https://github.com/linkedin/Liger-Kernel
· scanned 2026-05-15 18:26 UTC (2 weeks, 6 days ago)
· 10 languages
267 findings (124 legacy + 143 scanner) 79th percentile · Python · medium (20-100K LoC) Scanner says 89 (lower by 10)
Last scanned 2 weeks, 6 days ago · v1 · 117 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
86.0 | 0.25 | 21.50 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
66.0 | 0.15 | 9.90 |
practices_score |
65.0 | 0.15 | 9.75 |
code_quality |
50.0 | 0.10 | 5.00 |
| Overall | 1.00 | 78.9 |
Showing 31 of 117 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/liger_kernel/transformers/model/qwen2_5_vl.py:95
path_traversallegacy
src/liger_kernel/transformers/model/qwen2_vl.py:92
path_traversallegacy
src/liger_kernel/transformers/model/llava.py:63
path_traversallegacy
src/liger_kernel/ops/backends/_ascend/ub_manager.py:172
error_handlinglegacy
bare-except-pass
· CWE-755
src/liger_kernel/ops/backends/_ascend/ub_manager.py:172
error_handlinglegacy
dev/modal/benchmarks.py:22
injectionlegacy
src/liger_kernel/chunked_loss/grpo_loss.py:10
cryptolegacy
http-not-https
· CWE-319
· A02:2021
examples/medusa/train.py:9
cryptolegacy
http-not-https
· CWE-319
· A02:2021
src/liger_kernel/ops/backends/_ascend/ops/rms_norm.py:4
qualitylegacy
src/liger_kernel/ops/backends/_ascend/ops/poly_norm.py:352
qualitylegacy
src/liger_kernel/ops/backends/_ascend/ops/layer_norm.py:285
qualitylegacy
src/liger_kernel/ops/backends/_ascend/ops/grpo_loss.py:875
qualitylegacy
src/liger_kernel/ops/backends/_ascend/ops/fused_linear_cross_entropy.py:207
qualitylegacy
src/liger_kernel/ops/backends/_ascend/ops/attn_res.py:1
qualitylegacy
src/liger_kernel/chunked_loss/simpo_loss.py:72
qualitylegacy
src/liger_kernel/chunked_loss/simpo_loss.py:35
qualitylegacy
src/liger_kernel/chunked_loss/orpo_loss.py:63
qualitylegacy
src/liger_kernel/chunked_loss/jsd_loss.py:43
qualitylegacy
src/liger_kernel/chunked_loss/grpo_loss.py:193
qualitylegacy
src/liger_kernel/chunked_loss/fused_linear_unpaired_preference.py:6
qualitylegacy
src/liger_kernel/transformers/model/internvl.py:70
logginglegacy
print-pii
· CWE-532
· A09:2021
benchmark/scripts/benchmark_grpo_loss.py:203
logginglegacy
print-pii
· CWE-532
· A09:2021
examples/huggingface/launch_on_modal.py:39
logginglegacy
print-pii
· CWE-532
· A09:2021
examples/medusa/train.py:308
logginglegacy
print-pii
· CWE-532
· A09:2021
examples/medusa/train.py:307
logginglegacy
print-pii
· CWE-532
· A09:2021
benchmark/scripts/utils.py:260
qualitylegacy
mutable-default-arg
· CWE-1023
examples/huggingface/launch_on_modal.py:11
supply_chainlegacy
npm-install-no-lockfile
· CWE-1357
· A06:2021
src/liger_kernel/ops/cross_entropy.py:287
qualitylegacy
todo-bomb
src/liger_kernel/ops/cross_entropy.py:236
qualitylegacy
todo-bomb
src/liger_kernel/transformers/model/hunyuan_v1.py:1
qualitylegacy
src/liger_kernel/transformers/model/hunyuan_v1.py:1
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/fedca033-f0ab-4858-8e75-ec394950c9b6/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/fedca033-f0ab-4858-8e75-ec394950c9b6/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.