Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel and perform like containers, but provide the workload isolation and security advantages of VMs. https://katacontainers.io/
This report presents the forensic synthetic code analysis of kata-containers/kata-containers, a Rust project with 8,304 GitHub stars. SynthScan v2.0 examined 506,113 lines of code across 2052 source files, recording 812 pattern matches distributed across 16 syntactic categories. The overall adjusted score of 2.3 places this repository in the Likely human-written band.
The scanner applied 160+ deterministic lexical heuristics, multi-line block detectors, abstract syntax tree depth profilers, and a cross-file Jaccard similarity matrix to construct a statistically normalised synthetic code estimate. All matches are individually weighted by severity coefficient and contextual multiplier before summation, and the resulting headline score is temporally discounted to account for the repository's development history relative to the commercial emergence of large language model coding tooling (November 2022 onward).
This chart maps the temporal evolution of the adjusted synthetic code score across successive scan runs. An upward trajectory indicates ongoing incorporation of AI-generated code or expanding LLM-assisted scaffolding; a stable or declining trajectory may reflect active human refactoring, code removal, or the adoption of stricter authorship policies. The dashed secondary line (right axis) independently tracks total raw pattern hit count, which can diverge from the normalised score when codebase size changes significantly between scans.
Classifies detected patterns by their diagnostic confidence and structural impact. CRITICAL patterns (coefficient 10) represent definitive synthetic signatures — hallucinated imports, explicit LLM attribution metadata — virtually never produced by human authors. HIGH (5) indicates strong structural tells such as cross-file repetition or cross-linguistic idioms. MEDIUM (2) covers recognisable conversational padding and AI-specific vocabulary. LOW (1) captures subtle indicators like tautological comments and generic boilerplate that require density to carry independent signal.
This horizontal bar chart decomposes the repository's raw synthetic code score by top-level directory, allowing you to pinpoint precisely which modules or components carry the highest AI authorship density. Directories with disproportionately high scores relative to their size warrant targeted manual review: concentrated AI signatures often trace back to mass-generated configuration layers, auto-ported test suites, LLM-scaffolded boilerplate classes, or entire subsystems authored under heavy copilot assistance. Use this view to prioritise your human code-review effort.
The scanner identified 812 distinct pattern matches across 16 syntactic categories. Each entry below represents a discrete location in the source code where the engine recorded a statistically significant AI authorship indicator. Expand any category row to inspect the individual file paths, line numbers, code snippets, and the lexical context (CODE, COMMENT, or STRING) in which each match was detected.
Reading the findings table: The Severity column indicates the diagnostic confidence level (CRITICAL / HIGH / MEDIUM / LOW). The Context column identifies whether the match occurred inside executable code, an inline comment, or a string literal — comment-context matches receive a ×1.5 weight because LLMs systematically over-annotate. The ⚡ bolt icon marks clustered matches: three or more patterns within a 10-line window, each receiving an additional ×1.5 density multiplier as dense clusters constitute far stronger evidence of synthetic authorship than isolated hits.
