Scan timing: clone 10.23s · analysis 39.56s · 31.8 MB · GitHub API rate-limit (preflight)
https://github.com/PaddlePaddle/FastDeploy
· scanned 2026-05-31 01:23 UTC (5 days, 6 hours ago)
· 10 languages
1206 findings (392 legacy + 814 scanner) 11/13 scanners ran 90th percentile · Python · large (100-500K LoC) Scanner says 69 (higher by 16)
Last scanned 5 days, 6 hours ago · v2 · 809 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
83.0 | 0.15 | 12.45 |
practices_score |
92.0 | 0.15 | 13.80 |
code_quality |
45.0 | 0.10 | 4.50 |
| Overall | 1.00 | 84.8 |
Showing 631 of 809 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
custom_ops/gpu_ops/sample_kernels/utils.cuh:110
qualitylegacy
custom_ops/gpu_ops/gelu_tanh.cu:58
qualitylegacy
custom_ops/gpu_ops/fused_cast_sigmoid_bias.cu:87
qualitylegacy
fastdeploy/cache_manager/multimodal_cache_manager.py:149
qualitylegacy
fastdeploy/cache_manager/transfer_factory/kvcache_transfer/include/util.h:188
qualitylegacy
fastdeploy/cache_manager/transfer_factory/kvcache_transfer/include/log.h:77
qualitylegacy
custom_ops/xpu_ops/src/ops/utility/debug.cc:37
qualitylegacy
fastdeploy/cache_manager/multimodal_cache_manager.py:149
qualitylegacy
fastdeploy/inter_communicator/ipc_signal.py:98
qualitylegacy
fastdeploy/rl/dynamic_weight_manager.py:486
qualitylegacy
tools/deep_gemm_pre-compile/pre_compile.py:152
qualitylegacy
fastdeploy/entrypoints/openai/utils.py:249
qualitylegacy
fastdeploy/engine/common_engine.py:1836
qualitylegacy
fastdeploy/input/multimodal_processor.py:522
qualitylegacy
fastdeploy/inter_communicator/fmq.py:60
qualitylegacy
fastdeploy/entrypoints/openai/tool_parsers/utils.py:107
qualitylegacy
fastdeploy/collect_env.py:716
qualitylegacy
fastdeploy/cache_manager/multimodal_cache_manager.py:149
qualitylegacy
fastdeploy/scheduler/config.py:242
secrets
fastdeploy/__init__.py:137
qualitylegacy
benchmarks/paddleocr_vl/benchmark.py:91
qualitylegacy
.claude/skills/benchmark-compare/scripts/extract_metrics.py:107
qualitylegacy
fastdeploy/logger/deterministic_logger.py:47
qualitylegacy
fastdeploy/golang_router/launch.py:96
qualitylegacy
fastdeploy/entrypoints/openai/multi_api_server.py:187
qualitylegacy
.claude/skills/nsys-capture/nsys_default_client.py:48
qualitylegacy
custom_ops/gpu_ops/fp8_gemm_with_cutlass/fp8_fp8_half_block_gemm.cu:115
qualitylegacy
custom_ops/gpu_ops/fp8_gemm_with_cutlass/fp8_fp8_fp8_dual_gemm.cu:110
qualitylegacy
custom_ops/gpu_ops/flash_mask_attn/flash_mask_attn.cu:83
qualitylegacy
fastdeploy/cache_manager/transfer_factory/kvcache_transfer/include/kvcache_rdma.h:121
qualitylegacy
fastdeploy/logger/deterministic_logger.py:299
qualitylegacy
fastdeploy/cache_manager/transfer_factory/mooncake_store/attention_store.py:146
qualitylegacy
fastdeploy/cache_manager/cache_metrics.py:103
qualitylegacy
scripts/extract_mtp_weight_from_safetensor.py:77
qualitylegacy
benchmarks/paddleocr_vl/benchmark.py:130
qualitylegacy
fastdeploy/config.py:342
qualitylegacy
fastdeploy/config.py:306
qualitylegacy
fastdeploy/config.py:305
qualitylegacy
fastdeploy/config.py:341
qualitylegacy
setup.py:146
qualitylegacy
fastdeploy/config.py:306
qualitylegacy
fastdeploy/config.py:305
qualitylegacy
fastdeploy/config.py:343
qualitylegacy
setup.py:226
qualitylegacy
setup.py:199
qualitylegacy
fastdeploy/config.py:306
qualitylegacy
fastdeploy/config.py:313
qualitylegacy
setup.py:182
qualitylegacy
