https://github.com/Azure/azureml-assets
· scanned 2026-06-05 17:39 UTC (4 days, 21 hours ago)
· 10 languages
1659 raw signals (555 security + 1104 graph) 11/13 scanners ran 79th percentile · Python · large (100-500K LoC) System graph score 59 (higher by 26)
Last scanned 4 days, 21 hours ago · v2 · 449 actionable findings from 2 signal sources. 658 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
79.0 | 0.15 | 11.85 |
code_quality |
68.0 | 0.10 | 6.80 |
| Overall | 1.00 | 84.6 |
Showing 345 of 449 actionable findings. 1107 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
assets/large_language_models/rag/components/src/embeddings/data_import_git.py:73
assets/model_monitoring/components/src/model_monitor_output_metrics/run.py:82
assets/aml-benchmark/scripts/custom_dataset_preprocessors/math_preprocessor.py:84
.github/workflows/batch-score-ci.yaml:51, 52, 53, 62, 63, 69, 70 (7 hits).github/workflows/batch-score-oss-ci.yaml:51, 52, 53, 62, 63, 69, 70 (7 hits).github/workflows/model-monitoring-ci.yml:55, 56, 57, 62, 63, 100, 101 (7 hits).github/workflows/assets-validation.yaml:66, 67, 68, 86 (4 hits)assets/batch_score/components/driver/src/batch_score/batch_pool/quota/estimators/dv3_estimator.py:45assets/batch_score/components/driver/src/batch_score/batch_pool/quota/estimators/embeddings_estimator.py:33assets/training/aoai/proxy_components/src/finetune_submit.py:181assets/training/finetune_acft_hf_nlp/src/model_converter/model_converter_utils.py:75
assets/batch_score/components/driver/src/batch_score/common/request_modification/modifiers/vesta_image_encoder.py:45
assets/aml-benchmark/components/src/aml_benchmark/dataset_preprocessor/dataset_preprocessor.py:161assets/aml-benchmark/components/src/aml_benchmark/utils/helper.py:227assets/training/finetune_acft_image/src/medimage_parse_finetune/medimageparse_finetune.py:244assets/training/model_management/environments/foundation-model-serve/context/foundation/model/serve/replica_manager.py:146
scripts/docs/generate_asset_documentation.py:72, 77, 82, 91, 92, 93, 108, 114, +13 more (25 hits)assets/training/model_management/environments/foundation-model-serve/context/foundation/model/serve/api_server.py:582
assets/training/model_management/environments/foundation-model-serve/context/foundation/model/serve/api_server.py:432
assets/training/model_management/environments/foundation-model-serve/context/foundation/model/serve/api_server.py:398
assets/training/model_management/environments/foundation-model-serve/context/foundation/model/serve/api_server.py:356
test/resources/release/environment-in-subdir/context/Dockerfile:1test/resources/release/src/context/Dockerfile:1test/resources/update/in-parent-dir/expected/environment/environment-in-parent-dir/src/context/Dockerfile:1test/resources/update/in-parent-dir/release/latest/environment/environment-in-parent-dir/src/context/Dockerfile:1test/resources/update/in-parent-dir/src/context/Dockerfile:1test/resources/update/in-place-no-release-dir/expected/context/Dockerfile:1test/resources/update/in-place-no-release-dir/main/context/Dockerfile:1test/resources/update/in-subdir/expected/environment/environment-in-subdir/context/Dockerfile:1assets/training/finetune_acft_hf_nlp/environments/acpt-draft/context/requirements.txt:5