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | Cargo.toml | 221 | # Per-package release profile overrides for kata-deploy. The kata-deploy | COMMENT |
| LOW | …kaging/kata-deploy/local-build/kata-deploy-binaries.sh | 501 | fi | COMMENT |
| LOW | …kaging/kata-deploy/local-build/kata-deploy-binaries.sh | 581 | # | COMMENT |
| LOW | …kaging/kata-deploy/local-build/kata-deploy-binaries.sh | 881 | # nvswitch -> enable DGX like systems | COMMENT |
| LOW | …ackaging/kata-deploy/helm-chart/kata-deploy/Chart.yaml | 1 | apiVersion: v2 | COMMENT |
| LOW | …helm-chart/kata-deploy/try-kata-nvidia-gpu.values.yaml | 1 | # Example values file to enable NVIDIA GPU shims | COMMENT |
| LOW | …deploy/helm-chart/kata-deploy/try-kata-tee.values.yaml | 1 | # Example values file to enable Trusted Execution Environment (TEE) shims | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 1 | # Deployment model for installing/cleaning up Kata on nodes. | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 21 | # When you add nodes later, re-run `helm upgrade` so the dispatcher enumerates | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 41 | # How to choose which nodes get a per-node INSTALL Job. Precedence: | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 61 | # - { key: node-role.kubernetes.io/control-plane, operator: DoesNotExist } | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 81 | # cleanup.nodeSelectorExpressions, else all nodes). | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 141 | # Use these when your containerd setup doesn't match any built-in distribution preset. | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 161 | # Node selector and tolerations to control which nodes the kata-deploy daemonset runs on | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 181 | # after the runtime is ready, at which point the scheduler admits the workloads. | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 201 | # Extra labels for the kata-deploy DaemonSet pods (in addition to the | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 221 | # themselves. NFD virtualization requirements cannot be bypassed. podAffinity, | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 241 | # topologyKey: kubernetes.io/hostname | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 261 | # Update strategy for the kata-deploy DaemonSet | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 281 | # Defaults sized from real measurements: VmRSS of the unpatched binary on | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 301 | # When empty, debug:true implies --log-level debug; otherwise kata-deploy falls | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 341 | timeoutSeconds: 3 | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 361 | # Independent of erofsSnapshotterMode — works with both disk and memory. | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 381 | # snapshotter: "" # e.g. nydus, erofs, devmapper, or "" for default | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 721 | installationPrefix: "" | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 741 | # control any external node-feature-discovery configuration). | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 761 | timeout: 180 | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 781 | # helm install kata-deploy ... \ | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 801 | # my-gpu-runtime: | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 821 | # katacontainers.io/kata-runtime: "true" | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 841 | # baseConfig: "qemu-nvidia-gpu" # Required: base config name | COMMENT |
| LOW | tools/packaging/kata-deploy/binary/src/config.rs | 201 | pub custom_runtimes: Vec<CustomRuntime>, | COMMENT |