fastdeploy/config.py:311
qualitylegacy
fastdeploy/config.py:304
qualitylegacy
setup.py:224
qualitylegacy
setup.py:223
qualitylegacy
setup.py:147
qualitylegacy
setup.py:213
qualitylegacy
setup.py:148
qualitylegacy
setup.py:145
qualitylegacy
fastdeploy/config.py:307
qualitylegacy
setup.py:144
qualitylegacy
fastdeploy/config.py:305
qualitylegacy
fastdeploy/config.py:339
qualitylegacy
fastdeploy/entrypoints/openai/api_server.py:729
qualitylegacy
fastdeploy/entrypoints/api_server.py:65
qualitylegacy
fastdeploy/entrypoints/openai/api_server.py:718
qualitylegacy
fastdeploy/entrypoints/openai/api_server.py:707
qualitylegacy
fastdeploy/router/router.py:535
qualitylegacy
fastdeploy/entrypoints/openai/api_server.py:490
qualitylegacy
fastdeploy/router/router.py:586
qualitylegacy
fastdeploy/entrypoints/openai/api_server.py:548
qualitylegacy
fastdeploy/router/router.py:557
qualitylegacy
fastdeploy/entrypoints/openai/api_server.py:589
qualitylegacy
fastdeploy/router/router.py:562
qualitylegacy
fastdeploy/entrypoints/openai/api_server.py:654
qualitylegacy
fastdeploy/entrypoints/openai/api_server.py:397
qualitylegacy
fastdeploy/entrypoints/openai/api_server.py:406
qualitylegacy
fastdeploy/entrypoints/openai/api_server.py:640
qualitylegacy
fastdeploy/entrypoints/openai/api_server.py:422
qualitylegacy
fastdeploy/entrypoints/openai/api_server.py:460
qualitylegacy
fastdeploy/entrypoints/openai/api_server.py:441
qualitylegacy
.github/workflows/ci_image_update.yml:28
dependencylegacy
.github/workflows/_clone_linux.yml:36
dependencylegacy
.github/workflows/publish_job.yml:140
dependencylegacy
.github/workflows/gh-pages.yml:18
dependencylegacy
.github/workflows/CheckPRTemplate.yml:26
dependencylegacy
.github/workflows/rerun.yml:18
dependencylegacy
.github/workflows/Codestyle-Check.yml:25
dependencylegacy
.github/workflows/remove-skip-ci-labels.yml:41
dependencylegacy
.github/workflows/remove-skip-ci-labels.yml:21
dependencylegacy
.github/workflows/_clone_linux.yml:54
dependencylegacy
.github/workflows/publish_job.yml:396
dependencylegacy
.github/workflows/publish_job.yml:360
dependencylegacy
.github/workflows/publish_job.yml:324
dependencylegacy
.github/workflows/publish_job.yml:264
dependencylegacy
.github/workflows/publish_job.yml:147
dependencylegacy
.github/workflows/gh-pages.yml:19
dependencylegacy
.github/workflows/CheckPRTemplate.yml:37
dependencylegacy
.github/workflows/Codestyle-Check.yml:36
dependencylegacy
.github/workflows/ci_metax.yml:27
dependencylegacy
.github/workflows/check-bypass.yml:37
dependencylegacy
dockerfiles/Dockerfile.gpu:1
dependencylegacy
tools/dockerfile/Dockerfile.ci:1
dependencylegacy
dockerfiles/Dockerfile.xpu:1
dependencylegacy
requirements.txt:49
dependencylegacy
.pre-commit-config.yaml:30
dependencylegacy
.pre-commit-config.yaml:53
dependencylegacy
.pre-commit-config.yaml:58
dependencylegacy
.pre-commit-config.yaml:14
dependencylegacy
.pre-commit-config.yaml:25
dependencylegacy
.pre-commit-config.yaml:21
dependencylegacy
fastdeploy/multimodal/image.py:116
path_traversallegacy
fastdeploy/logger/setup_logging.py:109
path_traversallegacy
benchmarks/paddleocr_vl/benchmark.py:130
path_traversallegacy
fastdeploy/demo/openai_demo.py:22
llm_injectionlegacy
fastdeploy/demo/openai_vl_demo.py:22
llm_injectionlegacy
tools/dockerfile/docker_build.sh:1
dockerlegacy
custom_ops/xpu_ops/setup_ops.py:59
qualitylegacy
