Cloud-native high-performance edge/middle/service proxy
This report presents the forensic synthetic code analysis of envoyproxy/envoy, a C++ project with 28,675 GitHub stars. SynthScan v2.0 examined 583,412 lines of code across 4738 source files, recording 1725 pattern matches distributed across 20 syntactic categories. The overall adjusted score of 3.5 places this repository in the Likely human-written band.
The scanner applied 160+ deterministic lexical heuristics, multi-line block detectors, abstract syntax tree depth profilers, and a cross-file Jaccard similarity matrix to construct a statistically normalised synthetic code estimate. All matches are individually weighted by severity coefficient and contextual multiplier before summation, and the resulting headline score is temporally discounted to account for the repository's development history relative to the commercial emergence of large language model coding tooling (November 2022 onward).
This chart maps the temporal evolution of the adjusted synthetic code score across successive scan runs. An upward trajectory indicates ongoing incorporation of AI-generated code or expanding LLM-assisted scaffolding; a stable or declining trajectory may reflect active human refactoring, code removal, or the adoption of stricter authorship policies. The dashed secondary line (right axis) independently tracks total raw pattern hit count, which can diverge from the normalised score when codebase size changes significantly between scans.
Classifies detected patterns by their diagnostic confidence and structural impact. CRITICAL patterns (coefficient 10) represent definitive synthetic signatures — hallucinated imports, explicit LLM attribution metadata — virtually never produced by human authors. HIGH (5) indicates strong structural tells such as cross-file repetition or cross-linguistic idioms. MEDIUM (2) covers recognisable conversational padding and AI-specific vocabulary. LOW (1) captures subtle indicators like tautological comments and generic boilerplate that require density to carry independent signal.
This horizontal bar chart decomposes the repository's raw synthetic code score by top-level directory, allowing you to pinpoint precisely which modules or components carry the highest AI authorship density. Directories with disproportionately high scores relative to their size warrant targeted manual review: concentrated AI signatures often trace back to mass-generated configuration layers, auto-ported test suites, LLM-scaffolded boilerplate classes, or entire subsystems authored under heavy copilot assistance. Use this view to prioritise your human code-review effort.
The scanner identified 1725 distinct pattern matches across 20 syntactic categories. Each entry below represents a discrete location in the source code where the engine recorded a statistically significant AI authorship indicator. Expand any category row to inspect the individual file paths, line numbers, code snippets, and the lexical context (CODE, COMMENT, or STRING) in which each match was detected.
Reading the findings table: The Severity column indicates the diagnostic confidence level (CRITICAL / HIGH / MEDIUM / LOW). The Context column identifies whether the match occurred inside executable code, an inline comment, or a string literal — comment-context matches receive a ×1.5 weight because LLMs systematically over-annotate. The ⚡ bolt icon marks clustered matches: three or more patterns within a 10-line window, each receiving an additional ×1.5 density multiplier as dense clusters constitute far stronger evidence of synthetic authorship than isolated hits.
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | rustfmt.toml | 1 | # This config is copied from https://github.com/bitdriftlabs/shared-core/blob/4114708cafb80103092b7e585987ef275a136f87/r | COMMENT |
| LOW | tools/stack_decode.py | 1 | #!/usr/bin/env python3 | COMMENT |
| LOW | tools/stack_decode.py | 21 | import sys | COMMENT |
| LOW | tools/local_fix_format.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | tools/find_related_envoy_files.py | 1 | #!/usr/bin/env python | COMMENT |
| LOW | tools/path_fix.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | tools/api_proto_plugin/type_context.py | 141 | def __init__(self, source_code_info, name): | COMMENT |
| LOW | tools/deprecate_guards/deprecate_guards.py | 1 | # Bazel usage | COMMENT |
| LOW | tools/debugging/run-valgrind.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | tools/dependency/ossf_scorecard.py | 1 | #!/usr/bin/env python3 | COMMENT |
| LOW | tools/github/sync_assignable.py | 1 | # Sync envoyproxy organization users to envoyproxy/assignable team. | COMMENT |