| LOW | tools/packaging/kata-deploy/binary/src/main.rs | 61 | /// the node cannot support installation. | COMMENT |
| LOW | tools/packaging/kata-deploy/binary/src/main.rs | 81 | #[clap(name = "cleanup-stage-unlabel")] | COMMENT |
| LOW | tools/packaging/kata-deploy/binary/src/main.rs | 101 | const KATA_RUNTIME_LABEL: &str = "katacontainers.io/kata-runtime"; | COMMENT |
| LOW | tools/packaging/kata-deploy/binary/src/main.rs | 221 | // kernel after free, so a long-running idle wait here would | COMMENT |
| LOW | tools/packaging/kata-deploy/binary/src/main.rs | 881 | /// Keep this in sync with the `#[clap(name = ...)]` attributes above. | COMMENT |
| LOW | …aging/kata-deploy/binary/src/artifacts/snapshotters.rs | 261 | // | COMMENT |
| LOW | …/packaging/kata-deploy/binary/src/artifacts/install.rs | 761 | Ok(()) | COMMENT |
| LOW | …/packaging/kata-deploy/binary/src/artifacts/install.rs | 1361 | mod tests { | COMMENT |
| LOW | …/packaging/kata-deploy/binary/src/artifacts/install.rs | 1381 | #[case("qemu-snp-runtime-rs", "qemu")] | COMMENT |
| LOW | …packaging/kata-deploy/binary/src/runtime/containerd.rs | 541 | let drop_in_file = get_containerd_output_path(&paths); | COMMENT |
| LOW | …packaging/kata-deploy/binary/src/runtime/containerd.rs | 1001 | "containerd://1.6.28", | COMMENT |
| LOW | …packaging/kata-deploy/binary/src/runtime/containerd.rs | 1061 | #[rstest] | COMMENT |
| LOW | …ls/packaging/kata-deploy/binary/src/runtime/manager.rs | 221 | } | COMMENT |
| LOW | …ls/packaging/kata-deploy/binary/src/runtime/manager.rs | 281 | #[case("containerd://2.2.0", true)] | COMMENT |
| LOW | …a-deploy/binary/src/utils/containerd_config_version.rs | 41 | #[cfg(test)] | COMMENT |
| LOW | tools/packaging/kata-deploy/binary/src/utils/toml.rs | 481 | #[case("", "", "")] | COMMENT |
| LOW | tools/packaging/kata-deploy/job-dispatcher/src/main.rs | 1 | // Copyright (c) 2026 NVIDIA Corporation | COMMENT |
| LOW | tools/packaging/kata-deploy/job-dispatcher/src/main.rs | 41 | )] | COMMENT |
| LOW | tools/packaging/kata-deploy/job-dispatcher/src/main.rs | 61 | COMMENT | |
| LOW | tools/packaging/scripts/download-with-oras-cache.sh | 1 | #!/bin/bash | COMMENT |
| LOW | tools/packaging/scripts/populate-oras-tarball-cache.sh | 1 | #!/bin/bash | COMMENT |
| LOW | tools/packaging/scripts/configure-hypervisor.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | tools/packaging/scripts/configure-hypervisor.sh | 21 | COMMENT | |
| LOW | tools/packaging/scripts/configure-hypervisor.sh | 321 | # | COMMENT |
| LOW | tools/packaging/static-build/shim-v2/build.sh | 41 | # shellcheck disable=SC2154 | COMMENT |
| LOW | tools/osbuilder/rootfs-builder/alpine/rootfs_lib.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | tools/osbuilder/rootfs-builder/debian/config.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | tools/osbuilder/rootfs-builder/debian/config.sh | 21 | # shellcheck disable=SC2034 | COMMENT |
| 591 more matches not shown… | ||||
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| CRITICAL | tests/cleanup_resources.py | 6 | from azure.core.exceptions import ResourceNotFoundError | CODE |
| CRITICAL | src/tools/genpolicy/src/policy.rs | 786 | .set_container_path(self.config.settings.devices.vfio.device_path.clone()); | CODE |
| CRITICAL | src/tools/genpolicy/src/policy.rs | 801 | self.config.settings.devices.vfio.anno_key_regex.clone(), | CODE |
| CRITICAL | src/tools/genpolicy/src/policy.rs | 840 | Version: self.config.settings.kata_config.oci_version.clone(), | CODE |
| CRITICAL | src/tools/genpolicy/src/job.rs | 172 | self.spec.template.spec.securityContext.as_ref() | CODE |
| CRITICAL | src/tools/genpolicy/src/deployment.rs | 183 | self.spec.template.spec.securityContext.as_ref() | CODE |
| CRITICAL | src/tools/genpolicy/src/stateful_set.rs | 216 | self.spec.template.spec.securityContext.as_ref() | CODE |