custom_ops/setup_ops_cpu.py:56
qualitylegacy
scripts/generate_diff_coverage_xml.py:17
injectionlegacy
scripts/extract_mtp_weight_from_safetensor.py:66
injectionlegacy
fastdeploy/scheduler/storage.py:88
injectionlegacy
scripts/extract_mtp_weight_from_safetensor.py:77
path_traversallegacy
fastdeploy/logger/setup_logging.py:109
path_traversallegacy
benchmarks/paddleocr_vl/benchmark.py:130
path_traversallegacy
fastdeploy/entrypoints/openai/api_server.py:489
authowaspauth.fastapi.unauth_mutation
fastdeploy/router/router.py:585
authowaspauth.fastapi.unauth_mutation
fastdeploy/entrypoints/openai/api_server.py:727
authowaspauth.fastapi.unauth_mutation
fastdeploy/entrypoints/openai/api_server.py:546
authowaspauth.fastapi.unauth_mutation
fastdeploy/router/router.py:556
authowaspauth.fastapi.unauth_mutation
fastdeploy/entrypoints/openai/api_server.py:587
authowaspauth.fastapi.unauth_mutation
fastdeploy/router/router.py:561
authowaspauth.fastapi.unauth_mutation
fastdeploy/entrypoints/openai/api_server.py:653
authowaspauth.fastapi.unauth_mutation
fastdeploy/entrypoints/openai/api_server.py:639
authowaspauth.fastapi.unauth_mutation
fastdeploy/entrypoints/api_server.py:64
authowaspauth.fastapi.unauth_mutation
fastdeploy/entrypoints/openai/api_server.py:716
authowaspauth.fastapi.unauth_mutation
fastdeploy/entrypoints/openai/api_server.py:396
authowaspauth.fastapi.unauth_mutation
fastdeploy/entrypoints/openai/api_server.py:705
authowaspauth.fastapi.unauth_mutation
fastdeploy/entrypoints/openai/api_server.py:405
authowaspauth.fastapi.unauth_mutation
fastdeploy/entrypoints/openai/api_server.py:421
authowaspauth.fastapi.unauth_mutation
fastdeploy/entrypoints/openai/api_server.py:459
authowaspauth.fastapi.unauth_mutation
fastdeploy/entrypoints/openai/api_server.py:440
authowaspauth.fastapi.unauth_mutation
benchmarks/benchmark_serving.py:935
owaspeval_used
fastdeploy/config.py:397
owaspeval_used
fastdeploy/engine/common_engine.py:2712
owaspeval_used
fastdeploy/engine/engine.py:920
owaspeval_used
fastdeploy/entrypoints/cli/tokenizer.py:222
owaspeval_used
fastdeploy/model_executor/layers/moe/routing_indices_cache.py:569
owaspeval_used
fastdeploy/model_executor/model_loader/default_loader.py:89
owaspeval_used
fastdeploy/model_executor/model_loader/default_loader_v1.py:101
owaspeval_used
fastdeploy/model_executor/model_loader/dummy_loader.py:102
owaspeval_used
fastdeploy/model_executor/models/ernie4_5_vl/ernie4_5_vl_moe.py:620
owaspeval_used
fastdeploy/model_executor/models/paddleformers/base.py:467
owaspeval_used
fastdeploy/model_executor/models/qwen2_5_vl/qwen2_5_vl.py:180
owaspeval_used
fastdeploy/model_executor/models/qwen3_vl/qwen3_vl.py:184
owaspeval_used
fastdeploy/rl/rollout_model.py:108
owaspeval_used
fastdeploy/entrypoints/openai/api_server.py:686
authlegacy
fastdeploy/entrypoints/openai/api_server.py:727
authlegacy
fastdeploy/entrypoints/openai/api_server.py:716
authlegacy
fastdeploy/entrypoints/openai/api_server.py:705
authlegacy
fastdeploy/cache_manager/v1/transfer/ipc/connector.py:61
error_handlinglegacy
.claude/skills/benchmark-compare/scripts/extract_metrics.py:107
error_handlinglegacy
benchmarks/paddleocr_vl/benchmark.py:91
error_handlinglegacy
fastdeploy/rl/rollout_config.py:24
qualitylegacy
fastdeploy/model_executor/ops/triton_ops/triton_utils.py:588
qualitylegacy
fastdeploy/model_executor/ops/triton_ops/triton_utils_v2.py:85