| LOW | tools/protoprint/protoprint.py | 361 | # if we evaluate to the fully qualified type. If so, we're done. It's not | COMMENT |
| LOW | tools/protoprint/protoprint.py | 381 | # 1. its root package is different from the root package of the context type | COMMENT |
| LOW | tools/spelling/check_spelling_pedantic.py | 21 | COMMENT | |
| LOW | tools/base/requirements.txt | 1 | # | COMMENT |
| LOW | tools/base/requirements.txt | 21 | # envoy-distribution-release | COMMENT |
| LOW | tools/base/requirements.txt | 41 | # aio-api-github | COMMENT |
| LOW | tools/base/requirements.txt | 61 | --hash=sha256:43c80688c50ba3a528d88635fee5653b9f0f40fc4a036e1aeaddf8ada3794d2e | COMMENT |
| LOW | tools/git/last_github_commit.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | compat/openssl/tools/generate.c.sh | 1 | #!/bin/bash | COMMENT |
| LOW | compat/openssl/tools/generate.c.sh | 61 | # Note that if the OpenSSL function that we are calling onto is a function-like | COMMENT |
| LOW | compat/openssl/prefixer/prefixer.cpp | 1 | #include "clang/AST/ASTConsumer.h" | COMMENT |
| LOW | compat/openssl/source/ossl_dlutil.c | 1 | #define _GNU_SOURCE | COMMENT |
| LOW | compat/openssl/source/log.h | 21 | #define bssl_compat_debug(...) \ | COMMENT |
| LOW | compat/openssl/source/SSL_get_curve_id.c | 61 | //case ossl_NID_curveSM2: return 41; | COMMENT |
| LOW | compat/openssl/source/BIO_gets.c | 1 | #include <openssl/bio.h> | COMMENT |
| LOW | compat/openssl/patch/crypto/test/file_test.cc.sh | 1 | #!/bin/bash | COMMENT |
| LOW | compat/openssl/patch/crypto/test/file_test_gtest.cc.sh | 1 | #!/bin/bash | COMMENT |
| LOW | compat/openssl/patch/crypto/test/test_data.cc.sh | 1 | #!/bin/bash | COMMENT |
| LOW | compat/openssl/patch/crypto/test/file_test.h.sh | 1 | #!/bin/bash | COMMENT |
| LOW | compat/openssl/patch/ssl/ssl_c_test.c.sh | 1 | #!/bin/bash | COMMENT |
| LOW | compat/openssl/patch/include/openssl/ssl.h.sh | 241 | --uncomment-macro DTLS1_3_VERSION | COMMENT |
| LOW | compat/openssl/patch/include/openssl/ssl.h.sh | 261 | // numbering (which densely covers 100-422 and 1010-1120). | COMMENT |
| LOW | compat/openssl/patch/include/openssl/ssl.h.sh | 281 | #define SSL_R_EXCESS_HANDSHAKE_DATA 10007 | COMMENT |
| LOW | compat/openssl/patch/include/openssl/ssl.h.sh | 301 | #ifndef SSL_R_INVALID_ALPN_PROTOCOL_LIST | COMMENT |
| LOW | test/test_listener.h | 1 | #pragma once | COMMENT |
| LOW | test/tools/router_check/router.h | 1 | #pragma once | COMMENT |
| LOW | test/config/v2_link_hacks.h | 1 | #pragma once | COMMENT |
| LOW | test/config/utility.h | 1 | #pragma once | COMMENT |
| LOW | test/config/integration/certs/generate_nul_cert.py | 81 | # Subject Alternative Name (SAN): | COMMENT |
| LOW | test/integration/integration_tcp_client.h | 1 | #pragma once | COMMENT |
| LOW | test/integration/quic_http_integration_test.h | 1 | #pragma once | COMMENT |
| LOW | test/integration/quic_http_integration_test.h | 21 | COMMENT | |
| LOW | test/integration/http_integration.h | 1 | #pragma once | COMMENT |
| LOW | test/integration/xdstp_config_sources_integration.h | 1 | #pragma once | COMMENT |
| LOW | test/integration/http_protocol_integration.h | 21 | // | COMMENT |
| LOW | test/integration/xfcc_integration_test.h | 1 | #pragma once | COMMENT |
| LOW | test/integration/base_integration_test.h | 1 | #pragma once | COMMENT |
| LOW | test/integration/base_integration_test.h | 21 | #include "test/integration/utility.h" | COMMENT |
| LOW | test/integration/scoped_rds.h | 1 | #pragma once | COMMENT |
| LOW | test/integration/ads_xdstp_config_sources_integration.h | 1 | #pragma once | COMMENT |
| LOW | test/integration/tracked_watermark_buffer.h | 1 | #pragma once | COMMENT |
| LOW | test/integration/tracked_watermark_buffer.h | 81 | // Number of buffers still in use. | COMMENT |
| LOW | test/integration/vhds.h | 1 | #pragma once | COMMENT |
| LOW | test/integration/vhds.h | 201 | // Make sure this number matches the size of the 'clusters' repeated field in the bootstrap | COMMENT |
| LOW | test/integration/fake_upstream.h | 1 | #pragma once | COMMENT |
| LOW | test/integration/fake_upstream.h | 21 | #include "source/common/common/basic_resource_impl.h" | COMMENT |
| LOW | test/integration/fake_upstream.h | 41 | #include "test/mocks/protobuf/mocks.h" | COMMENT |
| LOW | test/integration/fake_upstream.h | 281 | // Headers get updated in decodeHeaders() and accessed in headers() methods. Those methods can | COMMENT |
| LOW | test/integration/integration.h | 1 | #pragma once | COMMENT |
| 1310 more matches not shown… | ||||
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | rustfmt.toml | 4 | # ========================= | COMMENT |