assets/aml-benchmark/components/src/aml_benchmark/dataset_sampler/main.py:82assets/aml-benchmark/components/src/aml_benchmark/prompt_crafter/package/prompt_crafter.py:51assets/batch_score/components/driver/src/batch_score/common/request_modification/modifiers/vesta_image_encoder.py:45assets/aml-benchmark/components/src/aml_benchmark/batch_benchmark_score/batch_score/header_handlers/claude/claude_header_handler.py:28assets/aml-benchmark/components/src/aml_benchmark/utils/helper.py:56assets/batch_score/components/driver/dev/routing_simulator.py:48assets/designer/environments/designer-r/context/Dockerfile:12assets/training/automl/environments/ai-ml-automl-dnn-gpu/context/Dockerfile:3assets/training/automl/environments/ai-ml-automl-dnn-text-gpu-ptca/context/Dockerfile:3assets/training/automl/environments/ai-ml-automl-gpu/context/Dockerfile:3assets/training/finetune_acft_hf_nlp/environments/acpt-draft/context/Dockerfile:3assets/training/finetune_acft_hf_nlp/environments/acpt-grpo/context/Dockerfile:4assets/training/finetune_acft_hf_nlp/environments/acpt-rft/context/Dockerfile:2assets/training/finetune_acft_hf_nlp/environments/acpt/context/Dockerfile:4assets/training/model_management/environments/foundation-model-serve/context/Dockerfile:44
CI/CD securitycontainers
.github/workflows/batch-score-ci.yaml:33, 41 (2 hits).github/workflows/assets-validation.yaml:42.github/workflows/batch-score-oss-ci.yaml:33.github/workflows/check-changed-files.yaml:35.github/workflows/assets-release.yaml:48, 54, 61, 74, 81, 105, 182, 201, +4 more (12 hits).github/workflows/assets-docs.yaml:40, 46, 53, 60 (8 hits).github/workflows/batch-score-ci.yaml:45, 74, 94 (6 hits).github/workflows/model-monitoring-ci.yml:47, 67, 89, 94, 135, 158 (6 hits).github/workflows/assets-test.yaml:70, 119, 161, 184 (4 hits).github/workflows/assets-validation.yaml:56, 59 (4 hits).github/workflows/training-model-mgmt-unittests.yaml:32, 35 (4 hits).github/workflows/batch-score-oss-ci.yaml:45, 74, 94 (3 hits)assets/training/model_management/environments/foundation-model-serve/context/foundation/model/serve/api_server.py:582
Sync io in asyncPerformance
assets/training/model_management/environments/foundation-model-serve/context/foundation/model/serve/api_server.py:431
securityAuth fastapi unauth mutation
assets/training/model_management/environments/foundation-model-serve/context/foundation/model/serve/api_server.py:397
securityAuth fastapi unauth mutation
assets/training/model_management/environments/foundation-model-serve/context/foundation/model/serve/api_server.py:355
securityAuth fastapi unauth mutation
.github/workflows/assets-test.yaml:36, 41, 64, 114 (4 hits).github/workflows/promptflow-ci.yml:28, 33, 46, 72 (4 hits).github/workflows/environments-ci.yaml:28, 33, 62 (3 hits).github/workflows/model-monitoring-ci.yml:35, 43, 84 (3 hits).github/workflows/scripts-test.yaml:23, 28, 60 (3 hits).github/workflows/batch-score-ci.yaml:33, 41 (2 hits).github/workflows/batch-score-oss-ci.yaml:33, 41 (2 hits).github/workflows/model-monitoring-gsq-ci.yml:33, 41 (2 hits)assets/model_monitoring/components/src/model_data_collector_preprocessor/run.py:331
Eval used
assets/model_monitoring/components/src/model_data_collector_preprocessor/spark_run.py:56
Eval used
assets/training/finetune_acft_image/src/medimage_insight_adapter_finetune/training.py:298
Eval used
assets/training/finetune_acft_image/src/model_converters/medimage_embed_adapter_merge/medimageinsight_adapter_classification_mlflow_wrapper.py:130
Eval used
assets/training/finetune_acft_image/src/model_converters/medimage_embed_adapter_merge/medimageinsight_zero_shot_classification_mlflow_wrapper.py:191
Eval used
assets/training/model_evaluation/src/utils.py:1057
Eval used
