingithub-actionspinned-dependencies
.github/workflows/autogen.yml:140
supply-chaingithub-actionspinned-dependencies
.github/workflows/szdiff.yml:18
supply-chaingithub-actionspinned-dependencies
.github/workflows/szdiff.yml:49
supply-chaingithub-actionspinned-dependencies
.github/workflows/szdiff.yml:56
supply-chaingithub-actionspinned-dependencies
.github/workflows/szdiff.yml:60
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:35
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:94
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:196
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:232
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:330
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:392
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:504
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:561
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:607
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:654
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:677
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:751
supply-chaingithub-actionspinned-dependencies
.github/workflows/benchmark.yml:811
supply-chaingithub-actionspinned-dependencies
tinygrad/runtime/support/am/ip.py:190
owaspdebug_true
extra/hcq2/hcq2.py:301
dead-code
extra/hcq2/hcq2.py:335
dead-code
extra/hcq2/hcq2.py:312
dead-code
extra/hcq2/hcq2.py:325
dead-code
extra/usbgpu/legacy/patch_exp.py:45
dead-code
docs/abstractions4.py:131
dead-code
extra/datasets/wikipedia.py:155
dead-code
docs/abstractions4.py:77
dead-code
extra/datasets/openimages.py:105
dead-code
extra/hcq2/hcq2.py:354
dead-code
extra/models/llama.py:111
dead-code
extra/models/llama.py:109
dead-code
extra/models/llama.py:107
dead-code
extra/datasets/__init__.py:19
dead-code
extra/models/mask_rcnn.py:160
dead-code
extra/hevc/decode.py:12
dead-code
docs/abstractions4.py:24
dead-code
extra/datasets/imagenet.py:37
dead-code
extra/multitensor.py:21
dead-code
extra/hcq2/hcq2.py:243
dead-code
extra/hcq2/hcq2.py:240
dead-code
extra/models/mask_rcnn.py:56
dead-code
extra/hook_cuda.py:44
dead-code
extra/hcq2/hcq2.py:211
dead-code
extra/hcq2/hcq2.py:202
dead-code
extra/models/clip.py:446
dead-code
extra/usbgpu/legacy/nvme_speed.py:10
dead-code
extra/hcq2/hcq2.py:275
dead-code
extra/hcq2/hcq2.py:185
dead-code
extra/onnx_helpers.py:86
dead-code
Showing first 300 of 313. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/7d580067-aa8f-412a-bfac-13e7cd18ddf3/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/7d580067-aa8f-412a-bfac-13e7cd18ddf3/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.