| MEDIUM⚡ | …ng/ProxyInfoIntentPerformHTTPSRequestUsingProxyTest.kt | 31 | // ┌──────────────────┐ | COMMENT |
| MEDIUM⚡ | …ng/ProxyInfoIntentPerformHTTPSRequestUsingProxyTest.kt | 33 | // │ ┌──────────────┐ │ | COMMENT |
| MEDIUM⚡ | …ng/ProxyInfoIntentPerformHTTPSRequestUsingProxyTest.kt | 34 | // ┌─────────────────────────┐ ┌─┼─►listener_proxy│ │ | COMMENT |
| MEDIUM⚡ | …ng/ProxyInfoIntentPerformHTTPSRequestUsingProxyTest.kt | 35 | // │https://localhost:{port} │ ┌──────────────┬┘ │ └──────┬───────┘ │ ┌─────────────────┐ | COMMENT |
| MEDIUM⚡ | …ng/ProxyInfoIntentPerformHTTPSRequestUsingProxyTest.kt | 37 | // └─────────────────────────┘ └──────────────┘ │ ┌──────▼──────┐ │ └──────▲──────────┘ | COMMENT |
| MEDIUM⚡ | …ng/ProxyInfoIntentPerformHTTPSRequestUsingProxyTest.kt | 39 | // │ └─────────────┴──┼────────┘ | COMMENT |
| MEDIUM⚡ | …ng/ProxyInfoIntentPerformHTTPSRequestUsingProxyTest.kt | 41 | // └──────────────────┘ | COMMENT |
| MEDIUM⚡ | …/proxying/ProxyPollPerformHTTPRequestUsingProxyTest.kt | 28 | // ┌──────────────────┐ | COMMENT |
| MEDIUM⚡ | …/proxying/ProxyPollPerformHTTPRequestUsingProxyTest.kt | 30 | // │ ┌──────────────┐ │ | COMMENT |
| MEDIUM⚡ | …/proxying/ProxyPollPerformHTTPRequestUsingProxyTest.kt | 31 | // ┌────────────────────────┐ ┌─┼─►listener_proxy│ │ | COMMENT |
| MEDIUM⚡ | …/proxying/ProxyPollPerformHTTPRequestUsingProxyTest.kt | 32 | // │http://localhost:{port} │ ┌──────────────┬┘ │ └──────┬───────┘ │ ┌─────────────────┐ | COMMENT |
| MEDIUM⚡ | …/proxying/ProxyPollPerformHTTPRequestUsingProxyTest.kt | 34 | // └────────────────────────┘ └──────────────┘ │ ┌──────▼──────┐ │ └──────▲──────────┘ | COMMENT |
| MEDIUM⚡ | …/proxying/ProxyPollPerformHTTPRequestUsingProxyTest.kt | 36 | // │ └─────────────┴──┼────────┘ | COMMENT |
| MEDIUM⚡ | …/proxying/ProxyPollPerformHTTPRequestUsingProxyTest.kt | 38 | // └──────────────────┘ | COMMENT |
| MEDIUM⚡ | …oxyInfoIntentPerformHTTPSRequestUsingAsyncProxyTest.kt | 31 | // ┌──────────────────┐ | COMMENT |
| MEDIUM⚡ | …oxyInfoIntentPerformHTTPSRequestUsingAsyncProxyTest.kt | 33 | // │ ┌──────────────┐ │ | COMMENT |
| MEDIUM⚡ | …oxyInfoIntentPerformHTTPSRequestUsingAsyncProxyTest.kt | 34 | // ┌─────────────────────────┐ ┌─┼─►listener_proxy│ │ | COMMENT |
| MEDIUM⚡ | …oxyInfoIntentPerformHTTPSRequestUsingAsyncProxyTest.kt | 35 | // │https://localhost:{port} │ ┌──────────────┬┘ │ └──────┬───────┘ │ ┌─────────────────┐ | COMMENT |
| MEDIUM⚡ | …oxyInfoIntentPerformHTTPSRequestUsingAsyncProxyTest.kt | 37 | // └─────────────────────────┘ └──────────────┘ │ ┌──────▼──────┐ │ └──────▲──────────┘ | COMMENT |
| MEDIUM⚡ | …oxyInfoIntentPerformHTTPSRequestUsingAsyncProxyTest.kt | 39 | // │ └─────────────┴──┼────────┘ | COMMENT |
| MEDIUM⚡ | …oxyInfoIntentPerformHTTPSRequestUsingAsyncProxyTest.kt | 41 | // └──────────────────┘ | COMMENT |
| MEDIUM⚡ | …g/ProxyInfoIntentPerformHTTPSRequestBadHostnameTest.kt | 31 | // ┌──────────────────┐ | COMMENT |
| MEDIUM⚡ | …g/ProxyInfoIntentPerformHTTPSRequestBadHostnameTest.kt | 33 | // │ ┌──────────────┐ │ | COMMENT |
| MEDIUM⚡ | …g/ProxyInfoIntentPerformHTTPSRequestBadHostnameTest.kt | 34 | // ┌─────────────────────────┐ ┌─┼─►listener_proxy│ │ | COMMENT |
| MEDIUM⚡ | …g/ProxyInfoIntentPerformHTTPSRequestBadHostnameTest.kt | 35 | // │https://localhost:{port} │ ┌──────────────┬┘ │ └──────┬───────┘ │ ┌──────────────────┐ | COMMENT |
| MEDIUM⚡ | …g/ProxyInfoIntentPerformHTTPSRequestBadHostnameTest.kt | 37 | // └─────────────────────────┘ └──────────────┘ │ ┌──────▼──────┐ │ └──────▲───────────┘ | COMMENT |
| MEDIUM⚡ | …g/ProxyInfoIntentPerformHTTPSRequestBadHostnameTest.kt | 39 | // │ └─────────────┴──┼────────┘ | COMMENT |
| MEDIUM⚡ | …g/ProxyInfoIntentPerformHTTPSRequestBadHostnameTest.kt | 41 | // └──────────────────┘ | COMMENT |
| MEDIUM⚡ | …ing/ProxyInfoIntentPerformHTTPRequestUsingProxyTest.kt | 30 | // ┌──────────────────┐ | COMMENT |
| MEDIUM⚡ | …ing/ProxyInfoIntentPerformHTTPRequestUsingProxyTest.kt | 32 | // │ ┌──────────────┐ │ | COMMENT |
| MEDIUM⚡ | …ing/ProxyInfoIntentPerformHTTPRequestUsingProxyTest.kt | 33 | // ┌────────────────────────┐ ┌─┼─►listener_proxy│ │ | COMMENT |
| MEDIUM⚡ | …ing/ProxyInfoIntentPerformHTTPRequestUsingProxyTest.kt | 34 | // │http://localhost:{port}/│ ┌──────────────┬┘ │ └──────┬───────┘ │ ┌────────────-----┐ | COMMENT |
| MEDIUM⚡ | …ing/ProxyInfoIntentPerformHTTPRequestUsingProxyTest.kt | 36 | // └────────────────────────┘ └──────────────┘ │ ┌──────▼──────┐ │ └──────▲─────-----┘ | COMMENT |
| MEDIUM⚡ | …ing/ProxyInfoIntentPerformHTTPRequestUsingProxyTest.kt | 38 | // │ └─────────────┴──┼────────┘ | COMMENT |
| MEDIUM⚡ | …ing/ProxyInfoIntentPerformHTTPRequestUsingProxyTest.kt | 40 | // └──────────────────┘ | COMMENT |