assets/training/model_management/src/azureml/model/mgmt/processors/pyfunc/virchow/virchow_mlflow_model_wrapper.py:45
Eval used
assets/aml-benchmark/scripts/custom_inference_postprocessors/humaneval.py:280
Exec used
.github/workflows/check-changed-files.yaml:42
CI/CD securitySupply chainGithub actions
.github/workflows/check-new-assets.yaml:34
CI/CD securitySupply chainGithub actions
assets/aml-benchmark/components/src/aml_benchmark/utils/exceptions.py:79assets/training/model_evaluation/src/run_utils.py:193assets/training/model_evaluation/src/task_factory/tabular/classification.py:88assets/large_language_models/utils/ComponentVersionUpdator.py:65assets/training/model_evaluation/src/workspace_utils.py:234scripts/validation/copyright_validation.py:19assets/training/model_evaluation/src/image_dataset.py:152, 214, 286, 338 (4 hits)assets/aml-benchmark/components/src/aml_benchmark/utils/online_endpoint/online_endpoint_factory.py:18assets/large_language_models/rag/components/src/embeddings/data_import_acs.py:121assets/large_language_models/rag/components/src/validate_deployments.py:249assets/training/model_evaluation/src/compute_metrics.py:74assets/training/model_management/src/azureml/model/mgmt/processors/pyfunc/convertors.py:92assets/training/model_management/src/azureml/model/mgmt/processors/pyfunc/vision/detection_predict.py:164assets/aml-benchmark/requirements.txt:9, 10, 11, 12, 13, 14, 15, 16, +3 more (11 hits)assets/evaluators/tests/requirements.txt:3, 4, 8, 9, 10, 11, 12 (7 hits)assets/evaluators/builtin/tests/requirements.txt:1, 2, 3 (3 hits)assets/model_monitoring/components/tests/requirements.txt:10, 16 (2 hits)scripts/docs/requirements.txt:2scripts/release/requirements.txt:1assets/aml-benchmark/components/src/aml_benchmark/dataset_preprocessor/dataset_preprocessor.py:161assets/aml-benchmark/components/src/aml_benchmark/utils/helper.py:227assets/training/finetune_acft_image/src/medimage_parse_finetune/medimageparse_finetune.py:244assets/training/vision/jobs/object-detection-using-built-in-component/src/predict.py:33
assets/training/vision/jobs/object-detection-using-built-in-component/prepare_data.py:119
assets/aml-benchmark/scripts/custom_dataset_preprocessors/math_preprocessor.py:76assets/common/src/utils/run_utils.py:146assets/training/model_management/src/azureml/model/mgmt/utils/logging_utils.py:98assets/common/src/delete_endpoint.py:54, 105, 114 (3 hits)assets/common/src/utils/run_utils.py:23, 149 (2 hits)assets/evaluators/builtin/ifeval/evaluator/_instructions.py:389, 403 (2 hits)assets/evaluation_on_cloud/environments/evaluations-built-in/context/online_eval/evaluate.py:187scripts/azureml-assets/azureml/assets/config.py:623scripts/promptflow-ci/check_spec_yaml.py:65.dockerignore
CI/CD securitycontainers
assets/Langchain/environments/general-langchain-app-deployment/context/Dockerfile:2assets/data-labeling/environments/data-labeling-sam/context/Dockerfile:1assets/data-labeling/environments/data-labeling/context/Dockerfile:1assets/designer/environments/component/context/Dockerfile:1assets/designer/environments/designer-cv-transform/context/Dockerfile:1assets/designer/environments/designer-cv/context/Dockerfile:1assets/designer/environments/designer-io/context/Dockerfile:1assets/designer/environments/designer-pytorch-2.3-train/context/Dockerfile:1assets/data-labeling/environments/data-labeling-sam/context/Dockerfile:20assets/training/automl/environments/ai-ml-automl-dnn-text-gpu-ptca/context/Dockerfile:5assets/training/automl/environments/ai-ml-automl-dnn-text-gpu/context/Dockerfile:13assets/training/automl/environments/ai-ml-automl-dnn/context/Dockerfile:14assets/training/finetune_acft_hf_nlp/environments/acpt-grpo/context/Dockerfile:6assets/training/finetune_acft_hf_nlp/environments/acpt-rft/context/Dockerfile:3assets/training/finetune_acft_hf_nlp/environments/acpt/context/Dockerfile:6assets/training/finetune_acft_image/environments/acft_image_medimageparse_finetune/context/Dockerfile:5test/resources/config/env1-1.0.0/context/Dockerfile:1test/resources/config/env1-1.0.1/context/Dockerfile:1test/resources/config/env1-1/context/Dockerfile:1test/resources/config/env1-2/context/Dockerfile:1test/resources/config/env1-auto/context/Dockerfile:1test/resources/validate-copyright/good-validation/context/Dockerfile:1test/resources/validate-copyright/missing-copyright/context/Dockerfile:1test/resources/validate/correct-order/context/Dockerfile:1assets/system/context/Dockerfile:59
containersPinned dependencies
assets/system/context/Dockerfile:127
containersPinned dependencies
.github/workflows/codeql-analysis.yml:38, 49 (4 hits).github/workflows/assets-validation.yaml:70 (2 hits).github/workflows/batch-score-ci.yaml:102 (2 hits).github/workflows/training-model-mgmt-unittests.yaml:57 (2 hits).github/workflows/assets-test.yaml:193.github/workflows/batch-score-oss-ci.yaml:102.github/workflows/check-changed-files.yaml:42.github/workflows/check-new-assets.yaml:34.github/workflows/assets-docs.yaml.github/workflows/assets-release.yaml.github/workflows/assets-test.yaml.github/workflows/assets-validation.yaml.github/workflows/batch-score-ci.yaml.github/workflows/batch-score-oss-ci.yaml.github/workflows/close-stale-items.yml.github/workflows/environments-ci.yamlassets/aml-benchmark/components/src/aml_benchmark/dataset_preprocessor/dataset_preprocessor.py:165
Subprocess shell true
assets/aml-benchmark/components/src/aml_benchmark/inference_postprocessor/inference_postprocessor.py:518
Subprocess shell true
assets/aml-benchmark/components/src/aml_benchmark/utils/helper.py:229
Subprocess shell true
assets/common/src/utils/common_utils.py:30
Subprocess shell true
assets/model_monitoring/components/src/model_data_collector_preprocessor/mdc_preprocessor_helper.py:270
Subprocess shell true
assets/training/finetune_acft_image/src/medimage_parse_3d_finetune/medimageparse_3d_finetune.py:253
Subprocess shell true
assets/training/finetune_acft_image/src/medimage_parse_finetune/medimageparse_finetune.py:245
Subprocess shell true
assets/training/model_management/src/azureml/model/mgmt/utils/common_utils.py:64
Subprocess shell true
assets/training/general/environments/lightgbm-3.3/context/Dockerfile
Ports
assets/training/model_management/src/run_model_preprocess.py:183
assets/training/general/environments/tensorflow-2.16-cuda11/context/Dockerfile:145, 154, 208, 214, 230, 251, 266 (7 hits)assets/training/general/environments/tensorflow-2.16-cuda12/context/Dockerfile:54, 139, 204, 210, 223, 248 (6 hits)assets/training/model_management/environments/foundation-model-inference/context/Dockerfile:20, 21 (2 hits)assets/data-labeling/environments/data-labeling-sam/context/Dockerfile:21assets/training/automl/environments/ai-ml-automl-dnn-forecasting-gpu/context/Dockerfile:29assets/training/automl/environments/ai-ml-automl/context/Dockerfile:23assets/training/finetune_acft_hf_nlp/environments/data_import/context/Dockerfile:39assets/training/forecasting_demand/environments/automl-gpu/context/Dockerfile:15assets/responsibleai/environments/responsibleai-tabular/context/Dockerfile:23, 