java-review swarm field test 2026-07-11 · updated 07-22

Does it catch real bugs — without crying wolf?

Seven real Apache & Halo pull requests the reviewer had never seen. Two with a maintainer-fixed bug reintroduced; five reviewed exactly as submitted. Every finding was attacked by an adversarial verifier before it was allowed to count.

628 / 938 known bugs caught
both adversarially confirmed
0 false positives across
5 already-reviewed PRs
◆

Mined regression pairs

Eight hundred eighty pull requests that introduced a bug a maintainer later fixed — replayed against the introducing PR, exactly as it stood. The world chose these bugs; the projects' own maintainers adjudicated them. Strictly out‑of‑distribution: real code, real defects, ground truth we didn't write.

628 / 938 maintainer-fixed regressions caught
at the PR that introduced them
0 fabricated findings
across all eight hundred eighty-seven runs

Finder model is disclosed per row: batches 1–7 Opus 4.8 n=1–70: 44/70 (63%); batches 8–90 Grok 4.5 n=71–890: 537/817 (66%); batches 91–92 Opus 5 n=891–941: 47/51 (92%). Campaign total 628/938 (67%). Treat mixed-model aggregates carefully — and treat that 92% as n=51, not as a rate: it is one model on 51 pairs, the newest and smallest stratum here, and it is not comparable to the Grok window without controlling for which pairs were mined. Same-pair re-run of those 51 on Grok 4.5: 44/51 (86%) — same briefs, same fixtures, blind finders-only; 3 HIT behind Opus 5 on this set (evidence).

Detection by specialty

Campaign 628/938 (67%) after batches 91–92, the first pairs scored on Opus 5 (47/51 HIT). A same-pair Grok 4.5 re-run of that cohort scored 44/51 (86%) — not a campaign re-bank; a confound-controlled model comparison. The four banked misses are the informative part. In three of them the reviewer read the changed code and affirmatively cleared it — solr-529 as “a faithful port”, and in pulsar-23062 all three reviewers cleared the very executor change that arms the deadlock, reading “it still runs on the same executor” as reassurance. In springframework-6e97587 a reviewer named the exact defect in its own coverage attestation and triaged it away as low severity. pulsar-23901 is additionally a weak test — the flawed pattern predates the change under review — and is discounted rather than counted against capability. Batch 91 was a clean 10/10, which fires the campaign’s perfect-decade gate: a blind re-score of 5 of those 10 — ground truth and raw finder output only, verdict and rationale stripped — agreed 5/5. One proposed pair was discarded as a duplicate of an already-mined PR and is not counted. Prior: batch 90 post-restructure Grok smoke 5/10, 85–89 was 23/50. Strict quote-backed target recall; scoring per pair. Recent hard-gate window (batches 80–89): 42/100 (42%) — residual public gold under Layer B; do not read the drop from a high decade (e.g. 69–73 at 82%) as a silent product regression without the miss postmortem (adjacent-target 39/58 MISSes, empty 12/58).

correctness158/236
concurrency137/198
security117/166
data107/162
performance109/176
total628/938

Recall by surface-directness

Grade is how pointable the introduced bug is on the diff: A a single wrong line, B visible after reading one helper, C cross‑file or subtle. Recall tracks it — the honest read on the headline: the aggregate drifts down as we deliberately mine harder, subtler pairs, not because detection got worse. The residual hard case is a grade‑A bug whose cost is real but emergent — a fold, a downstream fast‑path, an uncached branch — visible only when you model the caller.

A · pointable494/704
B · one helper131/225
C · subtle3/9
total628/938

Recall by attribution stratum

A mined pair is only a fair test if the defect the fixing PR repairs is visible from the introducing diff. A mechanical screen (no model call) compares the two diffs line by line across every pair and sorts each by how the fix relates to what the intro actually wrote. 28.2% of the misses are not clean in‑diff tests, against 16.2% of the hits — so part of the headline is test validity rather than capability, and the honest read is the split below, not one number. Only 3 pairs were provably invalid (one fix branched before its intro merged; one bank named the same PR as both intro and fix; one fix merged seven weeks before its intro) — those were removed from both sides, taking the corpus from 890 to 887 and the headline from 65.4% to 65.5%. That is the point: the audit buys a clearer picture, not a better percentage. Nothing else was deleted — arms‑sibling and unattributed pairs are harder tests, not broken ones, so they stay and are reported as strata. Method, per‑lane composition, and the wrong‑ref defect it caught: pair‑validity audit.