| CRITICAL | src/tools/genpolicy/src/replication_controller.rs | 136 | self.spec.template.spec.securityContext.as_ref() | CODE |
| CRITICAL | src/tools/genpolicy/src/replica_set.rs | 133 | self.spec.template.spec.securityContext.as_ref() | CODE |
| CRITICAL | src/tools/genpolicy/src/daemon_set.rs | 172 | self.spec.template.spec.securityContext.as_ref() | CODE |
| CRITICAL | …rates/resource/src/network/endpoint/ipvlan_endpoint.rs | 73 | self.net_pair.tap.tap_iface.hard_addr.clone() | CODE |
| CRITICAL | …ates/resource/src/network/endpoint/macvlan_endpoint.rs | 72 | self.net_pair.tap.tap_iface.hard_addr.clone() | CODE |
| CRITICAL | …/crates/resource/src/network/endpoint/veth_endpoint.rs | 72 | self.net_pair.tap.tap_iface.hard_addr.clone() | CODE |
| CRITICAL | …/crates/resource/src/network/endpoint/vlan_endpoint.rs | 72 | self.net_pair.tap.tap_iface.hard_addr.clone() | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | …kaging/kata-deploy/local-build/kata-deploy-binaries.sh | 1557 | # Create a sym-link with the extension removed | COMMENT |
| MEDIUM | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 796 | # Create a custom-runtimes.values.yaml file: | COMMENT |
| MEDIUM | tools/osbuilder/scripts/lib.sh | 153 | # Create a YAML metadata file inside the rootfs. | COMMENT |
| MEDIUM | tools/osbuilder/rootfs-builder/rootfs.sh | 657 | # This file is part of systemd. | COMMENT |
| MEDIUM | tools/osbuilder/rootfs-builder/rootfs.sh | 847 | # Create an empty /etc/resolv.conf, to allow agent to bind mount container resolv.conf to Kata VM | COMMENT |
| MEDIUM | tools/testing/kata-webhook/create-certs.sh | 37 | # Create a Certificate Signing Request configuration file. | COMMENT |
| MEDIUM | ci/openshift-ci/run_smoke_test.sh | 16 | # Create a pod. | COMMENT |
| MEDIUM | ci/openshift-ci/smoke/service.yaml | 5 | # Create the service on port 80 for the http-server app. | COMMENT |
| MEDIUM | ci/openshift-ci/smoke/service.yaml | 18 | # Create the route to the app's service '/'. | COMMENT |
| MEDIUM | ci/openshift-ci/smoke/service_kubernetes.yaml | 5 | # Create the service on port 80 for the http-server app. | COMMENT |
| MEDIUM | tests/gha-run-k8s-common.sh | 155 | # Create the cluster. | COMMENT |
| MEDIUM | tests/gha-run-k8s-common.sh | 655 | # Create a new namespace for the tests and switch to it | COMMENT |
| MEDIUM | tests/common.bash | 7 | # This file contains common functions that | COMMENT |
| MEDIUM | tests/common.bash | 48 | # This function is called to indicate a fatal error occurred, so | COMMENT |
| MEDIUM | tests/common.bash | 1402 | # This function provides consistent test execution and reporting across | COMMENT |
| MEDIUM | tests/cmd/github-labels/github-labels.sh | 109 | # Create the master database from the template | COMMENT |
| MEDIUM | tests/integration/nerdctl/gha-run.sh | 54 | # Create the default containerd configuration | COMMENT |
| MEDIUM⚡ | tests/integration/kubernetes/confidential_common.sh | 219 | # Create the sealed secret test secret: | COMMENT |
| MEDIUM⚡ | tests/integration/kubernetes/confidential_common.sh | 225 | # Create the NIM test instruct secret: | COMMENT |
| MEDIUM⚡ | tests/integration/kubernetes/confidential_common.sh | 231 | # Create the NIM test embedqa secret: | COMMENT |
| MEDIUM | tests/integration/kubernetes/lib.sh | 34 | # Create a pod with a given number of retries if an output includes a timeout. | COMMENT |
| MEDIUM | tests/integration/kubernetes/lib.sh | 73 | # Create a pod and wait it be ready, otherwise fail. | COMMENT |
| MEDIUM | tests/integration/kubernetes/lib.sh | 189 | # Create a pod then assert it fails to run. Use in tests that you expect the | COMMENT |
| MEDIUM | tests/integration/kubernetes/lib.sh | 238 | # Create a pod then assert it remains in ContainerCreating. | COMMENT |
| MEDIUM | tests/integration/kubernetes/lib.sh | 314 | # Create a pod configuration out of a template file. | COMMENT |