27, 35, 40, 45, 48, 51, 54, +6 more (14 hits)assets/training/automl/environments/ai-ml-automl/context/Dockerfile:60, 105, 111, 112, 113, 114 (6 hits)assets/training/finetune_acft_hf_nlp/environments/acpt-rft/context/Dockerfile:12, 13, 14, 15, 42, 56 (6 hits)assets/training/automl/environments/ai-ml-automl-dnn-text-gpu-ptca/context/Dockerfile:17, 21, 24, 49, 76 (5 hits)assets/training/finetune_acft_hf_nlp/environments/acpt-draft/context/Dockerfile:16, 17, 18, 25, 28 (5 hits)assets/training/finetune_acft_image/environments/acft_video_mmtracking/context/Dockerfile:25, 26, 27, 30, 34 (5 hits)assets/training/automl/environments/ai-ml-automl-gpu/context/Dockerfile:46, 51, 91, 147 (4 hits)assets/training/finetune_acft_hf_nlp/environments/acpt-grpo/context/Dockerfile:11, 12, 15, 32 (4 hits)assets/training/general/environments/tensorflow-2.16-cuda11/context/Dockerfile:145, 208, 214 (3 hits)assets/training/general/environments/tensorflow-2.16-cuda12/context/Dockerfile:139, 204, 210 (3 hits)assets/training/model_management/environments/foundation-model-inference/context/Dockerfile:20, 25 (2 hits)assets/aml-benchmark/scripts/custom_dataset_preprocessors/quac_textgen_babel.py:7, 34 (2 hits)assets/batch_score_oss/components/driver/src/batch_score_oss/common/auth/token_provider.py:3, 32 (2 hits)assets/aml-benchmark/components/src/aml_benchmark/benchmark_embedding_model/deployments/oss_deployment.py:67assets/aml-benchmark/components/src/aml_benchmark/utils/error_definitions.py:1assets/aml-benchmark/components/src/aml_benchmark/utils/online_endpoint/claude_online_endpoint.py:48assets/aml-benchmark/components/src/aml_benchmark/utils/online_endpoint/oss_online_endpoint.py:38assets/aml-benchmark/scripts/custom_dataset_preprocessors/math_preprocessor.py:2assets/aml-benchmark/scripts/custom_dataset_preprocessors/truthfulqa_hf.py:15assets/training/general/environments/acpt-pytorch-1.13-cuda11.7/context/Dockerfile:1
containersPinned dependencies
assets/training/vision/environments/automl-dnn-vision-gpu/context/Dockerfile:1
containersPinned dependencies
assets/training/automl/environments/ai-ml-automl-dnn-text-gpu-ptca/context/Dockerfile:1assets/training/automl/environments/ai-ml-automl-dnn-text-gpu/context/Dockerfile:1assets/training/finetune_acft_hf_nlp/environments/acpt-draft/context/Dockerfile:2assets/training/finetune_acft_hf_nlp/environments/acpt-grpo/context/Dockerfile:2assets/training/finetune_acft_hf_nlp/environments/acpt-rft/context/Dockerfile:1assets/training/finetune_acft_hf_nlp/environments/acpt/context/Dockerfile:2assets/training/finetune_acft_image/environments/acft_image_huggingface/context/Dockerfile:2assets/training/finetune_acft_image/environments/acft_image_medimageinsight_adapter_finetune/context/Dockerfile:1assets/training/automl/environments/ai-ml-automl-dnn-vision-gpu/context/Dockerfile:1
containersPinned dependencies
test/resources/validate/dockerfile-from-ce-image-comment/context/Dockerfile:2test/resources/validate/dockerfile-from-ce-image-windows/context/Dockerfile:1test/resources/validate/dockerfile-from-ce-image/context/Dockerfile:1assets/inference/environments/minimal-py311-inference/context/Dockerfile:1
containersPinned dependencies
assets/inference/environments/mlflow-py312-inference/context/Dockerfile:1
containersPinned dependencies
assets/inference/environments/minimal-py312-cuda12.4-inference/context/Dockerfile:1
containersPinned dependencies