qualitylegacy
fastdeploy/model_executor/models/qwen2_5_vl/dfnrope/configuration.py:67
qualitylegacy
fastdeploy/cache_manager/transfer_factory/rdma_cache_transfer.py:30
qualitylegacy
fastdeploy/cache_manager/cache_data.py:43
qualitylegacy
fastdeploy/model_executor/layers/sample/sampler.py:266
qualitylegacy
fastdeploy/model_executor/layers/sample/sampler.py:395
qualitylegacy
fastdeploy/cache_manager/v1/radix_tree.py:625
qualitylegacy
fastdeploy/utils.py:795
qualitylegacy
fastdeploy/scheduler/splitwise_scheduler.py:140
qualitylegacy
fastdeploy/model_executor/ops/triton_ops/triton_utils_v2.py:340
qualitylegacy
fastdeploy/model_executor/ops/triton_ops/triton_utils_v2.py:340
qualitylegacy
fastdeploy/model_executor/ops/triton_ops/triton_utils.py:828
qualitylegacy
fastdeploy/model_executor/ops/triton_ops/triton_utils.py:828
qualitylegacy
fastdeploy/model_executor/layers/utils.py:253
qualitylegacy
fastdeploy/model_executor/layers/sample/sampler.py:476
qualitylegacy
fastdeploy/model_executor/layers/sample/sampler.py:317
qualitylegacy
benchmarks/backend_request_func.py:1318
qualitylegacy
benchmarks/backend_request_func.py:1227
qualitylegacy
benchmarks/backend_request_func.py:1179
qualitylegacy
benchmarks/backend_request_func.py:1114
qualitylegacy
benchmarks/backend_request_func.py:1035
qualitylegacy
benchmarks/backend_request_func.py:633
qualitylegacy
benchmarks/backend_request_func.py:567
qualitylegacy
benchmarks/quick_benchmark.py:681
qualitylegacy
benchmarks/backend_request_func_swe.py:531
qualitylegacy
benchmarks/backend_request_func_swe.py:1422
qualitylegacy
benchmarks/backend_request_func_swe.py:275
qualitylegacy
benchmarks/backend_request_func_swe.py:1324
qualitylegacy
benchmarks/backend_request_func_swe.py:1233
qualitylegacy
benchmarks/backend_request_func_swe.py:1185
qualitylegacy
benchmarks/backend_request_func_swe.py:1120
qualitylegacy
benchmarks/backend_request_func_swe.py:1041
qualitylegacy
benchmarks/backend_request_func_swe.py:633
qualitylegacy
benchmarks/backend_request_func_swe.py:567
qualitylegacy
scripts/CheckPRTemplate.py:133
qualitylegacy
fastdeploy/collect_env.py:529
qualitylegacy
fastdeploy/utils.py:1113
qualitylegacy
fastdeploy/utils.py:1038
qualitylegacy
custom_ops/setup_ops.py:125
qualitylegacy
custom_ops/setup_ops_cpu.py:62
qualitylegacy
setup.py:122
qualitylegacy
requirements.txt:7
dependencylegacy
requirements.txt:29
dependencylegacy
requirements.txt:18
dependencylegacy
requirements.txt:15
dependencylegacy
requirements.txt:17
dependencylegacy
requirements.txt:12
dependencylegacy
requirements.txt:4
dependencylegacy
requirements.txt:21
dependencylegacy
requirements.txt:16
dependencylegacy
requirements.txt:27
dependencylegacy
requirements.txt:26
dependencylegacy
requirements.txt:2
dependencylegacy
requirements.txt:25
dependencylegacy
requirements.txt:19
dependencylegacy
requirements.txt:10
dependencylegacy
requirements.txt:14
dependencylegacy
requirements.txt:5
dependencylegacy
requirements.txt:1
dependencylegacy
requirements.txt:20
dependencylegacy
requirements.txt:9
dependencylegacy
requirements.txt:28
dependencylegacy
requirements.txt:23
dependencylegacy
requirements.txt:22
dependencylegacy
requirements.txt:3
dependencylegacy
requirements.txt:6
dependencylegacy
fastdeploy/cache_manager/multimodal_cache_manager.py:149
deserializationlegacy
custom_ops/xpu_ops/setup_ops.py:59