| MEDIUM | tests/functional/vfio-ap/run.sh | 168 | # Create a mediated device (mdev) for the released device | COMMENT |
| MEDIUM | tests/functional/vfio-ap/run.sh | 223 | # Create a container and run the test | COMMENT |
| MEDIUM | utils/kata-manager.sh | 196 | # Create an array to store architecture names | COMMENT |
| MEDIUM | utils/kata-manager.sh | 215 | # Create a regular expression for matching | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | …/packaging/kata-deploy/binary/src/artifacts/install.rs | 766 | const KATA_DEPLOY_CONFIG_WARNING: &str = r#"# ========================================================================== | CODE |
| MEDIUM | …/packaging/kata-deploy/binary/src/artifacts/install.rs | 777 | # ============================================================================= | COMMENT |
| MEDIUM | tools/packaging/scripts/configure-hypervisor.sh | 7 | #--------------------------------------------------------------------- | COMMENT |
| MEDIUM | tools/packaging/scripts/configure-hypervisor.sh | 15 | #--------------------------------------------------------------------- | COMMENT |
| MEDIUM | tools/packaging/scripts/configure-hypervisor.sh | 211 | #--------------------------------------------------------------------- | COMMENT |
| MEDIUM | tools/packaging/scripts/configure-hypervisor.sh | 423 | #--------------------------------------------------------------------- | COMMENT |
| MEDIUM | tools/packaging/scripts/configure-hypervisor.sh | 480 | #--------------------------------------------------------------------- | COMMENT |
| MEDIUM | ci/gh-util.sh | 17 | #--------------------------------------------------------------------- | COMMENT |
| MEDIUM | ci/check_agent_policy_coverage.sh | 25 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | ci/check_agent_policy_coverage.sh | 27 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM⚡ | ci/check_agent_policy_coverage.sh | 52 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM⚡ | ci/check_agent_policy_coverage.sh | 56 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM⚡ | ci/check_agent_policy_coverage.sh | 66 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM⚡ | ci/check_agent_policy_coverage.sh | 68 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | ci/check_agent_policy_coverage.sh | 94 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | ci/check_agent_policy_coverage.sh | 96 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM⚡ | tests/kata-doc-to-script.sh | 125 | #---------------------------------------------- | COMMENT |
| MEDIUM⚡ | tests/kata-doc-to-script.sh | 129 | #---------------------------------------------- | COMMENT |
| MEDIUM⚡ | tests/kata-doc-to-script.sh | 131 | #---------------------------------------------- | COMMENT |
| MEDIUM⚡ | tests/kata-doc-to-script.sh | 133 | #---------------------------------------------- | COMMENT |
| MEDIUM | src/tools/log-parser/display.go | 20 | #---------------------------------------- | COMMENT |
| MEDIUM | src/tools/log-parser/display.go | 26 | #---------------------------------------- | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| HIGH | …untime-rs/crates/hypervisor/src/ch/inner_hypervisor.rs | 854 | // Early Check to verify if boot memory is the same as requested | COMMENT |
| HIGH | src/runtime/virtcontainers/clh.go | 1389 | // Early Check to verify if boot memory is the same as requested | COMMENT |
| HIGH | …gent/rustjail/src/cgroups/systemd/interface/session.rs | 11 | //! This code was generated by `zbus-xmlgen` `2.0.1` from DBus introspection data. | COMMENT |
| HIGH | …agent/rustjail/src/cgroups/systemd/interface/system.rs | 11 | //! This code was generated by `zbus-xmlgen` `3.1.1` from DBus introspection data. | COMMENT |