| MEDIUM⚡ | …ProxyPollPerformHTTPRequestWithoutUsingPACProxyTest.kt | 29 | // ┌──────────────────┐ | COMMENT |
| MEDIUM⚡ | …ProxyPollPerformHTTPRequestWithoutUsingPACProxyTest.kt | 31 | // │ ┌──────────────┐ │ | COMMENT |
| MEDIUM⚡ | …ProxyPollPerformHTTPRequestWithoutUsingPACProxyTest.kt | 32 | // ┌─────────────────────────┐ │ │listener_proxy│ │ | COMMENT |
| MEDIUM⚡ | …ProxyPollPerformHTTPRequestWithoutUsingPACProxyTest.kt | 33 | // │https://localhost:{port} │ ┌──────────────┐ │ └──────┬───────┘ │ ┌─────────────────┐ | COMMENT |
| MEDIUM⚡ | …ProxyPollPerformHTTPRequestWithoutUsingPACProxyTest.kt | 35 | // └─────────────────────────┘ └───────┬──────┘ │ ┌──────▼──────┐ │ └──────▲──────────┘ | COMMENT |
| MEDIUM⚡ | …ProxyPollPerformHTTPRequestWithoutUsingPACProxyTest.kt | 37 | // │ │ └─────────────┘ │ │ | COMMENT |
| MEDIUM⚡ | …ProxyPollPerformHTTPRequestWithoutUsingPACProxyTest.kt | 39 | // │ └──────────────────┘ │ | COMMENT |
| MEDIUM⚡ | …ProxyPollPerformHTTPRequestWithoutUsingPACProxyTest.kt | 41 | // └─────────────────────────────────────┘ | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | tools/gen_compilation_database.py | 11 | def get_bazel_startup_options(): | CODE |
| LOW | tools/gen_compilation_database.py | 30 | def generate_compilation_database(args): | CODE |
| LOW | tools/api_proto_plugin/type_context.py | 16 | def get_comment_with_transforms(self, annotation_xforms): | CODE |
| LOW | tools/api_proto_plugin/type_context.py | 80 | def leading_comment_path_lookup(self, path): | CODE |
| LOW | tools/api_proto_plugin/type_context.py | 96 | def leading_detached_comments_path_lookup(self, path): | CODE |
| LOW | tools/api_proto_plugin/type_context.py | 115 | def trailing_comment_path_lookup(self, path): | CODE |
| LOW | tools/api_proto_plugin/type_context.py | 275 | def leading_detached_comments(self): | CODE |
| LOW | tools/api_proto_plugin/utils.py | 4 | def proto_file_canonical_from_label(label): | CODE |
| LOW | tools/api_proto_plugin/utils.py | 18 | def bazel_bin_path_for_output_artifact(label, suffix, root=''): | CODE |
| LOW | tools/type_whisperer/typedb_gen.py | 72 | def upgraded_type_with_description(type_name, type_desc): | CODE |
| LOW⚡ | tools/dependency/validate_test.py | 50 | def test_valid_build_graph_structure(self): | CODE |
| LOW⚡ | tools/dependency/validate_test.py | 58 | def test_invalid_build_graph_structure(self): | CODE |
| LOW⚡ | tools/dependency/validate_test.py | 68 | def test_valid_test_only_deps(self): | CODE |
| LOW⚡ | tools/dependency/validate_test.py | 75 | def test_invalid_test_only_deps(self): | CODE |
| LOW⚡ | tools/dependency/validate_test.py | 83 | def test_valid_dataplane_core_deps(self): | CODE |
| LOW⚡ | tools/dependency/validate_test.py | 88 | def test_invalid_dataplane_core_deps(self): | CODE |
| LOW⚡ | tools/dependency/validate_test.py | 95 | def test_valid_controlplane_deps(self): | CODE |
| LOW⚡ | tools/dependency/validate_test.py | 100 | def test_invalid_controlplane_deps(self): | CODE |
| LOW⚡ | tools/dependency/validate_test.py | 106 | def test_valid_extension_deps(self): | CODE |
| LOW⚡ | tools/dependency/validate_test.py | 116 | def test_invalid_extension_deps_wrong_category(self): | CODE |
| LOW | tools/dependency/validate_test.py | 128 | def test_invalid_extension_deps_allowlist(self): | CODE |
| LOW | tools/dependency/validate.py | 198 | async def validate_build_graph_structure(self): | CODE |
| LOW | tools/dependency/validate.py | 243 | async def validate_data_plane_core_deps(self): | CODE |
| LOW | tools/dependency/validate.py | 277 | async def validate_control_plane_deps(self): | CODE |
| LOW | tools/clang-tidy/collect_fixes.py | 47 | def get_bazel_startup_options() -> list[str]: | CODE |
| LOW | tools/clang-tidy/collect_fixes.py | 170 | def external_repository_from_path(path: str) -> str | None: | CODE |
| LOW | tools/clang-tidy/collect_fixes.py | 186 | def filter_document_diagnostics(document: dict, repository_name: str | None) -> dict | None: | CODE |
| LOW | tools/protoprint/protoprint.py | 47 | def get_versioning_annotation(options): | CODE |
| LOW | tools/protoprint/protoprint.py | 62 | def extract_clang_proto_style(clang_format_text): | CODE |
| LOW | tools/protoprint/protoprint.py | 146 | def create_next_free_field_xform(msg_proto): | CODE |
| LOW | tools/protoprint/protoprint.py | 164 | def format_type_context_comments(type_context, annotation_xforms=None): | CODE |
| LOW | tools/protoprint/protoprint.py | 325 | def format_public_import_block(xs): | CODE |
| LOW | tools/protoprint/protoprint.py | 338 | def normalize_field_type_name(type_context, field_fqn): | CODE |
| LOW | tools/protoprint/protoprint.py | 397 | def equivalent_in_type_context(splits): | CODE |
