https://github.com/sgl-project/sglang
· scanned 2026-05-15 07:29 UTC (3 weeks ago)
· 10 languages
1626 findings (103 legacy + 1523 scanner) 0th percentile · Python · huge (>500K LoC)
Last scanned 3 weeks ago · v1 · 94 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
22.9 | 0.25 | 5.72 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
66.0 | 0.15 | 9.90 |
practices_score |
65.0 | 0.15 | 9.75 |
code_quality |
46.9 | 0.10 | 4.69 |
| Overall | 1.00 | 56.1 |
agent: 3.2 ·
authz: 1.2 ·
docker: 50.6 ·
threat: 45.4 ·
journey: 2.5
Showing 79 of 94 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
docker/compose.yaml:1
dockerlegacy
docs/deploy.py:19
injectionlegacy
scripts/playground/reference_hf.py:80
path_traversallegacy
docs_new/scripts/update_lmsys_sglang_blogs.py:64
path_traversallegacy
scripts/export_deepseek_nextn.py:38
path_traversallegacy
benchmark/asr/bench_sglang.py:262
llm_injectionlegacy
docker/compose.yaml:1
dockerlegacy
examples/monitoring/docker-compose.yaml:12
dockerlegacy
examples/monitoring/docker-compose.yaml:2
dockerlegacy
docker/compose.yaml:1
dockerlegacy
docker/Dockerfile:418
dockerlegacy
docker/Dockerfile:187
dockerlegacy
.devcontainer/Dockerfile:33
dockerlegacy
.devcontainer/Dockerfile:30
dockerlegacy
scripts/ci/utils/diffusion/generate_diffusion_dashboard.py:104
error_handlinglegacy
scripts/ci/utils/publish_traces.py:272
error_handlinglegacy
scripts/ci/cuda/warmup_server.py:230
error_handlinglegacy
benchmark/llava_bench/download_images.py:18
injectionlegacy
scripts/code_sync/copy_from_oss.py:66
injectionlegacy
benchmark/mmlu/bench_sglang.py:66
path_traversallegacy
scripts/ci/slurm/analyze_logs_with_modal.py:83
path_traversallegacy
sgl-kernel/analyze_whl_kernel_sizes.py:14
path_traversallegacy
benchmark/asr/bench_sglang.py:262
llm_injectionlegacy
docs/performance_dashboard/app.js:1037
authlegacy
docs/performance_dashboard/app.js:952
authlegacy
examples/monitoring/docker-compose.yaml:12
dockerlegacy
examples/monitoring/docker-compose.yaml:2
dockerlegacy
docker/compose.yaml:1
dockerlegacy
examples/frontend_language/usage/triton/Dockerfile:1
dockerlegacy
docker/Dockerfile:696
dockerlegacy
sgl-kernel/Dockerfile:94
dockerlegacy
docker/Dockerfile:603
dockerlegacy
docs_new/src/snippets/autoregressive/deepseek-v32-deployment.jsx:111
qualitylegacy
docs_new/src/snippets/autoregressive/deepseek-v32-deployment.jsx:76
qualitylegacy
docs_new/src/snippets/autoregressive/deepseek-v31-deployment.jsx:47
qualitylegacy
docs_new/src/snippets/autoregressive/deepseek-v31-deployment.jsx:35
qualitylegacy
docs_new/src/snippets/autoregressive/deepseek-v3-deployment.jsx:48
qualitylegacy
docs_new/src/snippets/autoregressive/deepseek-r1-basic-deployment.jsx:133
qualitylegacy
docs_new/src/snippets/autoregressive/deepseek-r1-basic-deployment.jsx:123
qualitylegacy
docs_new/src/snippets/autoregressive/deepseek-r1-advanced-deployment.jsx:553
qualitylegacy
docs_new/src/snippets/autoregressive/deepseek-ocr-v2-deployment.jsx:52
qualitylegacy
python/sglang/srt/models/hunyuan_v3.py:1
qualitylegacy
python/sglang/srt/models/deepseek_v4.py:1
qualitylegacy
python/sglang/srt/models/deepseek_v2.py:1
qualitylegacy
python/sglang/srt/layers/attention/dsv4/compressor_v2.py:1
qualitylegacy
python/sglang/srt/distributed/device_communicators/custom_all_reduce_v2.py:1
qualitylegacy
python/sglang/jit_kernel/flash_attention_v4.py:1
qualitylegacy
python/sglang/jit_kernel/flash_attention_v3.py:1
qualitylegacy
docs_new/docs/hardware-platforms/cpu_server.mdx:123
dependencylegacy
docs/platforms/cpu_server.md:71
dependencylegacy
3rdparty/amd/wheel/README.md:82
dependencylegacy
.dockerignore
dockerlegacy
sgl-model-gateway/bindings/golang/internal/grpc/client_grpc.go:539
error_handlinglegacy
docker/Dockerfile:777
dockerlegacy
docker/Dockerfile:587
dockerlegacy
.devcontainer/Dockerfile:11
dockerlegacy
sgl-kernel/Dockerfile:79
dockerlegacy
examples/frontend_language/usage/triton/Dockerfile:8
dockerlegacy
docker/Dockerfile:656
dockerlegacy
docker/Dockerfile:629
dockerlegacy
docker/Dockerfile:586
dockerlegacy
docker/Dockerfile:552
dockerlegacy
docker/Dockerfile:527
dockerlegacy
docker/Dockerfile:518
dockerlegacy
docker/Dockerfile:456
dockerlegacy
docker/Dockerfile:418
dockerlegacy
docker/Dockerfile:335
dockerlegacy
docker/Dockerfile:226
dockerlegacy
docker/Dockerfile:192
dockerlegacy
docker/Dockerfile:45
dockerlegacy
python/sglang/jit_kernel/flash_attention_v3.py:1
qualitylegacy
python/sglang/srt/layers/attention/dsv4/compressor_v2.py:1
qualitylegacy
python/sglang/jit_kernel/deepseek_v4.py:1
qualitylegacy
python/sglang/srt/mem_cache/cpp_radix_tree/tree_v2.h:1
qualitylegacy
python/sglang/srt/mem_cache/cpp_radix_tree/tree_v2.cpp:1
qualitylegacy
python/sglang/srt/configs/deepseek_v4.py:1
qualitylegacy
python/sglang/jit_kernel/fused_metadata_copy.py:1
qualitylegacy
python/sglang/jit_kernel/deepseek_v4.py:1
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/fd17d536-6c38-4682-a122-18cea8fe9f8b/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/fd17d536-6c38-4682-a122-18cea8fe9f8b/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.