in-diff · defect on the shown surface524/749
arms-sibling · breakage in an untouched file49/87
unattributed · fix repairs nothing the intro wrote48/95
fair-test subset (in-diff)524/749
unscreened / unresolvable ref7
Show Showing 938 pairs
Pair  introduced → fixedSpecialtyGradeModelResultWhat the bug was
apache/pulsar#24784→#26045correctnessAOpus 4.8HIT under-rated LOWPulsarClientImpl.shutdown() closes addressResolver + dnsResolverGroupLocalInstance UNGUARDED; a throw…
apache/pulsar#21798→#24512correctnessAOpus 4.8HIT HIGHPersistentTopicsBase.internalGetDelayedDeliveryPolicies (introducing tree line 908) builds a…
apache/pulsar#24533→#24593securityBOpus 4.8HIT under-rated LOWIn ServerCnx.isTopicOperationAllowed (introducing tree lines 480-482), #24533 replaced a two-part proxy…
apache/pulsar#25352→#25460concurrencyCOpus 4.8MISS The async-ification in #25352 DELAYS the producer-creation callbacks. When a client-side createProducer…
netty/netty#12709→#12762correctnessCOpus 4.8HIT HIGH#12709 removed the generic post-encode release that MessageToMessageEncoder.write() provided.…
apache/pulsar#22908→#22966concurrencyBOpus 4.8HIT HIGHConcurrentRoaringBitSet's read methods (get, nextSetBit, ...) use rwLock.tryOptimisticRead() and call…
apache/pulsar#25984→#26080dataCOpus 4.8MISS off-target (found deeper)THE RECALL TARGET (what #26080 fixed): nextDeliveryTime() falls through to…
apache/pulsar#25087→#25110concurrencyAOpus 4.8HIT MEDIUM#25087 replaced an in-memory-only cursor-tracking reset with a real…
netty/netty#15165→#15391correctnessAOpus 4.8HIT CRITICALThe added AdaptiveByteBuf.setCharSequence override guards with checkIndex(index, sequence.length()) — a…
apache/pulsar#20990→#23796correctnessAOpus 4.8MISS target miss; defect-level hit #21126#20990's added conditional runs removePendingAcks (whose unblock check reads the unacked count) BEFORE…
apache/pulsar#22411→#25434concurrencyAOpus 4.8MISS #22411 MOVED the optimistic-concurrency version snapshot 'final Stat lastCursorLedgerStat =…
netty/netty#8939→#10247correctnessBOpus 4.8MISS addFlattenedComponents does 'final CompositeByteBuf from = (CompositeByteBuf) buffer;' and reads from's…
netty/netty#17007→#17074performanceAOpus 4.8MISS weak target#17007's cached(String) does TWO passes over the input: (1) new AsciiString(string) internally converts…
elastic/elasticsearch#105718→#136649correctnessBOpus 4.8MISS With allow_duplicates:false, appending a value that is already present (a no-op de-dup) still UPCASTS…
apache/pulsar#16234→#18816correctnessCOpus 4.8MISS nearconvertFrom() drops configuration data: it builds a NEW empty Properties from unknown DECLARED FIELDS…
apache/pulsar#22521→#22576correctnessBOpus 4.8HIT under-rated LOWThe hand-rolled Deflater loop + gzip framing in GzipByteBufferWriter mishandles buffer-full / finish…
apache/pulsar#22789→#23903correctnessAOpus 4.8HIT HIGHgetValue() guards the get() path with a REFERENCE comparison `if (valueWrapper.getKey() != key) return…
apache/pulsar#20158→#20170correctnessAOpus 4.8HIT HIGH#20158's parse paths call ledgerEntry.getEntryBuffer() (returns the pooled direct ByteBuf, transfers no…
elastic/elasticsearch#152748→#153584correctnessAOpus 4.8HIT MEDIUMMath.clamp(value, min, max) requires min <= max; here min=4096, max=n, so when the vector count n <…
netty/netty#15533→#15630correctnessBOpus 4.8HIT HIGHReflecting BC SSLEngine ALPN methods against engine.getClass() (BouncyCastle's package-private impl,…
apache/druid#17170→#19484correctnessAOpus 4.8HIT HIGHSinkQuerySegmentWalker.java line ~538: switch(metricName) over three cases has NO break statements =>…
apache/pulsar#13157→#13463securityAOpus 4.8HIT HIGHThe added validateNamespacePolicyOperation(...) is NOT equivalent to validateSuperUserAccess(): under…
elastic/elasticsearch#138489→#139510concurrencyBOpus 4.8HIT HIGHThe live IndexService MapperService and the cluster-state IndexMetadata are updated NON-ATOMICALLY as…
quarkusio/quarkus#48153→#48393securityBOpus 4.8HIT HIGHDefaultTokenStateManager.java:84 appends the raw space-delimited access-token scope into the session…
micronaut-projects/micronaut-core#7635→#8156concurrencyAOpus 4.8HIT HIGHConversionService.SHARED is a static final JVM-global shared by every bean context. reset()…
apache/iceberg#15297→#15726dataBOpus 4.8HIT HIGHgetProjectedIds() omits list/map CONTAINER field IDs (only element/key/value IDs are added), whereas…
apache/druid#17394→#17403concurrencyBOpus 4.8HIT CRITICALworkerExec is reused as the RPC connectExec. ServiceClientImpl completes response/service-location…
apache/hbase#3230→#3775correctnessBOpus 4.8MISS HbckChore.java:226 -- relying on the in-memory RegionState alone. RegionState.isSplit() == (state ==…
apache/ozone#9322→#9384dataBOpus 4.8MISS RDBStore.close() calls flushDB() unconditionally, but the store can be opened READ-ONLY; flushing a…
hibernate/hibernate-orm#3590→#5261dataBOpus 4.8MISS The new OneToOneType.isDirty is correct for simple ids but throws IllegalArgumentException for a…
apache/kafka#20334→#22269correctnessBOpus 4.8HIT HIGHconnect/runtime/.../rest/util/SSLUtils.java configureSslContextFactoryAlgorithms: the removed `if…
apache/camel#22490→#22801securityBOpus 4.8MISS shipped v0.38.4 sliceNettyConverter.java + the DEFAULT_DESERIALIZATION_FILTER constant =…
apache/iceberg#15150→#16521dataBOpus 4.8MISS SerializableTable.java new sortOrders(): `sortOrderAsJsonMap.forEach((id, json) -> sortOrders.put(id,…
apache/flink#27861→#28605correctnessBOpus 4.8HIT HIGHLocalInputChannel.checkpointStarted() was changed from startPersisting(id, Collections.emptyList()) to…
apache/hadoop#6748→#6772correctnessBOpus 4.8HIT HIGHPendingDataNodeMessages.removeQueuedBlock() (line ~111-133) obtains its queue via getBlockQueue(block)…
apache/lucene#15722→#16156correctnessAOpus 4.8HIT MEDIUMOffHeapFloatVectorValues.prefetch (line ~100): loops for(i=0; i<numOrds; i++) reading…
apache/iceberg#13507→#16695performanceBOpus 4.8HIT HIGHTasks.run() with a non-null service takes runParallel: it submits the single task and then blocks the…
eclipse/jetty.project#14400→#14524correctnessBOpus 4.8HIT HIGHImmutableHttpFields/MutableHttpFields newQuotedCSV/newQuotedQualityCSV overrides call…
opensearch-project/OpenSearch#20921→#21830correctnessBOpus 4.8HIT HIGHNonClosingReaderWrapper (FilterDirectoryReader) overrides only doClose() (no-op for the delegate) but…
opensearch-project/OpenSearch#21305→#21456correctnessCOpus 4.8MISS cross-fileThe added `listener.onResponse(null)` completes the replica listener with SUCCESS on the closed-primary…
apache/bookkeeper#2701→#4196correctnessAOpus 4.8HIT MEDIUMDigestManager.computeDigestAndPackageForSending and ByteBufList.add/prepend compute `final ByteBuf…
FasterXML/jackson-databind#5012→#5099correctnessAOpus 4.8HIT HIGHObjectNode.with(String) create path was rewritten from `_children.put(exprOrProperty, result); return…
FasterXML/jackson-databind#4008→#4230correctnessAOpus 4.8HIT HIGHThe three LIST-returning finders (findValues, findValuesAsText, findParents) were rewritten to…
apache/cassandra#3641→#4096performanceAOpus 4.8HIT under-rated LOWparseAndPrepare unconditionally runs `res.pstmntSize = measurePstmnt(res)` (QueryProcessor.java:475),…
apache/calcite#688→#747performanceAOpus 4.8MISS simplifyAndTerms/simplifyOrTerms (RexSimplify.java) loop over every term and for each perform…
apache/solr#3851→#4176concurrencyBOpus 4.8MISS triggerCollectionRefresh dedups via collectionRefreshes.computeIfAbsent(key, ...). There is a race…
apache/solr#1501→#3477concurrencyBOpus 4.8HIT HIGHperSegmentFingerprintCache is a shared field on SolrCore read/written by getIndexFingerprint…
apache/paimon#7175→#8623dataAOpus 4.8HIT HIGHFor DecimalType precision > 18, ParquetFilters builds the predicate literal via…
apache/paimon#2572→#7906dataAOpus 4.8HIT under-rated MEDIUMFieldProductAgg.agg() computes the running product with unchecked arithmetic for…
debezium/debezium#7065→#7606dataAOpus 4.8HIT CRITICALRowIdCodec.encode() loops over all 18 base-64 ROWID chars doing `result = (result << 6) | value` = 18*6…
elastic/elasticsearch#87735→#88340performanceAOpus 4.8MISS evidence-bar suppressed as constant-factortierNodesPresent replaced an explicit `for (DiscoveryNode n : nodes) if (allocationAllowed(...)) return…
apache/hadoop#1932→#3411performanceBOpus 4.8MISS shipped v0.38.5 sliceensureCapacity sizes the backing array to EXACTLY `capacity` (the immediate logical need) with no…