| LOW | tools/protoprint/protoprint.py | 618 | def _deprecated_annotation_version_value(self): | CODE |
| LOW | tools/api_proto_breaking_change_detector/detector_ci.py | 17 | def detect_breaking_changes_git(path_to_buf, ref): | CODE |
| LOW⚡ | …ls/api_proto_breaking_change_detector/detector_test.py | 41 | def test_change_field_plurality(self): | CODE |
| LOW⚡ | …ls/api_proto_breaking_change_detector/detector_test.py | 50 | def test_change_field_from_oneof(self): | CODE |
| LOW⚡ | …ls/api_proto_breaking_change_detector/detector_test.py | 53 | def test_change_field_to_oneof(self): | CODE |
| LOW | …ls/api_proto_breaking_change_detector/detector_test.py | 83 | def test_remove_and_reserve_field(self): | CODE |
| LOW⚡ | tools/api_versioning/utils_test.py | 44 | def test_valid_version_newline(self): | CODE |
| LOW⚡ | tools/api_versioning/utils_test.py | 47 | def test_invalid_version_string(self): | CODE |
| LOW⚡ | tools/api_versioning/utils_test.py | 50 | def test_invalid_version_partial(self): | CODE |
| LOW⚡ | tools/api_versioning/utils_test.py | 60 | def test_invalid_multiple_lines(self): | CODE |
| LOW⚡ | tools/api_versioning/utils_test.py | 63 | def test_valid_oldest_api_version(self): | CODE |
| LOW⚡ | tools/api_versioning/utils_test.py | 73 | def test_valid_deprecated_version_annotation(self): | CODE |
| LOW⚡ | tools/api_versioning/utils_test.py | 76 | def test_zero_major_deprecated_version_annotation(self): | CODE |
| LOW⚡ | tools/api_versioning/utils_test.py | 79 | def test_char_deprecated_version_annotation(self): | CODE |
| LOW⚡ | tools/api_versioning/utils_test.py | 82 | def test_patch_deprecated_version_annotation(self): | CODE |
| LOW⚡ | tools/api_versioning/utils_test.py | 85 | def test_negative_minor_deprecated_version_annotation(self): | CODE |
| LOW⚡ | tools/api_versioning/utils_test.py | 88 | def test_missing_major_deprecated_version_annotation(self): | CODE |
| LOW⚡ | tools/api_versioning/utils_test.py | 91 | def test_single_number_deprecated_version_annotation(self): | CODE |
| LOW⚡ | tools/api_versioning/utils_test.py | 94 | def test_empty_number_deprecated_version_annotation(self): | CODE |
| LOW | tools/api_versioning/utils.py | 37 | def compute_oldest_api_version(current_version: ApiVersion): | CODE |
| LOW | tools/api_versioning/utils.py | 55 | def is_deprecated_annotation_version(version: str): | CODE |
| LOW | …ols/api_versioning/generate_api_version_header_test.py | 57 | def test_valid_version_newline(self): | CODE |
| LOW | tools/vscode/generate_debug_config.py | 41 | def build_binary_with_debug_info(target, config=None): | CODE |
| LOW | tools/spelling/check_spelling_pedantic_test.py | 56 | def check_file_expecting_errors(filename, expected_substrings): | CODE |
| LOW | tools/spelling/check_spelling_pedantic_test.py | 61 | def check_file_path_expecting_ok(filename): | CODE |
| LOW⚡ | tools/code_format/check_format.py | 355 | def allow_listed_for_protobuf_deps(self, file_path): | CODE |
| 88 more matches not shown… | ||||
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| CRITICAL⚡ | contrib/kafka/filters/network/source/serialization.h | 1018 | * Ref: org.apache.kafka.common.utils.ByteUtils.writeUnsignedVarint(int, ByteBuffer) | COMMENT |
| CRITICAL⚡ | contrib/kafka/filters/network/source/serialization.h | 1024 | * Ref: org.apache.kafka.common.utils.ByteUtils.writeVarint(int, ByteBuffer) | COMMENT |
| CRITICAL⚡ | contrib/kafka/filters/network/source/serialization.h | 1030 | * Ref: org.apache.kafka.common.utils.ByteUtils.writeVarlong(long, ByteBuffer) | COMMENT |
| CRITICAL⚡ | …proxy/envoymobile/utilities/AndroidNetworkLibrary.java | 132 | if (io.envoyproxy.envoymobile.engine.AndroidNetworkMonitorV2.getInstance() == null) { | CODE |
| CRITICAL⚡ | …proxy/envoymobile/utilities/AndroidNetworkLibrary.java | 135 | return io.envoyproxy.envoymobile.engine.AndroidNetworkMonitorV2.getInstance().getDefaultNetId(); | CODE |
| CRITICAL⚡ | …proxy/envoymobile/utilities/AndroidNetworkLibrary.java | 139 | if (io.envoyproxy.envoymobile.engine.AndroidNetworkMonitorV2.getInstance() == null) { | CODE |
| CRITICAL⚡ | …proxy/envoymobile/utilities/AndroidNetworkLibrary.java | 143 | io.envoyproxy.envoymobile.engine.AndroidNetworkMonitorV2.getInstance() | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | tools/build_profile.py | 6 | CODE | |
| LOW | tools/envoy_collect/envoy_collect.py | 37 | CODE | |
| LOW | tools/deprecate_guards/deprecate_guards.py | 15 | CODE | |
| LOW | tools/deprecate_features/deprecate_features.py | 3 | CODE | |
| LOW | tools/spelling/check_spelling_pedantic.py | 3 | CODE | |
| LOW | tools/spelling/check_spelling_pedantic_test.py | 5 | CODE | |
| LOW | test/config/integration/certs/generate_nul_cert.py | 7 | CODE | |
