https://github.com/vllm-project/vllm
· scanned 2026-05-16 13:37 UTC (3 weeks, 3 days ago)
· 10 languages
1310 raw signals (345 security + 965 graph) 8/10 scanners ran 6th percentile · Python · huge (>500K LoC) System graph score 82 (lower by 23)
Last scanned 3 weeks, 5 days ago · v1 · 45 actionable findings from 1 signal source. 187 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
0.0 | 0.25 | 0.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
86.0 | 0.15 | 12.90 |
practices_score |
65.0 | 0.15 | 9.75 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 58.6 |
agent: 3.2 ·
docker: 86.6 ·
threat: 75.1
Showing 35 of 45 actionable findings. 232 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
docker/Dockerfile.rocm:89, 549 (2 hits)docker/Dockerfile.rocm_base:104benchmarks/multi_turn/benchmark_serving_multi_turn.py:1532benchmarks/multi_turn/convert_sharegpt_to_openai.py:140vllm/distributed/kv_transfer/kv_connector/v1/example_connector.py:433.buildkite/scripts/cleanup-nightly-builds.sh:39
.buildkite/scripts/upload-release-wheels-pypi.sh:40
benchmarks/kernels/graph_machete_bench.py:25
setup.py:738
docker/Dockerfile:291docker/Dockerfile.nightly_torch:125docker/Dockerfile.rocm:25docker/Dockerfile.rocm_base:23docker/Dockerfile:148docker/Dockerfile.cpu:31docker/Dockerfile.ppc64le:57docker/Dockerfile.s390x:76docker/Dockerfile.xpu:58setup.py:464vllm/compilation/wrapper.py:245vllm/env_override.py:578vllm/platforms/cpu.py:57
vllm/utils/cpu_resource_utils.py:167
benchmarks/kernels/graph_machete_bench.py:26vllm/compilation/caching.py:129vllm/distributed/parallel_state.py:721vllm/entrypoints/openai/cli_args.py:265
vllm/entrypoints/api_server.py:173
examples/tool_calling/openai_responses_client_with_mcp_tools.py:30
examples/deployment/chart-helm/values.yaml:2
examples/observability/prometheus_grafana/docker-compose.yaml:4, 13 (2 hits)docker/Dockerfile.rocm:65
CI/CD securitycontainers
docker/Dockerfile.rocm_base:70
CI/CD securitycontainers
docker/Dockerfile:904docker/Dockerfile.cpu:240docker/Dockerfile.nightly_torch:257docker/Dockerfile.ppc64le:278docker/Dockerfile.rocm:567docker/Dockerfile.rocm_base:313docker/Dockerfile.tpu:4docker/Dockerfile.xpu:115docker/Dockerfile:436docker/Dockerfile.cpu:115docker/Dockerfile.nightly_torch:105docker/Dockerfile.ppc64le:335docker/Dockerfile.s390x:228docker/Dockerfile.tpu:14docker/Dockerfile.xpu:101docker/Dockerfile.nightly_torch:109
CI/CD securitycontainers
docker/Dockerfile:778
CI/CD securitycontainers
vllm/model_executor/models/hyperclovax_vision_v2.py:1vllm/model_executor/models/mimo_v2.py:1vllm/v1/executor/ray_executor_v2.py:1docs/getting_started/installation/cpu.s390x.inc.md:40
.dockerignore
CI/CD securitycontainers
examples/observability/prometheus_grafana/docker-compose.yaml:4, 13 (2 hits)examples/observability/prometheus_grafana/docker-compose.yaml:4, 13 (2 hits)docker/Dockerfile.rocm_base:46, 62, 109, 173 (4 hits)docker/Dockerfile.nightly_torch:23, 47, 173 (3 hits)docker/Dockerfile.rocm:33, 430 (2 hits)docker/Dockerfile:765docker/Dockerfile.tpu:8docker/Dockerfile.xpu:125docker/Dockerfile.rocm:37, 118, 161, 241, 327, 365, 393, 397, +7 more (15 hits)docker/Dockerfile:201, 257, 418, 512, 609, 631, 643, 675, +6 more (14 hits)docker/Dockerfile.nightly_torch:38, 71, 79, 82, 109, 188, 204, 208, +5 more (13 hits)docker/Dockerfile.rocm_base:61, 110, 148, 176, 178, 189, 199, 221, +5 more (13 hits)docker/Dockerfile.cpu:61, 112, 150, 165, 175, 187, 199, 213, +1 more (9 hits)docker/Dockerfile.ppc64le:57, 86, 132, 164, 228, 238, 302, 324, +1 more (9 hits)docker/Dockerfile.s390x:36, 44, 97, 110, 129, 189, 201, 235, +1 more (9 hits)docker/Dockerfile.xpu:85, 109, 118, 159, 174 (5 hits)docker/Dockerfile.rocm_base:46, 109, 173 (3 hits)docker/Dockerfile.nightly_torch:23, 173 (2 hits)docker/Dockerfile.xpu:8, 125 (2 hits)docker/Dockerfile:765docker/Dockerfile.cpu:31docker/Dockerfile.rocm:33vllm/model_executor/models/deepseek_v2.py:1
vllm/model_executor/models/hunyuan_v1.py:1
csrc/cpu/cpu_attn_vxe.hpp:62, 190, 233 (3 hits)csrc/cpu/cpu_types_x86.hpp:32, 651, 652 (3 hits)csrc/cpu/cpu_attn_vec.hpp:151, 189 (2 hits)csrc/cpu/cpu_attn_vec16.hpp:5, 117 (2 hits)csrc/cpu/cpu_attn_vsx.hpp:90, 174 (2 hits)csrc/cpu/cpu_types_vxe.hpp:7, 528 (2 hits)csrc/cpu/sgl-kernels/moe_fp8.cpp:1, 17 (2 hits)vllm/model_executor/models/mimo_v2.py:27, 30 (2 hits)vllm/model_executor/models/deepseek_v2.py:1vllm/model_executor/models/hunyuan_v1.py:1vllm/model_executor/models/hy_v3.py:1vllm/renderers/deepseek_v32.py:1vllm/tokenizers/deepseek_v32.py:1vllm/transformers_utils/configs/deepseek_v4.py:1vllm/transformers_utils/configs/hy_v3.py:1
This page is publicly accessible at:
https://repobility.com/scan/cea585c0-944b-4614-9116-8abca2930bfe/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/cea585c0-944b-4614-9116-8abca2930bfe/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.