apache/kafka#15105→#15393performanceBOpus 4.8HIT HIGH (data+corr caught; perf lane missed WAL drop)DirectDBAccessor.put/delete/deleteRange use the WriteOptions-less RocksDB overloads, so RocksDB's…
apache/lucene#13199→#13498performanceAOpus 4.8MISS shipped v0.38.5 sliceThe PointTree is materialized eagerly in the NumericLeafComparator constructor for every comparator x…
netty/netty#14127→#14144securityAOpus 4.8HIT HIGHSSLEngine.getSSLParameters() returns a defensive COPY; mutating it and discarding it is a no-op, so for…
apache/httpcomponents-client#643→#848securityBOpus 4.8HIT HIGHDropping scheme from the same-authority check means an https->http downgrade to the same host and…
apache/pulsar#25564→#25635securityAOpus 4.8HIT CRITICALhandleCommandScalableTopicSubscribe registers a consumer and handleCommandScalableTopicLookup resolves…
apache/avro#3126→#3537dataAOpus 4.8HIT CRITICALArrays.compare(byte[]...) compares elements SIGNED (Byte.compare), but the old code and the Avro spec…
apache/orc#581→#672dataAOpus 4.8HIT HIGHparseName treats '.' as a nested-field separator and interprets backtick-quoting, but the writer stores…
apache/pulsar#26025→#26132concurrencyCOpus 4.8HIT MEDIUM (grade-C on-family)The reader-close (AlreadyClosedException) branch in readMorePoliciesAsync stayed on the namespace-keyed…
apache/lucene#13408→#14543performanceBOpus 4.8MISS leadCost overwrite buried in a 27-file refactorFor a conjunction, leadCost must be the min cost() over ALL required clauses (MUST+FILTER) since…
trinodb/trino#15369→#22039performanceBOpus 4.8HIT HIGH (O(n^2) LinkedList.contains hot loop)scheduleRequestIfNecessary() runs on hot paths (pollPage() per page consumed, requestComplete() per…
apache/druid#2753→#2841performanceBOpus 4.8MISS second-order: reorder defeats ConciseSet.add fast-pathConciseSet.add() has a fast append path taken only when the added element is greater than the current…
prestodb/presto#21236→#22661performanceAOpus 4.8MISS fold-quadratic immutable rebuild; perf near-miss (adjacent MEDIUM)FilterStatsCalculator folds a large IN (...) list via reduce(), one addDisjunction per element. Because…
apache/cassandraf33267c8→0b6ae26performanceAOpus 4.8MISS assumed-cache: missed uncached 3.0/3.11 isSuper disk readOn 3.0/3.11 (no role-metadata cache), user.isSuper() reads from disk. The new guard evaluates isSuper()…
netty/netty#13233→#13237concurrencyAOpus 4.8MISS BORDERLINE: cleared the cross-thread clobber; 2/3 convergent adjacentCross-thread clobber: an exiting/rescheduling thread's unconditional `executingThread = null` store can…
apache/hbase#7089→#7107concurrencyAOpus 4.8HIT CRITICAL 2/3 blind-convergent (lock-inversion deadlock)flush()/close() are synchronized(this) and call internalFlush(), which blocks on…
apache/parquet-java#3197→#3576correctnessBOpus 4.8HIT MEDIUM (wire-format charset; data lane perceived+deferred)The Variant spec mandates UTF-8; the write path uses StandardCharsets.UTF_8, but the read path decodes…
apache/parquet-java#3202→#3626correctnessBOpus 4.8MISS test-trust masking; convergent adjacent appendFloat overrunDuplicate-key resolution keeps the LAST-written value (greater offset), whose size can differ from the…
keycloak/keycloak#6912→#50486securityBOpus 4.8MISS shipped v0.38.6 sliceaddChild authorizes requireManage on the PARENT (destination) but performs no manage check on the CHILD…
apache/kafka#20097→#21058performanceAGrok 4.5HIT MEDIUM (design; perf+corr CLEARED modernization)MemberAssignmentImpl unmodifiableMap forces assignor deep-clone on every mutation
apache/pinot#9667→#9688performanceAGrok 4.5HIT MEDIUMArrayDeque→LinkedList BFS queue on star-tree hot path
apache/pulsar#23611→#24430performanceAGrok 4.5HIT HIGHgetNumberOfDelayedMessages full stream walk on hot path
quarkusio/quarkus#53885→#55176performanceAGrok 4.5MISS eager getResource declined as cold-path costeager Class.getResource always evaluated as resolveJarPath arg
apache/pulsar#25565→#25618securityAGrok 4.5HIT CRITICALScalableTopics/Segments admin REST missing authz
apache/camel#24180→#24377securityAGrok 4.5HIT HIGH 3/3jail startsWith without path-segment boundary
hazelcast/hazelcast#25509→#25529securityAGrok 4.5MISS adjacent CacheLoadAll underpermission; missed wrong-type targetsWrong permission types ConfigPermission / SemaphorePermission ACTION_READ
apache/kafka#16914→#17078concurrencyAGrok 4.5HIT HIGHCountDownLatch released before setState(RUNNING)
apache/paimon#7295→#7920dataAGrok 4.5HIT CRITICALempty listFileDirs promotes partitions into recursive orphan delete
apache/iceberg#6570→#10069dataAGrok 4.5HIT HIGHe.getMessage().contains NPE skips checkCommitStatus
apache/pinot#15641→#16230performanceAGrok 4.5HIT MEDIUMAdminClient created per offset fetch via try-with-resources in…
apache/pinot#15335→#18905performanceAGrok 4.5HIT HIGHPooledByteBufAllocatorWithLimits creates new PooledByteBufAllocator per ServerChannel instead of…
apache/kafka#12049→#12365performanceAGrok 4.5MISS adjacent ready() allocs; missed time-under-lock + ProducerRecord pintime.milliseconds() under per-partition queue lock in appendNewBatch and AppendCallbacks holds full…
elastic/elasticsearch#148833→#148858performanceAGrok 4.5HIT MEDIUMfindLastRecordBoundary default replaced O(1) reverse newline scan with forward per-record…
keycloak/keycloak#45562→#49590securityAGrok 4.5MISS adjacent hierarchical authz; missed getMembers view-usersOrganizationGroupResource.getMembers missing auth.users().requireQuery / view-users permission check
apache/camel#19324→#23958securityAGrok 4.5HIT HIGH (empty-roles skip; also CRITICAL no signature verify)KeycloakSecurityProcessor only validates token when requiredRoles non-empty; empty defaults accept any…
apache/knox#876→#1039securityAGrok 4.5MISS adjacent cache/secret-query; missed ignored client_idparseFromClientCredentialsFlow ignores client_id; only client_secret/tokenId used so mismatched…
apache/kafka#12397→#13167concurrencyAGrok 4.5HIT HIGHTasks maps dropped Collections.synchronizedSortedMap for plain unsynchronized TreeMap shared…
debezium/debezium#3938→#4298dataAGrok 4.5HIT HIGHLogMinerQueryBuilder PDB SRC_CON_NAME applied to all OPERATION_CODE including START/COMMIT/ROLLBACK so…
elastic/elasticsearch#145376→#153043dataAGrok 4.5MISS adjacent empty-array fidelity; missed per-call context flushFlattenedFieldArrayContext created and flushed per parseCreateField call instead of document-scoped;…
apache/beam#37355→#39310performanceAGrok 4.5HIT MEDIUM (blind re-score 07-22; was self-scored MISS — per-call TypeDescriptor cost named)newByteBuddyInvoker resolves input/output TypeDescriptors before cache lookup on every call including…
elastic/elasticsearch#130857→#138126performanceAGrok 4.5HIT HIGHTransportIndicesStatsAction always calls getSharedRamSizeForShard causing O(N^2) full shard walk even…
apache/knox#1039→#1170securityAGrok 4.5HIT MEDIUM (missing client_id fail-open)validateClientCredentialsFlow skips client_id match when client_id is null; client_secret alone still…
apache/struts#1592→#1690securityBGrok 4.5HIT MEDIUMmethodSpecified=true for wildcard methods makes HttpMethodInterceptor skip class-level…
netty/netty#7800→#17063securityAGrok 4.5HIT HIGH 3/3CorsHandler getForOrigin uses || for null-origin check allowing Origin:null when isNullOriginAllowed is…
apache/kafka#17957→#18053concurrencyAGrok 4.5MISS shipped v0.38.7 sliceSharePartition completes CompletableFuture while holding writeLock in whenComplete (deadlock risk)
hazelcast/hazelcast#20419→#25700concurrencyBGrok 4.5HIT HIGHEventListenerCounter shared by map name only races concurrent create/destroy of same-named IMap (assert…
opensearch-project/OpenSearch#22249→#22358concurrencyAGrok 4.5MISS all 3 CLEARED double-close as intentionalFlightTransportResponse prefetch finally re-reads closed and double-closes Flight stream racing close()
datahub-project/datahub#17206→#18401dataAGrok 4.5HIT HIGHgetLatestAspects sorts keys then batchGet(new HashSet<>(keys)) erases order for FOR UPDATE deadlocks
apache/druid#18589→#18948dataAGrok 4.5MISS found NONE encoding fidelity; missed isNumeric NestedArrayElementCompressedNestedDataComplexColumn.isNumeric returns true for NestedArrayElement fall-through
apache/solr#2363→#2463performanceAGrok 4.5HIT HIGH (forceUpdateCollection on alias)ZkClientClusterStateProvider forceUpdateCollection on every alias request after missing CollectionRef;…