| HIGH | src/dragonball/dbs_virtio_devices/src/mem.rs | 1266 | // Make sure we have the correct resource as requested. | COMMENT |
| HIGH | …agonball/dbs_virtio_devices/src/vhost/vhost_user/fs.rs | 446 | // Make sure we have the correct resource as requested, and currently we only support one | COMMENT |
| HIGH | src/dragonball/dbs_virtio_devices/src/fs/device.rs | 886 | // Make sure we have the correct resource as requested, and currently we only support one | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | …helm-chart/kata-deploy/templates/verification-job.yaml | 302 | # Check if pod is stuck - look for events indicating it can't start | COMMENT |
| LOW | tools/packaging/scripts/gen_versions_txt.sh | 44 | # Check if qemu.version can be used to get the version and hash, otherwise use qemu.tag | COMMENT |
| LOW | tools/packaging/scripts/download-with-oras-cache.sh | 100 | # Check if artifact exists in GHCR and pull it | COMMENT |
| LOW | tools/packaging/scripts/download-with-oras-cache.sh | 147 | # Check if this version already exists in cache (avoid race conditions with parallel builds) | COMMENT |
| LOW | tools/packaging/scripts/configure-hypervisor.sh | 66 | # Display message to stderr and exit indicating script failed. | COMMENT |
| LOW | tools/packaging/static-build/kernel/install_yq.sh | 49 | # Check if we need sudo to install yq | COMMENT |
| LOW | tools/packaging/static-build/kernel/install_yq.sh | 51 | # Check if we have sudo privileges | COMMENT |
| LOW | tools/packaging/guest-image/lib_se.sh | 33 | # Check if FAKE_SE_IMAGE mode is enabled | COMMENT |
| LOW | tools/packaging/guest-image/build_se_image.sh | 52 | # Check if FAKE_SE_IMAGE mode is enabled | COMMENT |
| LOW | tools/osbuilder/image-builder/image_builder.sh | 222 | # Check if we have alternative init systems installed | COMMENT |
| LOW | tools/osbuilder/rootfs-builder/debian/config.sh | 9 | # Set OS_NAME to the desired debian "codename" | COMMENT |
| LOW | ci/install_yq.sh | 49 | # Check if we need sudo to install yq | COMMENT |
| LOW | ci/install_yq.sh | 51 | # Check if we have sudo privileges | COMMENT |
| LOW | ci/openshift-ci/cluster/install_kata.sh | 229 | # Set SELinux to permissive mode | COMMENT |
| LOW | tests/gha-run-k8s-common.sh | 973 | # Check if this mapping has a colon (shim-specific) | COMMENT |
| LOW | tests/static-checks.sh | 941 | # Check if the expected linter version | COMMENT |
| LOW | tests/govulncheck-runner.sh | 93 | # Check if any real vulnerabilities remain | COMMENT |
| LOW | tests/govulncheck-runner.sh | 102 | # Check if binary exists | COMMENT |
| LOW | tests/common.bash | 144 | # Check if first two arguments are numbers (for max_tries and interval) | COMMENT |
| LOW | tests/common.bash | 200 | # Check if the $1 argument is the name of a 'known' | COMMENT |
| LOW | tests/common.bash | 908 | # Check if helm is available in the system's PATH | COMMENT |
| LOW | tests/common.bash | 1379 | # Check if the 1st argument version is greater than and equal to 2nd one | COMMENT |
| LOW | tests/integration/kubernetes/lib.sh | 114 | # Check if there is an existing node debugger pod and reuse it | COMMENT |
| LOW | tests/integration/kubernetes/run_kubernetes_nv_tests.sh | 26 | # Check if drop-in already exists | COMMENT |
| LOW | …n/kubernetes/runtimeclass_workloads/numa/entrypoint.sh | 20 | # Print results to stdout (readable via "kubectl logs"), then sleep to | COMMENT |
| LOW | tests/stability/common_stability.bash | 12 | # Set variables to reasonable defaults if unset or empty | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | tools/packaging/kata-deploy/binary/src/main.rs | 676 | // Step 1: Check if THIS pod's owning DaemonSet still exists. | COMMENT |
| LOW | tools/packaging/kata-deploy/binary/src/main.rs | 692 | // Step 2: Our DaemonSet is gone (uninstall). Perform instance-specific | COMMENT |