| LOW | test/integration/capture_fuzz_gen.py | 8 | CODE | |
| LOW | test/integration/capture_fuzz_gen.py | 10 | CODE | |
| LOW | …twork/thrift_proxy/driver/fbthrift/THeaderTransport.py | 23 | CODE | |
| LOW | …twork/thrift_proxy/driver/fbthrift/THeaderTransport.py | 24 | CODE | |
| LOW | …twork/thrift_proxy/driver/fbthrift/THeaderTransport.py | 25 | CODE | |
| LOW | …twork/thrift_proxy/driver/fbthrift/THeaderTransport.py | 26 | CODE | |
| LOW | …dential_providers/iam_roles_anywhere_test_generator.py | 12 | CODE | |
| LOW | …nfig_schemas_test_data/test_top_level_config_schema.py | 2 | CODE | |
| LOW | …nfig_schemas_test_data/test_top_level_config_schema.py | 2 | CODE | |
| LOW | …n/json/config_schemas_test_data/test_cluster_schema.py | 2 | CODE | |
| LOW | …n/json/config_schemas_test_data/test_cluster_schema.py | 2 | CODE | |
| LOW | …g_schemas_test_data/test_route_configuration_schema.py | 2 | CODE | |
| LOW | …g_schemas_test_data/test_route_configuration_schema.py | 2 | CODE | |
| LOW | …/json/config_schemas_test_data/test_listener_schema.py | 2 | CODE | |
| LOW | …on/config_schemas_test_data/test_route_entry_schema.py | 2 | CODE | |
| LOW | …on/config_schemas_test_data/test_route_entry_schema.py | 2 | CODE | |
| LOW | …on/config_schemas_test_data/test_http_router_schema.py | 2 | CODE | |
| LOW | …son/config_schemas_test_data/test_access_log_schema.py | 2 | CODE | |
| LOW | …son/config_schemas_test_data/test_access_log_schema.py | 2 | CODE | |
| LOW | restarter/hot-restarter.py | 2 | CODE | |
| LOW | mobile/test/python/echo_test_server.py | 3 | CODE | |
| LOW | mobile/test/python/test_transport_factory.py | 11 | CODE | |
| LOW | mobile/test/python/test_transport_factory.py | 11 | CODE | |
| LOW | mobile/test/python/fetch_test.py | 7 | CODE | |
| LOW | mobile/test/python/fetch_test.py | 7 | CODE | |
| LOW | mobile/test/python/fetch_test.py | 7 | CODE | |
| LOW | mobile/test/python/test_httpx_transport.py | 11 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 1 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 1 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 1 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 1 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 1 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 1 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 1 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 1 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 1 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 1 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 13 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 14 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 15 | CODE | |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 16 | CODE | |
| LOW | api/tools/tap2pcap.py | 20 | CODE | |
| LOW | api/tools/tap2pcap_test.py | 2 | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | tools/stack_decode.py | 28 | CODE | |
| LOW | tools/envoy_collect/envoy_collect.py | 66 | CODE | |
| LOW | tools/envoy_collect/envoy_collect.py | 153 | CODE | |
| LOW | tools/socket_passing/socket_passing.py | 25 | CODE | |
| LOW | tools/dependency/cve_fetch.py | 160 | CODE | |
| LOW | tools/dependency/validate.py | 308 | CODE | |
| LOW | tools/clang-tidy/collect_fixes.py | 150 | CODE | |
| LOW | tools/clang-tidy/collect_fixes.py | 212 | CODE | |
| LOW | tools/protoprint/protoprint.py | 183 | CODE | |
| LOW | tools/protoprint/protoprint.py | 621 | CODE | |
| LOW | tools/proto_format/proto_sync.py | 68 | CODE | |
| LOW | tools/proto_format/format_api.py | 96 | CODE | |
| LOW | tools/vscode/generate_debug_config.py | 110 | CODE | |
| LOW | tools/repo/notify.py | 138 | CODE | |
| LOW | tools/spelling/check_spelling_pedantic.py | 326 | CODE | |
| LOW | tools/spelling/check_spelling_pedantic.py | 505 | CODE | |
| LOW | tools/spelling/check_spelling_pedantic.py | 608 | CODE | |
| LOW | tools/spelling/check_spelling_pedantic.py | 262 | CODE | |
| LOW | tools/code_format/check_format.py | 109 | CODE | |
| LOW | tools/code_format/check_format.py | 276 | CODE | |
| LOW | tools/code_format/check_format.py | 460 | CODE | |
| LOW | tools/code_format/check_format.py | 1033 | CODE | |
| LOW | …tensions/filters/network/thrift_proxy/driver/server.py | 98 | CODE | |
| LOW | …tensions/filters/network/thrift_proxy/driver/client.py | 58 | CODE | |
| LOW | …twork/thrift_proxy/driver/fbthrift/THeaderTransport.py | 283 | CODE | |
| LOW | …twork/thrift_proxy/driver/fbthrift/THeaderTransport.py | 349 | CODE | |
| LOW | …twork/thrift_proxy/driver/fbthrift/THeaderTransport.py | 496 | CODE | |
| LOW | docs/tools/protodoc/protodoc.py | 390 | CODE | |
| LOW | …rib/kafka/filters/network/source/protocol/generator.py | 144 | CODE | |