apache/hbase#7477→#8353performanceAGrok 4.5MISS adjacent pool/equals; missed Path ctor hot-path costBlockCacheKey(Path) constructor does path.getParent walks and isHFileArchived on every block read hot…
elastic/elasticsearch#112173→#112480performanceAGrok 4.5MISS shipped v0.38.8 sliceSourceLoader synthetic write calls advanceToDoc on every storedFieldLoader even when empty O(fields)…
lettuce-io/lettuce-core#2961→#3640performanceAGrok 4.5HIT HIGH (per-instance ThreadLocal expunge)SharedLock per-instance ThreadLocal threadWriters leaks under connection pooling causing…
apache/flink#18991→#19398performanceAGrok 4.5HIT MEDIUM (unconditional mailbox latency probe)Unconditional scheduleMailboxMetrics/measureMailboxLatency enqueues mailbox work every ~1s even on…
keycloak/keycloak#47636→#50961securityAGrok 4.5HIT HIGH (SCIM members missing isAdminUser)SCIM group members adder/remover checkRequireManageGroupMembership missing isAdminUser so admin-role…
keycloak/keycloak#25647→#50026securityAGrok 4.5HIT HIGH (SecureRedirectUris skips AUTHORIZATION_REQUEST)SecureRedirectUrisEnforcerExecutor only handles REGISTER/UPDATE/PRE_AUTHORIZATION_REQUEST not…
apache/nifi#10393→#11179securityAGrok 4.5HIT HIGH (registry verify READ-only)Registry client config verification authorized with READ only instead of WRITE plus CS READ via…
apache/struts#1674→#1774securityBGrok 4.5HIT HIGH (Jackson creator bypasses @StrutsParameter)@StrutsParameter enforcement on setter/field path does not cover Jackson creator-bound constructor…
netty/netty#16053→#16767concurrencyAGrok 4.5HIT CRITICAL (BuddyChunk.remainingCapacity freeList drain)BuddyChunk.remainingCapacity drains freeList mutating buddies as side effect of capacity query under…
elastic/elasticsearch#149926→#152838concurrencyAGrok 4.5HIT HIGH (hasNext threshold before rowsRemaining)OptimizedParquetColumnIterator.hasNext checks dynamicThreshold.noFurtherCandidates before serving…
apache/pulsar#24363→#25988concurrencyAGrok 4.5HIT HIGH (updateAndGet null wipe eviction marker)triggerEvictionWhenNeeded updateAndGet returns null for losers which stores null wiping owner…
opensearch-project/OpenSearch#21756→#21771concurrencyAGrok 4.5HIT CRITICAL (SEARCH pool self-deadlock)reduce stage and fragment execution both use SEARCH thread pool causing self-deadlock
apache/bookkeeper#4730→#4830concurrencyBGrok 4.5HIT CRITICAL (async listener + maxReads default deadlock)read-path deadlock from async ChannelFutureListener plus maxReadsInProgressLimit default change
apache/iceberg#12105→#15087dataAGrok 4.5HIT CRITICAL (shreddedFields shadow data loss)local variable shreddedFields shadows instance field causing permanent data loss of unshredded fields
apache/iceberg#13302→#16324dataAGrok 4.5HIT CRITICAL (ListMetadataFiles no table.refresh)ListMetadataFiles never table.refresh so snapshots after open missing from referenced set…
debezium/debezium#6726→#6791dataBGrok 4.5HIT CRITICAL (LOB eventIndex skip drops events)TransactionCommitConsumer eventIndex LOB skip regression DBZ-8060 loses events
apache/hbase#3786→#6308dataAGrok 4.5HIT CRITICAL (BrokenStoreFileCleaner region-close race)BrokenStoreFileCleaner may delete live files during region close race without isAvailable guard
apache/zookeeper#2152→#2254dataBGrok 4.5HIT CRITICAL (processTxn skips committedLog)Learner processTxn path leaves committedLog untouched causing data loss after ZOOKEEPER-4394
keycloak/keycloak#35899→#50451securityBGrok 4.5HIT HIGH (ScopeMapped missing requireMapClientScope)ScopeMappedResource add/delete missing requireMapClientScope after FGAP role scopes shipped
elastic/elasticsearch#150052→#151201performanceBGrok 4.5MISS all 3 cleared megamorphic advanceExact as refactor-neutralmegamorphic advanceExact after #150052; fix reverts/restores monomorphic path
apache/lucene#13221→#13971performanceBGrok 4.5HIT HIGH (competitive int[] disjunction / lost density gate)competitive iterator disjunction cost; fix restores prior competitive path
opensearch-project/OpenSearch#22319→#22335performanceBGrok 4.5HIT HIGH (correctness; continuous throttle via pending overcount)continuous merge throttle; fix reverts #22319
micrometer-metrics/micrometer#4857→#5750performanceAGrok 4.5HIT MEDIUM (remove O(n) under meterMapLock)MeterRegistry.remove scans preFilterIdToMeterMap O(n) under meterMapLock
apache/flink#10358→#10529performanceAGrok 4.5MISS perf cleared bulk-buffer as intentional win; missed alloc regressionStringValue writeString/readString allocates fresh byte[] per string
redis/jedis#4504→#4537performanceAGrok 4.5HIT MEDIUM (TSElement ArrayList thrash on single-value path)TSElement single-value ctor always new ArrayList + List storage
apache/bookkeeper#2962→#3454performanceAGrok 4.5HIT HIGH (correctness; forceWriteMarkerSent per-loop reset)forceWriteMarkerSent declared inside while loop so grouping fails open / excess fsyncs
elastic/elasticsearch#152050→#152433performanceAGrok 4.5HIT MEDIUM (lost TermsSortedDocsProducer + disjunction rebuild)SegmentOrdinalValuesSource null sorted-docs producer + remapSlots every leaf + no parallel collection
hazelcast/hazelcast#6735→#7045performanceAGrok 4.5HIT MEDIUM (Externalizable/Enum serializer path loss)ExternalizableSerializer removed so Externalizable falls to slow default path
apache/flink#6417→#6833performanceBGrok 4.5HIT MEDIUM (per-record hasRemaining/mustCommit)SpanningRecordSerializer per-record hasRemaining/mustCommit checks on hot path
keycloak/keycloak#49344→#50729securityAGrok 4.5HIT HIGH (blank authenticatorAttachment early-return)PolicyVerifier.verifyAuthenticatorAttachment early-returns when attachment blank so policy skipped
keycloak/keycloak#41688→#48729securityAGrok 4.5HIT HIGH (self-signed x5c skips PKIX)verifierFromX5CChain skips PKIX when x5c[0] self-signed (no runtime test gate)
keycloak/keycloak#46811→#47616securityAGrok 4.5HIT HIGH (SCIM groups missing membership authz)SCIM User groups attribute joinGroup/leaveGroup without manage-group-membership authz
keycloak/keycloak#47632→#50567securityAGrok 4.5HIT HIGH (AuthZEN any bearer token)AuthZEN Evaluation API accepts any valid bearer token including user tokens
apache/cxf#3154→#3256securityAGrok 4.5HIT HIGH (correctness; ProxySelector without doPrivileged)ProxyFactory.getSystemProxy calls ProxySelector.getDefault without doPrivileged
apache/dubbo#15352→#16374securityAGrok 4.5HIT HIGH (AuthPolicy.NONE plaintext hang)port-unification TLS detect short-circuits AuthPolicy.NONE plaintext so clients hang
apache/dubbo#11418→#15997securityAGrok 4.5HIT CRITICAL (SecurityContext never cleared on provider thread)ContextHolderAuthenticationResolverFilter sets SecurityContextHolder without clearContext finally
keycloak/keycloak#40526→#49070securityAGrok 4.5HIT MEDIUM (org invitations missing org-scoped authz)Organization invitation endpoints missing org-scoped requireManage checks
apache/flink#10009→#10177performanceBGrok 4.5HIT MEDIUM (createBatch locks empty mailbox)TaskMailboxImpl.hasMail locks even when empty after volatile count removed
apache/ozone#9813→#10692performanceBGrok 4.5HIT HIGH (correctness; 60s wait under bootstrap lock)60s wait under BOOTSTRAP_LOCK after RocksDB 10 upgrade path
apache/pulsar#25038→#26143concurrencyBGrok 4.5HIT MEDIUM (lookup semaphore timeout double-release)lookup semaphore timeout ownership / double-release
quarkusio/quarkus#52715→#52866concurrencyBGrok 4.5HIT HIGH (WorkspaceLoader thenLoad/GAV race)WorkspaceLoader GAV race
apache/pulsar#25625→#25767concurrencyAGrok 4.5HIT HIGH (readEntriesFailed early-return leaves InFlightTask)readEntriesFailed returns early when state!=Started without completing InFlightTask
apache/flink#23988→#26204performanceBGrok 4.5HIT MEDIUM (removeTransientMetrics full-map removeIf)MetricStore.removeTransientMetrics full-map removeIf scan on REST/UI path
redisson/redissone3e3c41→#7221concurrencyAGrok 4.5HIT HIGH (registerMasterEntry under lazyConnectLatch)registerMasterEntry inline on connecting thread under lazyConnectLatch self-deadlock
redisson/redisson2ddc4a→#7206concurrencyAGrok 4.5HIT HIGH (AsyncSemaphore double-increment on cancel)AsyncSemaphore dead-waiter branch increments then falls through to trailing increment (+2)
apache/flink#11687→#12231performanceAGrok 4.5HIT MEDIUM (requestPartitions on every getNextRecord)requestPartitions on every getNextRecord