| LOW | tools/packaging/kata-deploy/binary/src/main.rs | 724 | // Step 3: Check if ANY other kata-deploy DaemonSets still exist. | COMMENT |
| LOW | tests/integration/kubernetes/numa-pinning-check.sh | 7 | # WARNING: This script runs directly on the host, NOT inside a container. | COMMENT |
| LOW | docs/how-to/how-to-use-erofs-snapshotter-with-kata.md | 37 | ### Step 1: Install erofs-utils | COMMENT |
| LOW | docs/how-to/how-to-use-erofs-snapshotter-with-kata.md | 60 | ### Step 2: Configure containerd | COMMENT |
| LOW | docs/how-to/how-to-use-erofs-snapshotter-with-kata.md | 132 | ### Step 3: Configure Kata Containers (runtime-rs) | COMMENT |
| LOW | docs/how-to/how-to-use-numa-with-kata.md | 26 | ## Step 1: Inspect the Host NUMA Topology | COMMENT |
| LOW | docs/how-to/how-to-use-numa-with-kata.md | 66 | ## Step 2: Kubernetes CPU Manager Policy | COMMENT |
| LOW | docs/how-to/how-to-use-numa-with-kata.md | 103 | ## Step 3: Configure Kata Containers for NUMA | COMMENT |
| LOW | docs/how-to/how-to-use-numa-with-kata.md | 213 | ## Step 4: Deploy a NUMA-Aware Pod | COMMENT |
| LOW | docs/how-to/how-to-use-numa-with-kata.md | 277 | ## Step 5: Verify NUMA Inside the Guest | COMMENT |
| LOW | docs/how-to/how-to-use-numa-with-kata.md | 352 | ## Step 6: Verify NUMA on the Host | COMMENT |
| LOW | docs/how-to/how-to-use-numa-with-kata.md | 420 | ## Step 7: Verify GPU NUMA Placement (GPU Passthrough Only) | COMMENT |
| LOW | src/tools/agent-ctl/src/image.rs | 43 | // Step 1: Use skopeo to copy the image to a local OCI directory with explicit tag | COMMENT |
| LOW | src/tools/agent-ctl/src/image.rs | 63 | // Step 2: Use umoci to unpack the OCI image into a bundle | COMMENT |
| LOW⚡ | …rs/crates/resource/src/cdi_devices/container_device.rs | 47 | // Step 1: Extract all devices and filter out devices without device_info for vfio_devices | COMMENT |
| LOW⚡ | …rs/crates/resource/src/cdi_devices/container_device.rs | 57 | // Step 2: Group devices by vendor_id-class_id | COMMENT |
| LOW | …rs/crates/resource/src/cdi_devices/container_device.rs | 73 | // Step 3: Sort devices within each group by guest_pcipath | COMMENT |
| LOW⚡ | src/libs/kata-types/src/dmverity.rs | 247 | // Step 0: Remove stale device if it already exists | COMMENT |
| LOW⚡ | src/libs/kata-types/src/dmverity.rs | 253 | // Step 1: Create device as read-only | COMMENT |
| LOW⚡ | src/libs/kata-types/src/dmverity.rs | 302 | // Step 2: Load table and resume (activate) | COMMENT |
| LOW⚡ | src/libs/kata-types/src/dmverity.rs | 306 | // Step 3: Ensure the device node exists under /dev/mapper/. | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | …kaging/kata-deploy/local-build/kata-deploy-binaries.sh | 1904 | # The variants could be built independently we need to check if | COMMENT |
| LOW | tools/packaging/kata-deploy/binary/src/main.rs | 676 | // Step 1: Check if THIS pod's owning DaemonSet still exists. | COMMENT |
| LOW | tools/packaging/kata-deploy/binary/src/main.rs | 692 | // Step 2: Our DaemonSet is gone (uninstall). Perform instance-specific | COMMENT |
| LOW | tools/packaging/kata-deploy/binary/src/main.rs | 724 | // Step 3: Check if ANY other kata-deploy DaemonSets still exist. | COMMENT |
| LOW | src/tools/agent-ctl/src/image.rs | 43 | // Step 1: Use skopeo to copy the image to a local OCI directory with explicit tag | COMMENT |
| LOW | src/tools/agent-ctl/src/image.rs | 63 | // Step 2: Use umoci to unpack the OCI image into a bundle | COMMENT |
| LOW⚡ | …rs/crates/resource/src/cdi_devices/container_device.rs | 47 | // Step 1: Extract all devices and filter out devices without device_info for vfio_devices | COMMENT |
| LOW⚡ | …rs/crates/resource/src/cdi_devices/container_device.rs | 57 | // Step 2: Group devices by vendor_id-class_id | COMMENT |
| LOW | …rs/crates/resource/src/cdi_devices/container_device.rs | 73 | // Step 3: Sort devices within each group by guest_pcipath | COMMENT |