| LOW | …rib/kafka/filters/network/source/protocol/generator.py | 210 | CODE | |
| LOW | …rib/kafka/filters/network/source/protocol/generator.py | 345 | CODE | |
| LOW | mobile/ci/sonatype_nexus_upload.py | 28 | CODE | |
| LOW | …/library/python/envoy_mobile/async_client_transport.py | 67 | CODE | |
| LOW | …e/library/python/envoy_mobile/sync_client_transport.py | 62 | CODE | |
| LOW | …bile/library/python/envoy_mobile/async_client/utils.py | 60 | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW⚡ | compat/openssl/AGENTS.md | 34 | ### Step 1: Uncomment the declaration | COMMENT |
| LOW⚡ | compat/openssl/AGENTS.md | 43 | ### Step 2: Add to the BUILD file | COMMENT |
| LOW⚡ | compat/openssl/AGENTS.md | 48 | ### Step 3: Decide if a handwritten source file is needed | COMMENT |
| LOW⚡ | source/extensions/dynamic_modules/sdk/go/shared/http.go | 463 | // NOTE: This method should only be called during OnRequest* or OnResponse* callbacks or | COMMENT |
| LOW⚡ | source/extensions/dynamic_modules/sdk/go/shared/http.go | 472 | // NOTE: This method should only be called during OnRequest* or OnResponse* callbacks or | COMMENT |
| LOW⚡ | source/extensions/dynamic_modules/sdk/go/shared/http.go | 480 | // NOTE: This method should only be called during OnRequest* or OnResponse* callbacks or | COMMENT |
| LOW⚡ | source/extensions/dynamic_modules/sdk/go/shared/http.go | 487 | // NOTE: This method should only be called during OnRequest* or OnResponse* callbacks or | COMMENT |
| LOW | source/extensions/dynamic_modules/sdk/go/shared/http.go | 286 | // NOTE: This function should only be called when the plugin chains are hung up because | COMMENT |
| LOW | source/extensions/dynamic_modules/sdk/go/shared/http.go | 291 | // NOTE: This function should only be called when the plugin chains are hung up because | COMMENT |
| LOW | source/extensions/dynamic_modules/sdk/go/shared/http.go | 451 | // NOTE: This method should only be called during OnRequest* or OnResponse* callbacks or | COMMENT |
| LOW | …tensions/dynamic_modules/sdk/go/shared/network_base.go | 213 | // NOTE: This method should only be called during network filter callbacks or scheduled functions | COMMENT |
| LOW | source/common/network/lc_trie.h | 80 | // Step 1: separate the provided prefixes by protocol (IPv4 vs IPv6), | COMMENT |
| LOW | source/common/network/lc_trie.h | 121 | // Step 2: push each Binary Trie's prefixes to its leaves. | COMMENT |
| LOW | source/common/network/lc_trie.h | 144 | // Step 3: take the disjoint prefixes from the leaves of each Binary Trie | COMMENT |
| LOW | .github/workflows/_run.yml | 348 | # WARNING: This allows untrusted code to run!!! | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | tools/socket_passing/socket_passing.py | 36 | except Exception as e: | CODE |
| LOW | tools/repo/notify.py | 170 | except Exception as e: | CODE |
| MEDIUM | tools/repo/notify.py | 171 | print("Error while fetching and parsing the on-call calendar: {e}") | CODE |
| LOW | test/config/integration/certs/generate_nul_cert.py | 18 | except Exception as e: | CODE |
| LOW | test/config/integration/certs/generate_nul_cert.py | 30 | except Exception as e: | CODE |
| LOW | test/config/integration/certs/generate_nul_cert.py | 72 | except Exception as e: | CODE |
| LOW | …rib/kafka/filters/network/source/protocol/generator.py | 170 | except Exception as e: | CODE |
| LOW | mobile/ci/sonatype_nexus_upload.py | 114 | except Exception as e: | CODE |
| LOW | mobile/ci/sonatype_nexus_upload.py | 150 | except Exception as e: | CODE |
| LOW | mobile/ci/sonatype_nexus_upload.py | 168 | except Exception as e: | CODE |
| LOW | mobile/ci/sonatype_nexus_upload.py | 184 | except Exception as e: | CODE |
| LOW | mobile/ci/sonatype_nexus_upload.py | 200 | except Exception as e: | CODE |
| LOW | mobile/ci/sonatype_nexus_upload.py | 322 | except Exception as e: | STRING |
| LOW | mobile/ci/sonatype_nexus_upload.py | 331 | except Exception as e: | STRING |
| MEDIUM | mobile/ci/sonatype_nexus_upload.py | 100 | def _create_staging_repository(profile_id): | CODE |
| LOW | mobile/ci/start_ios_mock_server.py | 46 | except Exception as e: | CODE |
| LOW | mobile/ci/start_ios_mock_server.py | 63 | except Exception: | CODE |
| LOW | …/library/python/envoy_mobile/async_client_transport.py | 203 | except Exception: | CODE |
| MEDIUM | …/library/python/envoy_mobile/async_client_transport.py | 28 | def __aiter__(self) -> AsyncIterable[bytes]: | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | tools/gen_compilation_database.py | 29 | # This method is equivalent to https://github.com/grailbio/bazel-compilation-database/blob/master/generate.py | COMMENT |
| MEDIUM | ci/docker-entrypoint-extra.sh | 9 | # Create a group with the same GID as the socket | COMMENT |