apache/lucene#13568→#13656performanceBGrok 4.5HIT HIGH (CollectorOwner synchronizedList on every search)CollectorOwner synchronizedList on IndexSearcher.search CollectorManager path
apache/hbase#7993→#8442dataBGrok 4.5HIT CRITICAL (isRedundantDelete visibility-blind)isRedundantDelete visibility-blind on minor compact can resurrect labeled cells
debezium/debezium#7536→#7569dataBGrok 4.5HIT HIGH (deferred offset ignores minCacheScn)deferred txn offset uses only oldestDeferred SCN ignoring minCacheScn
apache/hbase#3359→#6040dataBGrok 4.5HIT HIGH (BackupLogCleaner multi-root min not applied)BackupLogCleaner multi-root min not considered; cleans WALs needed by other root
opensearch-project/OpenSearch#21803→#22281dataAGrok 4.5MISS adjacent get-by-id gaps; missed version-map restore gateversion-map restore gated by persistedCheckpoint < maxSeqNo never true; duplicate rows
debezium/debezium#7415→#7605dataAGrok 4.5HIT HIGH (DATETIME hardcodes millis Timestamp)ZeroDateFallbackConverter hardcodes Timestamp millis for every DATETIME truncating micros
apache/flink#26245→#28762dataBGrok 4.5HIT CRITICAL (ForSt MapState putAll missing null flag)ForStMapState null flag not used by BunchPutRequest buildSerializedValue
apache/iceberg#12979→#17210dataAGrok 4.5HIT HIGH (TableMaintenance UUID uidSuffix breaks savepoint)TableMaintenance uidSuffix defaults UUID.randomUUID so savepoints cannot restore
netty/netty#12898→#17063securityBGrok 4.5HIT CRITICAL (OCSP missing CertID match)OCSP CertID validation defect surface from #12898 (CVE family)
micronaut-projects/micronaut-security#456→CVE-2023-36820securityAGrok 4.5HIT HIGH (OIDC iss||aud short-circuit)OIDC aud validation short-circuits with || so wrong audience can pass
spring-projects/spring-boot996ee243a3→#49885securityAGrok 4.5HIT HIGH (excluding drops withHttpMethod)EndpointRequest.withHttpMethod lost when excluding() rebuilds matcher
apache/camel0c3b02a2e3→#24777securityAGrok 4.5MISS saw insecure=false path; missed no-op without Saxon extensionssecureProcessing no-op without Saxon extensions enabled
netty/netty0b7bf49→#16868securityAGrok 4.5HIT HIGH (plain TM wrap drops hostname verify)plain TrustManager wrap drops hostname verification
apache/ozone#9718→#10747performanceAGrok 4.5MISS perf CLEARED close-path sleep as cold; missed clientCache monitor holdclose() graceful shutdown sleep holds clientCache monitor ≥100ms
elastic/elasticsearch#150240→#151393performanceAGrok 4.5HIT MEDIUMmax_record_size CSV/TSV char-by-char StringBuilder + re-tokenize; NDJSON double-scan
apache/beam#33293→#33575performanceAGrok 4.5HIT MEDIUMparseTableIdentifier try Jackson first forces exception on common non-JSON path
elastic/elasticsearch#150906→#151518performanceAGrok 4.5MISS adjacent float COSINE fallback; missed castShape part-split costPanama bulk byte-vector castShape part-splitting regresses scoring
elastic/elasticsearch#149223→#150276performanceAGrok 4.5MISS ArrayOrder adjacent; missed megamorphic shared read()generic AbstractNumericBlockLoader shared read() megamorphic numeric loaders
apache/druid#12315→#15614performanceAGrok 4.5HIT HIGHgetColumnCapabilities only checks virtualColumns → expression filters skip bitmaps
netty/netty#10267→#10825performanceAGrok 4.5HIT HIGHSizeClasses rewrite broke PoolThreadCache normal-cache indexing (~3×)
apache/flink#16556→#16710performanceAGrok 4.5HIT MEDIUMunconditional throughputCalculationSetup for 0-input-gate sources
quarkusio/quarkus#18110→#18267performanceAGrok 4.5HIT MEDIUMResults.NotFound interface+factories replace NOT_FOUND singleton → alloc thrash
hazelcast/hazelcast#19474→#21323performanceAGrok 4.5MISS CLEARED as intentional local-read opt (sold-as-faster)local map read on cooperative thread via recordStore.fetchEntries
apache/activemq-artemis#1577→#2514performanceAGrok 4.5HIT MEDIUMoffer() always false → create threads instead of reusing idle
apache/maven-resolver#1902→#1937performanceAGrok 4.5HIT MEDIUMsynchronized(versionCache)/WeakInternPool → 2× Quarkus build
apache/hudi#13976→#17477performanceAGrok 4.5HIT HIGHplain coalesce fails to cut Spark DAG for streaming MDT writes
elastic/elasticsearch#134701→#147357performanceAGrok 4.5MISS CLEARED as intentional over-estimate; missed TEXT page-size blowTEXT estimate 50→1024 blows enrich/lookup page size
elastic/elasticsearch#140843→#141980performanceAGrok 4.5HIT HIGHArena.ofConfined 'opt' fails EA → young GC regression
apache/druid#16775→#16928performanceAGrok 4.5HIT HIGHSuperSorter stores writable channels → 1MB/channel waste
apache/beam#15637→#33521performanceBGrok 4.5HIT HIGHGlobalWindows GBK preempts memory-sensitive path → OOM risk
netty/netty#10226→#10623performanceBGrok 4.5MISS treated as correctness win; missed offer-buf allocator costmultipart uses offer-buf allocator → direct buffer 100× slow
trinodb/trino#26225→#30245performanceAGrok 4.5HIT HIGHaddBytes adds delta to rounded currentBytes → memory accounting drift
redis/jedis#3848→#4205performanceAGrok 4.5HIT HIGHreplicaSlots never cleared on reset → unbounded heap under topology refresh
apache/knox#1175→#1176securityAGrok 4.5HIT HIGHcipherSuites used instead of tlsVersions for SSL protocols config
keycloak/keycloak#49522→#50537securityAGrok 4.5HIT HIGHassert-only realm ownership check no-op without -ea
keycloak/keycloak#8243→#50565securityAGrok 4.5HIT HIGHJWE fallthrough accepts unsigned JSON when signature required (CVE-2026-9793)
keycloak/keycloak#49420→#50650securityAGrok 4.5HIT HIGHpre-auth UsernameScopeType user-store lookup enables username enum
apache/hive#1791→#6534securityAGrok 4.5HIT CRITICALinverted !MessageDigest.isEqual in SAML signatureMatches → authn bypass
datahub-project/datahub#9592→#16279securityAGrok 4.5HIT HIGHopen redirect: scheme/authority check misses ///host
datahub-project/datahub#14707→#18140securityAGrok 4.5HIT HIGHINFO logs full headers including bearer JWT
apache/activemq-artemis#62→#6275securityAGrok 4.5MISS adjacent MQTT authz; missed QoS2 PubRec-before-sendQoS2 PubRec recorded before send → unauthorized retry ignored
prestodb/presto#3799→#28031securityAGrok 4.5HIT HIGHInitializingSystemAccessControl only overrides few SPI methods → allow-all during startup
keycloak/keycloak#7412→#49512securityAGrok 4.5HIT MEDIUMCORS Allow-Origin from unverified JWT azp (UMA) CVE-2026-37977
keycloak/keycloak#10603→#50910securityAGrok 4.5MISS rotated-secret export/JWT gaps; missed feature-off still accepts rotatedrotated client secret still valid when CLIENT_SECRET_ROTATION disabled
keycloak/keycloak#38322→#50824securityAGrok 4.5HIT HIGHFGAP partial-eval drops per-child canView on parent /children CVE-2026-14615
apache/struts#832→#1681securityAGrok 4.5HIT HIGHcookie channel bypasses @StrutsParameter/requireAnnotations
keycloak/keycloak#44600→#50374securityAGrok 4.5MISS jwks flag/use-filter; missed HMAC algorithm confusionJWT Authorization Grant algorithm confusion via HMAC in public-key loader
hazelcast/hazelcast#5091→#25965securityAGrok 4.5HIT HIGHMapPermission instead of ReplicatedMapPermission on addEntryListener
redisson/redisson#7032→#7162securityAGrok 4.5HIT HIGHpassword-masking toString used for cluster slave addresses → WRONGPASS
eclipse/jetty.project#14859→#15115securityAGrok 4.5MISS treated as de-alias fix; missed LoaderHiding dropbase-resource re-materialization drops LoaderHidingResource path hide
apache/kafka#10579→#17492concurrencyAGrok 4.5HIT CRITICALclose() holds writeLock then join()s init thread needing same lock → deadlock
netty/netty#14818→#17087concurrencyAGrok 4.5HIT HIGHIoUring multishot cancel clears readPending before re-schedule → permanent stall
apache/hbase#5256→#7886concurrencyAGrok 4.5HIT HIGHFlushRegionProcedure execute/complete race on unsync dispatched/succ
apache/hbase#4115→#7084concurrencyAGrok 4.5HIT HIGHsnapshot shared table lock + holdLock deadlocks with Enable exclusive
apache/hbase#4803→#7077concurrencyBGrok 4.5HIT HIGHglobal queue cleanup helper never wired into completionCleanup → hang
apache/hbase#7282→#7401concurrencyAGrok 4.5HIT HIGHQuotaCache ConcurrentHashMap→HashMap data race
opensearch-project/OpenSearch#19403→#22244concurrencyAGrok 4.5HIT HIGHremoved synchronized from FlightServerChannel.close() → double-close race
apache/flink#23180→#23296concurrencyAGrok 4.5HIT HIGHclose vs request race on collect sink socket
apache/pulsar#25581→#25589concurrencyAGrok 4.5HIT HIGHexpire path decrements unacked while redeliver is non-atomic
quarkusio/quarkus#34855→#55041concurrencyBGrok 4.5HIT HIGHgRPC @RunOnVirtualThread half-close before message