| LOW⚡ | src/libs/kata-types/src/dmverity.rs | 247 | // Step 0: Remove stale device if it already exists | COMMENT |
| LOW⚡ | src/libs/kata-types/src/dmverity.rs | 253 | // Step 1: Create device as read-only | COMMENT |
| LOW⚡ | src/libs/kata-types/src/dmverity.rs | 302 | // Step 2: Load table and resume (activate) | COMMENT |
| LOW⚡ | src/libs/kata-types/src/dmverity.rs | 306 | // Step 3: Ensure the device node exists under /dev/mapper/. | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | tools/packaging/scripts/gen_versions_txt.sh | 161 | # (ie, 1.8.0-alpha0 may live on stable-1.8 as well as master: we'd just use master in this case) | COMMENT |
| LOW | tests/gha-run-k8s-common.sh | 267 | # Due to this issue, let's simply use a different port (:9999) and | COMMENT |
| LOW | tests/integration/kubernetes/lib.sh | 14 | # Delete all pods if any exist, otherwise just return | COMMENT |
| LOW | tests/stability/soak_parallel_rm.sh | 43 | # then just set this to a very large number | COMMENT |
| MEDIUM | …ime-rs/crates/resource/src/coco_data/initdata_block.rs | 235 | // Essentially, it unwraps the layered writers (compression, buffering) to get back the original temporary file (tem | COMMENT |
| MEDIUM | src/runtime/virtcontainers/container_test.go | 340 | // Create container to utilize this mount/secret | COMMENT |
| MEDIUM | src/runtime/virtcontainers/kata_agent.go | 2104 | // given container and will update the OCI spec to utilize this mount point as the new source for the | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | …helm-chart/kata-deploy/try-kata-nvidia-gpu.values.yaml | 4 | # Usage: | COMMENT |
| LOW | …deploy/helm-chart/kata-deploy/try-kata-tee.values.yaml | 4 | # Usage: | COMMENT |
| LOW | …ckaging/kata-deploy/helm-chart/kata-deploy/values.yaml | 780 | # Usage: | COMMENT |
| LOW | tools/packaging/scripts/populate-oras-tarball-cache.sh | 15 | # Usage: | COMMENT |
| LOW | tests/common.bash | 136 | # Usage: | COMMENT |
| LOW | tests/common.bash | 1412 | # Example usage: | COMMENT |
| LOW | tests/common.bash | 1463 | # Example usage: | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| HIGH | …gonball/dbs_virtio_devices/src/vsock/csm/connection.rs | 60 | // is undefined. In this implementation, we forcefully terminate the | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | tools/testing/gatekeeper/jobs.py | 253 | def get_jobs_for_workflow_run(self, run_id): | CODE |
| LOW | tools/testing/gatekeeper/jobs.py | 259 | def check_workflow_runs_status(self, attempt): | CODE |
| LOW | tests/integration/cri-containerd/integration-tests.sh | 414 | function TestContainerMemoryUpdate() { | CODE |
| LOW | tests/integration/cri-containerd/integration-tests.sh | 446 | function PrepareContainerMemoryUpdate() { | CODE |
| LOW | tests/integration/cri-containerd/integration-tests.sh | 664 | function startDeviceCgroupContainers() { | CODE |
| LOW | tests/integration/cri-containerd/integration-tests.sh | 719 | function stopDeviceCgroupContainers() { | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | docs/use-cases/NVIDIA-GPU-passthrough-and-Kata-QEMU.md | 176 | #### UVM orchestration flow | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | .github/workflows/codeql.yml | 58 | # If you are analyzing a compiled language, you can modify the 'build-mode' for that language to customize how | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | src/dragonball/src/device_manager/blk_dev_mgr.rs | 1012 | let dummy_id = String::from("1"); | CODE |
| LOW | src/dragonball/src/device_manager/blk_dev_mgr.rs | 1021 | drive_id: dummy_id.clone(), | CODE |
| LOW | src/dragonball/src/device_manager/blk_dev_mgr.rs | 1067 | .get_index_of_drive_id(&dummy_id) | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | tools/testing/gatekeeper/skips.py | 76 | CODE |