assets/training/general/environments/tensorflow-2.16-cuda11/context/Dockerfile:3
containersPinned dependencies
assets/training/general/environments/tensorflow-2.16-cuda12/context/Dockerfile:3
containersPinned dependencies
test/resources/release/environment-in-subdir/context/Dockerfile:1test/resources/release/src/context/Dockerfile:1test/resources/update/in-parent-dir/expected/environment/environment-in-parent-dir/src/context/Dockerfile:1test/resources/update/in-parent-dir/release/latest/environment/environment-in-parent-dir/src/context/Dockerfile:1test/resources/update/in-parent-dir/src/context/Dockerfile:1test/resources/update/in-place-no-release-dir/expected/context/Dockerfile:1test/resources/update/in-place-no-release-dir/main/context/Dockerfile:1test/resources/update/in-place/expected/context/Dockerfile:1assets/data-labeling/environments/data-labeling-sam/context/Dockerfile:1assets/training/general/environments/sklearn-1.0/context/Dockerfile:1assets/training/general/environments/sklearn-1.1/context/Dockerfile:1assets/data-labeling/environments/data-labeling/context/Dockerfile:1assets/large_language_models/rag/environments/rag_embeddings/context/Dockerfile:1assets/pipelines/environments/mldesigner-minimal/context/Dockerfile:1assets/pipelines/environments/mldesigner/context/Dockerfile:1assets/training/automl/environments/ai-ml-automl-dnn-forecasting-gpu/context/Dockerfile:1assets/training/automl/environments/ai-ml-automl-dnn-gpu/context/Dockerfile:1assets/training/automl/environments/ai-ml-automl-gpu/context/Dockerfile:1assets/training/forecasting_demand/environments/automl-gpu/context/Dockerfile:1assets/training/finetune_acft_image/environments/acft_image_medimageparse_3d_finetune/context/Dockerfile:15
containersPinned dependencies
assets/training/finetune_acft_hf_nlp/environments/slime-pytorch-2.9-cuda12.8/context/Dockerfile:1
containersPinned dependencies
assets/training/model_management/environments/foundation-model-inference/context/Dockerfile:1
containersPinned dependencies
assets/training/model_management/environments/foundation-model-serve/context/Dockerfile:1
containersPinned dependencies
assets/designer/environments/component/context/Dockerfile:1assets/designer/environments/designer-cv-transform/context/Dockerfile:1assets/designer/environments/designer-cv/context/Dockerfile:1assets/designer/environments/designer-io/context/Dockerfile:1assets/designer/environments/designer-pytorch-2.3-train/context/Dockerfile:1assets/designer/environments/designer-pytorch-2.3/context/Dockerfile:1assets/designer/environments/designer-r/context/Dockerfile:1assets/designer/environments/designer-recommender/context/Dockerfile:1assets/Langchain/environments/general-langchain-app-deployment/context/Dockerfile:2
containersPinned dependencies
assets/training/model_management/environments/mlflow-model-inference/context/Dockerfile:1
containersPinned dependencies
assets/training/general/environments/tensorflow-2.16-cuda11/context/Dockerfile:12
containersPinned dependencies
assets/training/general/environments/tensorflow-2.16-cuda12/context/Dockerfile:12
containersPinned dependencies
assets/system/context/Dockerfile:19, 43, 76, 110 (4 hits)repo-level (8 hits)repo-level (3 hits)repo-level (8 hits)Showing first 300 of 345. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/c30c591d-720d-4fb4-b933-c9417526f87b/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/c30c591d-720d-4fb4-b933-c9417526f87b/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.