prestodb/presto#23257→#27597concurrencyAGrok 4.5MISS pruneFinished/expireQueue; missed queryScheduler.set(null) racepruneFinishedQueryInfo sets queryScheduler null without abort → race/leak
apache/kafka#20403→#22590dataAGrok 4.5MISS init commitNeeded; missed getStateStore context wipegetStateStore unconditionally resets live ProcessorRecordContext → timestamps wiped
apache/iceberg#6962→#16435dataAGrok 4.5HIT HIGHINT96 dict decode setLong(idx) uses row index as byte offset → corruption
apache/iceberg#14297→#17002dataAGrok 4.5HIT HIGHVariant decimal shredding hardcodes .length(16) vs decimalRequiredBytes
apache/kafka#22625→#22710dataAGrok 4.5HIT CRITICALtxn buffer stages all CFs into pendingWrites → offset/Position leaks into data iteration
opensearch-project/OpenSearch#18536→#20284dataAGrok 4.5HIT HIGHsnapshot restore breaks for index-sort (parent field missing on prune)
apache/pinot#18814→#18940dataAGrok 4.5HIT HIGHepoch strings via strict Long.parseLong wrong codec/parse
apache/iceberg#12836→#17039dataAGrok 4.5HIT CRITICALrow lineage uses fileSequenceNumber not dataSequenceNumber
apache/hudi#13543→#19237dataAGrok 4.5HIT HIGHcheckpoint serializes all-null write-metadata → failover data loss
opensearch-project/OpenSearch#20551→#22099dataBGrok 4.5HIT HIGHsegrep retry leaves replica behind (achieved vs target ckp)
apache/pinot#16991→#17751dataAGrok 4.5HIT HIGHhybrid time-boundary filters not re-optimized after attach
apache/accumulo#5416→#5548dataAGrok 4.5HIT CRITICALmigration cleanup fetches PREV_ROW+MIGRATION but not LOCATION → null location
trinodb/trino#29643→#29877dataAGrok 4.5HIT HIGHflatHash equality-delete channel map misaligned with metadata columns
elastic/elasticsearch#151021→#151914performanceAGrok 4.5MISS MEDIUMArrayOrderInlineNull always constructed before maxValue≤1 check; skipped OptionalColumnAtATimeReader…
elastic/elasticsearch#86922→#87407performanceAGrok 4.5MISS HIGHRemoved Netty4WriteThrottlingHandler from HTTP pipeline; lost lower-level write throttling…
elastic/elasticsearch#149176→#149341performanceAGrok 4.5HIT HIGHDefault schema resolution FIRST_FILE_WINS→UNION_BY_NAME bypassed schema cache on multi-file globs (~34×)
apache/flink#25551→#25887performanceAGrok 4.5MISS HIGHConsumedSubpartitionContext.build O(n) iterates all partitions on scheduler hot path
apache/kafka#21897→#22199performanceAGrok 4.5HIT HIGHcollectFetch always waits on reconciliationCheckFuture even when not reconciling
netty/netty#14704→#14711performanceAGrok 4.5HIT HIGHprocessOneNow linear-scans completion array on hot write path (10-15% drop; sold-as-safer)
apache/kafka#19589→#20354performanceAGrok 4.5HIT HIGHObserver poll Math.min with expired updateVoterSet timer → busy-spin Raft client
apache/kafka#20175→#21027performanceAGrok 4.5HIT MEDIUMPer-handler LoggerFactory.getLogger(canonicalName) CPU cost on share-group persister path
apache/beam#31805→#31960performanceAGrok 4.5HIT HIGHDuplicate getTableToExtract lineage call starts extra BQ query job on export read
spring-projects/spring-framework12dd758→#36293performanceAGrok 4.5MISS MEDIUMConcurrentReferenceHashMap.compute* always locks even for present read-only keys
apache/hive#1876→#4005performanceAGrok 4.5HIT HIGHMapredContext.createDummy on every GenericUDF initialize bloated query compilation
apache/lucene#672→#12072performanceAGrok 4.5MISS HIGHrewriteNoScoring re-enters ConstantScoreQuery.rewrite → exponential nested Boolean rewrite…
apache/pinot#10528→#15878performanceAGrok 4.5HIT MEDIUMByteBufferUtil setAccessible(true) on every newDirectByteBuffer instead of once
elastic/elasticsearch#140475→#141229performanceAGrok 4.5HIT MEDIUMTime-series partitioner many fixed slices on high-CPU → scheduling overhead (sold-as-faster; full…
google/guava#8258→#8545performanceAGrok 4.5MISS MEDIUMClosingFuture logging/close made closingFutureToString() eager instead of lazy
apache/logging-log4j2#2691→#3123performanceBGrok 4.5HIT HIGHPattern Layout stack rewrite made %xEx extended stack rendering far slower
apache/druid#15757→#19518performanceBGrok 4.5MISS HIGHPer-hydrant SpecificSegmentQueryRunner multiplies Thread.setName cost 50–200×
apache/ignite2d69600→#11848performanceAGrok 4.5HIT MEDIUMSQL plan history records plans synchronously on H2/Calcite query paths
keycloak/keycloak#6093→#49089securityAGrok 4.5HIT HIGHAccount resources API never checks userManagedAccessAllowed (UMA config theater)
keycloak/keycloak#36880→#50780securityAGrok 4.5HIT HIGHFGAP v2 client-scope assign lacks manage-on-scope (CVE-2026-14614)
keycloak/keycloak#8589→#49474securityAGrok 4.5HIT HIGHreject-ropc-grant policy bypass when conditions fail to resolve client (CVE-2026-9792)
keycloak/keycloak#7286→#48715securityAGrok 4.5HIT HIGHVersioned Account API path lacks checkAccountApiEnabled (CVE-2026-7500)
netty/netty#14358→#16931securityAGrok 4.5HIT HIGHReferenceCountedOpenSslContext hard-codes startTls=false; SslContextBuilder.startTls(true) no-op
hazelcast/hazelcast#25477→#26074securityBGrok 4.5HIT CRITICALUpdatingEntryProcessor serializes Subject; client can tamper ExpressionEvalContext for GET_DDL
apache/ranger8c2363a→#1067securityAGrok 4.5HIT HIGHGDS secure download uses weaker isValidateHttpsAuthentication than sibling secure downloads
redisson/redisson2570af5→#7243securityAGrok 4.5HIT HIGHConfig endpoint password URL rebuild drops ACL username → WRONGPASS after topology discovery
undertow-io/undertow#859→#1943securityAGrok 4.5HIT HIGHAJP_ALLOWED_REQUEST_ATTRIBUTES_PATTERN not applied in setUndertowOptions (config theater)
spring-projects/spring-security#16574→462e38c0e3securityAGrok 4.5HIT HIGHDPoP jkt uses PublicKey.getEncoded digest instead of JWK SHA-256 thumbprint (RFC 9449)
apache/ozone#8875→#10753securityAGrok 4.5MISS HIGHLifecycle set/delete used ACLType.ALL; wrong under Ranger
opensearch-project/OpenSearch#21660→#21917securityBGrok 4.5MISS HIGHanalytics executeWithProfile bypasses SecurityFilter/index permission path
apache/zookeeper#2173→#2303securityBGrok 4.5MISS HIGHssl.clientHostnameVerification ignored when ssl.authProvider set (hardcoded false)
apache/kafka#9695→#9887concurrencyAGrok 4.5HIT HIGHcreateAndAddStreamThread outside changeThreadCount → duplicate StreamThread index
netty/netty#14334→#14495concurrencyAGrok 4.5HIT HIGHAdaptivePoolingAllocator free/offerToQueue TOCTOU → chunk leak
apache/pulsar#23761→#23853concurrencyAGrok 4.5MISS HIGHEarly closeAndClearPendingMessages races reconnect/resend of recycled messages
apache/pulsar#14078→#15366concurrencyBGrok 4.5MISS HIGHProxy close during outbound connect leaks connections (port exhaustion)
apache/flink#25732→#26053concurrencyAGrok 4.5MISS HIGHForSt close joins shared background threads used by other instances
opensearch-project/OpenSearch#18754→#20918concurrencyAGrok 4.5HIT HIGHasyncLoadIndexInput unconditional decRef after remove races re-insert
netty/netty#15369→#15743concurrencyAGrok 4.5HIT HIGHReturnChunkEvent static INSTANCE wrong type → JFR class-init deadlock
apache/pulsar#25573→#25778concurrencyAGrok 4.5HIT HIGHeagerAttachInitialAsync vs onLayoutChange exclusive claim race
elastic/elasticsearch#152771→#153074concurrencyBGrok 4.5HIT HIGHSingle esql_external_io pool for drain+parse + POISON readiness → deadlock
opensearch-project/OpenSearch#19958→#22515dataAGrok 4.5HIT HIGHparseV1Mappings complete field replacement broke multi-template deep merge
apache/iceberg#15475→#17194dataAGrok 4.5HIT CRITICALAvroToRowDataConverters microsecond→nano multiplies by 1e6 not 1000
apache/pinot#10891→#18952dataAGrok 4.5HIT HIGHReversed ByteArray.compare for raw BYTES min/max metadata
apache/iceberg#12227→#16501dataAGrok 4.5MISS HIGHNestedField.from copies defaults onto FIXED physical type → castDefault fails for decimals
apache/pinot#16025→#16469dataAGrok 4.5HIT HIGHvar-length dictionary validate rejects BIG_DECIMAL (STRING||BYTES only)
apache/hudi#7620→#8374dataAGrok 4.5HIT HIGHCkpMetadata.bootstrap stopped cleaning checkpoint-meta → stale ckp on JM restart
apache/hudi#9755→#10923dataAGrok 4.5HIT HIGHgetLastClusterCommit only sees completed CLUSTER; ignores pending clustering
apache/iceberg#11220→#11621dataAGrok 4.5MISS MEDIUMTableMetadataParser double-closes stream in try-with-resources
apache/iceberg#10771→#11858dataAGrok 4.5HIT HIGHHiveCatalog.close closes shared FileIO while tables still need it
apache/paimon#4283→#4387dataAGrok 4.5HIT HIGHHive metastore proxy factory only tries first constructor param type → DLF catalog fail