path_traversallegacy
custom_ops/setup_ops_cpu.py:56
path_traversallegacy
fastdeploy/entrypoints/cli/openai.py:198
llm_injectionlegacy
fastdeploy/demo/openai_demo.py:22
llm_injectionlegacy
fastdeploy/demo/openai_vl_demo.py:22
llm_injectionlegacy
.claude/skills/research-report/scripts/update_index.py:132
securitylegacy
fastdeploy/golang_router/pkg/logger/logger.go:40
qualitylegacy
fastdeploy/golang_router/launch.py:38
securitylegacy
custom_ops/xpu_ops/setup_ops.py:109
securitylegacy
fastdeploy/cache_manager/transfer_factory/mooncake_store/attention_store.py:276
qualitylegacy
fastdeploy/cache_manager/multimodal_cache_manager.py:101
qualitylegacy
benchmarks/paddleocr_vl/benchmark.py:38
qualitylegacy
fastdeploy/demo/tokenizer_client_demo.py:31
qualitylegacy
fastdeploy/cache_manager/cache_messager.py:12
qualitylegacy
fastdeploy/engine/common_engine.py:12
qualitylegacy
fastdeploy/engine/args_utils.py:12
qualitylegacy
fastdeploy/config.py:12
qualitylegacy
fastdeploy/cache_manager/cache_transfer_manager.py:12
qualitylegacy
examples/observability/docker-compose.yaml:13
dockerlegacy
examples/observability/docker-compose.yaml:2
dockerlegacy
.dockerignore
dockerlegacy
tools/dockerfile/Dockerfile.ci:1
dockerlegacy
dockerfiles/Dockerfile.xpu:1
dockerlegacy
dockerfiles/Dockerfile.gpu:1
dockerlegacy
.well-known/security.txt
qualitylegacy
.github/workflows/check-bypass.yml:37
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci_metax.yml:27
supply-chaingithub-actionspinned-dependencies
.github/workflows/_xpu_coverage_report.yml:300
supply-chaingithub-actionspinned-dependencies
.github/workflows/gh-pages.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/cherry-pick.yml
supply-chaingithub-actionsleast-privilege
custom_ops/setup_ops.py:60
owaspsubprocess_shell_true
fastdeploy/cache_manager/prefix_cache_manager.py:338
owaspsubprocess_shell_true
fastdeploy/collect_env.py:116
owaspsubprocess_shell_true
fastdeploy/engine/common_engine.py:2597
owaspsubprocess_shell_true
fastdeploy/engine/engine.py:725
owaspsubprocess_shell_true
fastdeploy/logger/deterministic_logger.py:193
owaspweak_hash
tools/dockerfile/docker_build.sh:1
dockerlegacy
custom_ops/gpu_ops/read_data_ipc.cu:59
qualitylegacy
custom_ops/gpu_ops/get_data_ptr_ipc.cu:45
qualitylegacy
custom_ops/gpu_ops/fused_cast_sigmoid_bias.cu:120
qualitylegacy
examples/observability/docker-compose.yaml:40
dockerlegacy
examples/observability/docker-compose.yaml:31
dockerlegacy
examples/observability/docker-compose.yaml:13
dockerlegacy
examples/observability/docker-compose.yaml:2
dockerlegacy
examples/observability/docker-compose.yaml:40
dockerlegacy
examples/observability/docker-compose.yaml:31
dockerlegacy
examples/observability/docker-compose.yaml:13
dockerlegacy
examples/observability/docker-compose.yaml:2
dockerlegacy
tools/dockerfile/Dockerfile.ci:23
dockerlegacy
tools/dockerfile/Dockerfile.ci:16
dockerlegacy
tools/dockerfile/Dockerfile.ci:2
dockerlegacy
dockerfiles/Dockerfile.xpu:11
dockerlegacy
dockerfiles/Dockerfile.xpu:35
dockerlegacy
dockerfiles/Dockerfile.xpu:15
dockerlegacy
tools/dockerfile/Dockerfile.ci:16
dockerlegacy
Showing first 300 of 631. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/ab654ff4-2d45-41c2-a338-f39e691f30b3/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/ab654ff4-2d45-41c2-a338-f39e691f30b3/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.