https://github.com/sgl-project/sglang
· scanned 2026-05-15 07:29 UTC (3 weeks ago)
· 10 languages
1626 findings (103 legacy + 1523 scanner) 0th percentile · Python · huge (>500K LoC)
Last scanned 3 weeks ago · v1 · 94 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
22.9 | 0.25 | 5.72 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
66.0 | 0.15 | 9.90 |
practices_score |
65.0 | 0.15 | 9.75 |
code_quality |
46.9 | 0.10 | 4.69 |
| Overall | 1.00 | 56.1 |
agent: 3.2 ·
authz: 1.2 ·
docker: 50.6 ·
threat: 45.4 ·
journey: 2.5
Showing 14 of 94 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
docs/deploy.py:19
injectionlegacy
scripts/playground/reference_hf.py:80
path_traversallegacy
docs_new/scripts/update_lmsys_sglang_blogs.py:64
path_traversallegacy
scripts/export_deepseek_nextn.py:38
path_traversallegacy
benchmark/asr/bench_sglang.py:262
llm_injectionlegacy
benchmark/llava_bench/download_images.py:18
injectionlegacy
scripts/code_sync/copy_from_oss.py:66
injectionlegacy
benchmark/mmlu/bench_sglang.py:66
path_traversallegacy
scripts/ci/slurm/analyze_logs_with_modal.py:83
path_traversallegacy
sgl-kernel/analyze_whl_kernel_sizes.py:14
path_traversallegacy
benchmark/asr/bench_sglang.py:262
llm_injectionlegacy
docs/performance_dashboard/app.js:1037
authlegacy
docs/performance_dashboard/app.js:952
authlegacy
This page is publicly accessible at:
https://repobility.com/scan/fd17d536-6c38-4682-a122-18cea8fe9f8b/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/fd17d536-6c38-4682-a122-18cea8fe9f8b/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.