apache/lucene#15021→#15183correctnessAGrok 4.5HIT HIGHbulkScore remainder maxScore uses scores[i+1] instead of scores[i+2] when remaining>2
netty/netty#16844→#17037correctnessAGrok 4.5HIT HIGHHttpContentDecompressor passes maxAllocation as BrotliDecoder input size not output cap
opensearch-project/OpenSearch#18195→#20823correctnessAGrok 4.5HIT HIGHterms-lookup fetch uses unregistered indices.query.max_clause_count stuck at 1024
apache/kafka#22368→#22849correctnessAGrok 4.5HIT HIGHShare-group DLQ stamps records with hiResClockMs (nanoTime) so retention deletes immediately
elastic/elasticsearch#150545→#153312correctnessAGrok 4.5HIT HIGHpointsInMemoryBytes required constructorArg breaks parse of older ShardFieldStats
apache/lucene#15760→#15817correctnessAGrok 4.5HIT HIGHNumericFieldStats.decodeLong only handles width 4/8; HalfFloat etc throw IAE
opensearch-project/OpenSearch#19060→#19273correctnessAGrok 4.5HIT HIGHBooleanFlatteningRewriter flattens must_not of pure must_not collapsing double-negation
netty/netty#13693→#15740correctnessAGrok 4.5HIT HIGHzeroTillAligned uses addr%8 as bytes-to-alignment (wrong for non-aligned addresses)
apache/pulsar#24938→#25037correctnessAGrok 4.5HIT HIGHgetNumberOfEntries current-ledger branch misses toPosition same ledger as LAC with smaller entry
apache/pulsar#15435→#18818correctnessAGrok 4.5HIT HIGHBitRateUnit refactor dropped * nics.size() from getTotalNicLimitWithConfiguration
apache/iceberg#12591→#15752correctnessAGrok 4.5HIT HIGHioBuilder branch of newFileIO silently drops storageCredentials
apache/pinot#16675→#18580correctnessAGrok 4.5HIT HIGHvalidate-only cluster checks wired into shared validateConfig used by create/update
apache/bookkeeper#3597→#3844correctnessAGrok 4.5HIT HIGHsmall-entry ReadResponse path writeBytes copy never rr.release() → ByteBuf leak
apache/maven-resolver#1957→#1980correctnessAGrok 4.5HIT HIGHREPOSITORY_SYSTEM_CALL marker stamped as RequestTrace tip overwriting Artifact data → CCE
apache/ozone#8914→#10592correctnessAGrok 4.5HIT MEDIUMper-datanode getBlock loop ignores loop variable; all replicas report same blockData
apache/camel#14062→#24859correctnessAGrok 4.5MISS HIGHmultipart stream state.index=1 reset + maxRead not reset → orphaned parts / silent body truncation
apache/bookkeeper#3837→#3884correctnessAGrok 4.5HIT CRITICALgroup-flush add responses never flush when writeDataToJournal is false → client timeouts
quarkusio/quarkus#49579→#50426correctnessAGrok 4.5HIT HIGHisProxiable wrongly excludes abstract classes with !isAbstract → lazy proxy break
hibernate/hibernate-orm#10530→#13065correctnessAGrok 4.5HIT HIGHnull-discriminator subclass CHECK uses 'is' instead of 'is not' → inverted constraint
quarkusio/quarkus#52324→#53019correctnessAGrok 4.5HIT HIGHDevServices reallyStart stopped putAll into shared configs → dependent services miss prior config
apache/pinot#18806→#18863correctnessAGrok 4.5HIT HIGHDefaultSegmentDirectoryLoader dropped segmentLoaderContext so task.config.json never injected
quarkusio/quarkus#54343→#54769correctnessAGrok 4.5MISS null-key NPE missedexcludedKeys.contains(key) NPE on null JBoss LogManager keys in nested JSON skip
apache/camel#20229→#24707correctnessAGrok 4.5HIT HIGHJdbcAggregationRepository.verifyTableName regex rejects schema-qualified table names
apache/lucene#16081→#16256correctnessAGrok 4.5HIT HIGHRoaringDocIdSet appendRangeInCurrentBlock uses < instead of <= at MAX_ARRAY_LENGTH 4096
apache/lucene#15603→#15995correctnessAGrok 4.5HIT HIGHTopGroupsCollectorManager hardcodes withinGroupOffset=0 ignoring pagination
netty/netty#16548→#16811correctnessAGrok 4.5HIT HIGHCompositeByteBuf component search fast path wrong after discardReadComponents with non-zero offsets
apache/kafka#18196→#22723correctnessAGrok 4.5HIT HIGHMetadataCache.toCluster filters fenced brokers then maps replicas through map causing NPE
FasterXML/jackson-databind#5896→#5903correctnessAGrok 4.5HIT HIGHdeserializeFromObjectId returns null early breaking forward refs when FAIL_ON_UNRESOLVED disabled
elastic/elasticsearch#152481→#153904correctnessBGrok 4.5HIT CRITICALRemoved IGNORED_SOURCE_AS_DOC_VALUES_FF without bumping index version gate for TSDB
apache/iceberg#11322→#17014correctnessAGrok 4.5HIT HIGHCharSequenceSet contains(null) NPE after WrapperSet rebase
apache/pulsar#25337→#26160correctnessAGrok 4.5MISS LightProto ByteBuf release missedLightProto parseSnapshotMetadataEntry releases ByteBuf before delayed_index_bit_map access
apache/pinot#18396→#18883correctnessAGrok 4.5HIT HIGHTIMESTAMP cast precision 0 truncates millis in binaryComparisonCoercion
apache/kafka#20749→#22490concurrencyAGrok 4.5HIT HIGHinitializeStartupStores close without unlock holds StateDirectory locks permanently
apache/pulsar#21406→#24945concurrencyAGrok 4.5HIT HIGHFirst txn buffer snapshot races concurrent first publishes after deferred snapshot
apache/pulsar#14494→#25578concurrencyAGrok 4.5HIT HIGHupdateAutoScaleReceiverQueueHint races unlocked incomingMessages.size vs drain
elastic/elasticsearch#153092→#154316concurrencyAGrok 4.5HIT MEDIUMSearch recovery wait metrics uses isCancelled race mislabeling TIMEOUT as WARMING_COMPLETE
redis/jedis#4011→#4601concurrencyAGrok 4.5HIT HIGHAuthXManager.authenticateConnections ConcurrentModificationException mid-iteration remove
quarkusio/quarkus#13977→#42260concurrencyAGrok 4.5HIT HIGHReactiveDatasourceHealthCheck post-await UP overwrites concurrent DOWN
apache/bookkeeper#3784→#4557concurrencyBGrok 4.5HIT HIGHcompleteAdd callbacks on IO threads race PendingAddOp unsynchronized queue
spring-projects/spring-frameworke6c2d446→#36869concurrencyAGrok 4.5HIT HIGHCookieLocaleResolver shared cookie field race on concurrent setLocaleContext
redisson/redisson597d604a→#7070concurrencyAGrok 4.5HIT HIGHRenewalTask non-atomic name2entry check-then-act drops live lock from watchdog
opensearch-project/OpenSearch#21242→#22231concurrencyAGrok 4.5MISS cancel-callback gap missedAnalyticsQueryTask cancel callback null gap before install
apache/hbase#4577→#7465concurrencyBGrok 4.5MISS suspend/wake race missedSplitWAL suspend/wake race leaves procedure WAITING forever
apache/accumulo#5335→#5342dataAGrok 4.5HIT HIGHTabletsMetadata.fetch iterates fetchedCols not colsToFetch
apache/pulsar#9292→#23759dataAGrok 4.5HIT HIGHCursor individual-ack long-array serialize loses ranges when OpenCacheSet disabled
apache/kafka#10964→#18901dataAGrok 4.5HIT HIGHlistConsumerGroupOffsets Map overload drops requireStable options
apache/kafka#19026→#22714dataBGrok 4.5MISS LATEST startOffset missedShare group new partitions always startOffset -1 LATEST skips existing records
apache/flink#27071→#28242dataAGrok 4.5HIT CRITICALLinkedMultiSetState updates highestSqn on replace breaking monotonic SQN
apache/paimon#7093→#8698dataAGrok 4.5HIT HIGHIncrementalSplit assignSuggestedTask returns raw postpone bucket -2 drops splits
apache/paimon#8287→#8333dataBGrok 4.5HIT HIGHOverwrite lookupEnabled gate also disables remote lookup file materialization
apache/iceberg#11555→#15470dataBGrok 4.5MISS file_size_in_bytes missedRewriteTablePath keeps stale file_size_in_bytes for rewritten position deletes
apache/pinot#15685→#18738dataAGrok 4.5MISS Utf8 desync missedUtf8.encodedLength throws mid-loop desyncing MutableJsonIndex docId mapping
apache/pinot#17308→#18503dataBGrok 4.5HIT HIGHExpressionTransformer null overwrite wipes existing BYTES on partial upsert
apache/pinot#18280→#18447dataAGrok 4.5HIT HIGHlengthOfLongestElement backfill skips dictionaryElementSize==0 empty strings
keycloak/keycloak#49399→#49953securityAGrok 4.5HIT HIGHTokenManager.isValidScope drops AuthorizationRequestContext parameter
keycloak/keycloak#44922→#50859securityAGrok 4.5HIT HIGHReset password action token reuse returns error without transaction rollback
apache/knox#1154→#1219securityAGrok 4.5HIT HIGHJWTFederationFilter grant_type param hidden by wrappers so Basic client_credentials no-op
hazelcast/hazelcast#19850→#25508securityAGrok 4.5HIT HIGHExplainStatementPlan missing checkPermissions leaks plan/schema
keycloak/keycloak#7586→#50463securityAGrok 4.5HIT HIGHClient URI scheme validation case-sensitive allows JaVaSCript data URIs
apache/ozone#10197→#10771securityAGrok 4.5HIT HIGHS3 actions attached to authorizer context even when STS feature flag off