| MEDIUM | docs/conf.py | 6 | # This file is execfile()d with the current directory set to its | COMMENT |
| MEDIUM | mobile/docs/conf.py | 6 | # This file is execfile()d with the current directory set to its | COMMENT |
| MEDIUM | .github/workflows/envoy-release.yml | 55 | # Create a release commit, when landed this will publish. | COMMENT |
| MEDIUM | .github/workflows/copilot-setup-steps.yml | 54 | # Create a helper script to fix truststore as mkcert CA changes when copilot starts | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | test/integration/filters/tee_filter.h | 39 | // Inject a specific instance of this factory in order to leverage the same | COMMENT |
| MEDIUM | test/server/guarddog_test_interlock.h | 12 | // Helps make tests using the GuardDog more robust by providing a way of | COMMENT |
| MEDIUM | source/server/hot_restart_impl.h | 61 | // Deal with robust handling here. If the other process dies without unlocking, we are going | COMMENT |
| MEDIUM | source/extensions/filters/common/ext_authz/ext_authz.h | 130 | // dynamic metadata that other filters can leverage. | COMMENT |
| MEDIUM | source/common/common/mutex_tracer_impl.h | 55 | // We utilize std::memory_order_relaxed for all operations for the least possible contention. | COMMENT |
| MEDIUM | source/common/http/headers.h | 17 | // is disallowed. Essentially this is write-once then read-only. | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| HIGH | tools/code_format/check_format.py | 274 | # writing the result lines as requested. | COMMENT |
| HIGH | test/integration/vhds.h | 207 | // 1) It appends to fake_upstreams_ as many as you asked for via setUpstreamCount(). | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| HIGH | mobile/test/python/lifecycle_test.py | 0 | integration tests for the envoy mobile python asyncio bindings. | STRING |
| HIGH | mobile/test/python/fetch_test.py | 0 | integration tests for the envoy mobile python asyncio bindings. | STRING |
| HIGH | …le/test/python/async_client/async_client_fetch_test.py | 0 | integration tests for the envoy mobile python asyncio bindings. | STRING |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| HIGH | tools/dependency/validate.py | 73 | Find the set of external dependencies in a given use_category. Args: use_category: string providing u | STRING |
| HIGH | tools/api_versioning/utils.py | 15 | Returns the API version from a given API version input file. Args: input_path: the file containing the API ve | STRING |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | tools/dependency/cve_test.sh | 9 | # Check if the JSON array contains any CVEs and not just if file is non-empty. | COMMENT |
| LOW | tools/github/write_current_source_version.py | 52 | # Check if we have VERSION.txt available | COMMENT |
| LOW | tools/api_versioning/generate_api_version_header.py | 48 | # Print output to stdout | COMMENT |
| LOW | tools/vscode/generate_debug_config.py | 146 | # Check if we're on ARM64 architecture | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | tools/dependency/ossf_scorecard.py | 5 | # Usage: | COMMENT |
| LOW | ci/docker_rebuild_google-vrp.sh | 9 | # Usage: | COMMENT |
| LOW | configs/envoy-otel-http.yaml | 4 | # Usage: | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | source/common/network/lc_trie.h | 80 | // Step 1: separate the provided prefixes by protocol (IPv4 vs IPv6), | COMMENT |
| LOW | source/common/network/lc_trie.h | 121 | // Step 2: push each Binary Trie's prefixes to its leaves. | COMMENT |
| LOW | source/common/network/lc_trie.h | 144 | // Step 3: take the disjoint prefixes from the leaves of each Binary Trie | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | tools/code_format/check_format.py | 23 | logger = logging.getLogger(__name__) | CODE |
| LOW | restarter/hot-restarter.py | 23 | logger = logging.getLogger(__name__) | CODE |
| LOW | docs/tools/protodoc/protodoc.py | 26 | logger = logging.getLogger(__name__) | CODE |
| LOW | mobile/library/python/envoy_mobile/__init__.py | 18 | __all__ = [ | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | …est/java/org/chromium/net/UploadDataProvidersTest.java | 35 | "Lorem ipsum dolor sit amet, consectetur adipiscing elit. " | CODE |
| LOW | …est/java/org/chromium/net/UploadDataProvidersTest.java | 35 | "Lorem ipsum dolor sit amet, consectetur adipiscing elit. " | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | …rib/kafka/filters/network/source/protocol/generator.py | 208 | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | …e/library/python/envoy_mobile/sync_client_transport.py | 144 | def handle_request(self, request: httpx.Request) -> httpx.Response: | CODE |