datahub-project/datahub#14588→#17904securityAGrok 4.5HIT HIGHSetLogicalParentResolver no authorization on dual-resource parent link
apache/pulsar#19467→#19976securityAGrok 4.5HIT HIGHTxn ownership check only principal omits dual proxy originalPrincipal
apache/ozone#9445→#9602securityBGrok 4.5HIT HIGHSTS revoke only checks session key not original permanent access key
undertow-io/undertow#1702→#1908securityBGrok 4.5HIT HIGHServletCookieAdaptor setSameSite(true) always forces Lax ignoring mode
apache/ranger5bc3cb303e11→#915securityAGrok 4.5HIT CRITICALJWT doAs replaces subject without impersonation authorization
apache/rangerfb53a3dc0022→#1081securityAGrok 4.5HIT HIGHJWT validation failure logs full serialize bearer credential
elastic/elasticsearch#123610→#125916performanceAGrok 4.5HIT HIGHTopHitsAggregationBuilder disables parallel collection for field sorts
elastic/elasticsearch#142047→#142363performanceAGrok 4.5MISS cell-size rehash missedHLL LinearCounting starts all groups at size 32 causing rehash storm
elastic/elasticsearch#146433→#154519performanceAGrok 4.5HIT HIGHNDJSON lenient decode allocates page-sized scratch builders per record
elastic/elasticsearch#148331→#152938performanceAGrok 4.5HIT MEDIUMImplicitPrivilegesProvider rebuilds StringMatcher every role build
opensearch-project/OpenSearch#20857→#20915performanceAGrok 4.5MISS sold-as-safer clearedSignificantTextAggregator disables concurrent segment search when filterDuplicateText
opensearch-project/OpenSearch#11643→#20623performanceBGrok 4.5HIT HIGHTerms agg precompute via terms dictionary regresses high-cardinality fields
apache/logging-log4j2#2101→#2256performanceAGrok 4.5HIT MEDIUMJdkMapAdapterStringMap probes immutability via replace throwing on hot path
apache/pinot#15609→#15977performanceBGrok 4.5HIT HIGHOpChain cache retains MultiStageOperator trees with large maps after EOS
spring-projects/spring-framework5cb2f870d047→#37059performanceAGrok 4.5HIT HIGHAbstractJacksonEncoder acquires BufferRecycler never releaseToPool under Jackson 3
apache/ignite8f1d5a280c→#11797performanceAGrok 4.5MISS sold-as-faster clearedwriteUuidRaw bulk I/O cannot partial-progress on fragmented buffers sold-as-faster
apache/logging-log4j2b34d8cc585→#251performanceAGrok 4.5HIT MEDIUMAsyncLoggerConfig ThreadLocal remove forces setInitialValue allocation hot path
apache/avro#2608→#3813correctnessAGrok 4.5HIT HIGHTimestampNanosConversion pre-epoch uses micros-scale constant instead of nanos
apache/parquet-java#1111→#3543correctnessAGrok 4.5HIT HIGHLocalInputFile ByteBuffer read wrong offset and arrayOffset on direct buffers
apache/solr#2402→#3992correctnessAGrok 4.5MISS double-register missedHttpJettySolrClient double registers asyncTracker listeners on async requests
apache/maven-resolver#1896→#1904correctnessAGrok 4.5HIT HIGHPathConflictResolver cycle handling reuses residual cycle state wrong
micronaut-projects/micronaut-core#12086→#12796correctnessAGrok 4.5HIT HIGHDefaultReplacesDefinition getBeanType fails for AOP proxied default implementations
hibernate/hibernate-orm#5471→#5547correctnessAGrok 4.5HIT HIGHStandardForeignKeyExporter double i++ skips composite FK columns
apache/rocketmq#9521→#10426correctnessAGrok 4.5HIT HIGHTopicConfigManager skips DataVersion nextVersion under enableSplitRegistration
apache/rocketmq#7687→#8331correctnessAGrok 4.5MISS bornTime skew clearedProxy stamps bornTime causing POLLING_TIMEOUT under clock skew
apache/rocketmq#7694→#8209correctnessAGrok 4.5HIT CRITICALFileRegionEncoder CompositeByteBuf wrap corrupts TLS queryMsgByUniqueKey
apache/rocketmq#10204→#10254correctnessAGrok 4.5HIT HIGHunmarkWildcardGroupIfNecessary splits on whitespace not @
hazelcast/hazelcast#19304→#19468concurrencyAGrok 4.5HIT CRITICALSingleProtocolEncoder signalProtocolLoaded races setupNextEncoder NPE
apache/pulsar#1521→#1548concurrencyAGrok 4.5HIT HIGHasyncAddEntry enqueue vs send split across threads races writers
elastic/elasticsearch#115017→#115127concurrencyAGrok 4.5HIT HIGHEsqlSession runPhase before updateExecutionInfoAtEndOfPlanning race
apache/kafka#21135→#21279concurrencyAGrok 4.5MISS backoff race clearedProducerIdManager request-path clears backoff racing handleUnsuccessfulResponse
spring-projects/spring-kafka#2613→#2629concurrencyAGrok 4.5HIT HIGH (blind re-score 07-22; was self-scored MISS — childStopped/lifecycleMonitor deadlock named 3/3)childStopped synchronized lifecycleMonitor then doStart deadlock
trinodb/trino#14644→#22302concurrencyBGrok 4.5HIT HIGHEvictableCache token revive races concurrent invalidation
apache/hudi#9936→#13650dataAGrok 4.5HIT CRITICALComplexAvroKeyGenerator single-field bare value breaks key encoding upgrade
debezium/debezium#7269→#7350dataBGrok 4.5HIT HIGHChangeEventSourceCoordinator never sets streaming from streamingConnected
apache/iceberg#13804→#14270dataBGrok 4.5MISS optional-path residual clearedAccessor hasOptionalFieldInPath incomplete for nested nullability binding
apache/druid#13653→#13714dataAGrok 4.5HIT CRITICALSimpleDictionaryMergingIterator drops values on equal heads without advance
apache/hudi#17994→#18738dataAGrok 4.5HIT HIGHFlink getRecordKeyStr always requires PK blocking append-only tables
keycloak/keycloak#40938→#50211securityAGrok 4.5HIT HIGHExternalToInternalTokenExchangeProvider missing canExchangeTo IdP permission
keycloak/keycloak#13185→#50841securityAGrok 4.5HIT HIGHBruteForceUsersResource prefix search skips canView FGAP filter
apache/activemq-artemis#4583→#6480concurrencyAGrok 4.5HIT HIGHMQTTStateManager.getSessionState (new in #4583) uses non-atomic ConcurrentHashMap
apache/curator#297→#1278concurrencyAGrok 4.5HIT HIGHCURATOR-495 / #297 added `runSafeService` (default
apache/curator#171→#1264concurrencyAGrok 4.5HIT HIGHPersistentTtlNode (CURATOR-351 / #171) creates an internal
apache/solr#3349→#4189concurrencyAGrok 4.5HIT HIGH#3349 switched globalCircuitBreakerMap to ConcurrentHashMap but left map values as plain ArrayLists…
apache/kafka#19885→#21253concurrencyAGrok 4.5MISS empty findings#19885 made OffsetFetch use topic IDs; response parsing resolves topicId → name via
apache/paimon#4328→#8684concurrencyAGrok 4.5HIT HIGH#4328 replaced atomic `connections.computeIfAbsent(...)` in
apache/pinot#13976→#14237concurrencyAGrok 4.5HIT CRITICALIdealStateGroupCommit (new in #13976) batches concurrent IdealState updaters then blindly writes a…
apache/pulsar#26051→#26075concurrencyAGrok 4.5HIT HIGH#26051 made `NonPersistentTopic.internalSubscribe` migration redirect async/fire-and-forget:…
apache/pulsar#26044→#26110concurrencyAGrok 4.5HIT HIGH#26044 adds `TopicPolicyListenerWrapper` that buffers live topic-policy updates until…
apache/pulsar#11389→#17056concurrencyAGrok 4.5MISS empty findingsManagedLedgerImpl.internalTrimLedgers (added invalidateReadHandle call when ledger is retained for…
apache/rocketmq#10239→#10267concurrencyAGrok 4.5HIT MEDIUMBatchSplittingMetricExporter.export() (added in #10239) splits large metric batches and fires N…
apache/solr#3398→#3843concurrencyAGrok 4.5MISS adjacent onlyParallelHttpShardHandler wraps `super.makeShardRequest` in a `FutureTask`
apache/accumulo#6484→#6485dataAGrok 4.5MISS design onlyNew `FileOperations.openFile(FileSystem, Path, FileStatus)` awaits Hadoop's…
apache/iceberg#6811→#8470dataAGrok 4.5HIT HIGH#6811 adds lazy snapshot loading in `TableMetadata` so a metadata
apache/iceberg#7581→#8969dataAGrok 4.5HIT HIGH#7581 rewrote the partitions metadata table to scan `ManifestEntry` (not just live files) so it could…
apache/iceberg#10547→#13435dataAGrok 4.5HIT HIGH#10547 added `calculateMetadataSchema()` to reassign field IDs for the `_partition` metadata column…
apache/ozone#9115→#10545dataAGrok 4.5HIT HIGHHDDS-13756 (#9115) switched FSO/key delete quota accounting to `decrUsedNamespace(1L, isKeyNonEmpty)`…
apache/paimon#4246→#8708dataAGrok 4.5HIT CRITICAL#4246 adds complex-type JSON parsing in `TypeUtils` for CDC (MAP/ROW/
apache/paimon#7330→#8676dataAGrok 4.5HIT HIGHLumina vector-index options (#7330) persist `lumina.distance.metric` into durable index meta via the…
apache/pinot#10978→#18813dataAGrok 4.5HIT HIGHIn `BaseSingleSegmentConversionExecutor.executeTask`, #10978 wrapped segment upload in try/catch to…
trinodb/trino#26405→#26806dataAGrok 4.5HIT CRITICAL#26405 introduces `RowBlock.startOffset` so `getRegion` can share nested
trinodb/trino#21070→#21073dataAGrok 4.5HIT HIGH#21070 "Reduce redundant TrinoInputFile.length call" threads a `length`
apache/iceberg#13080→#16011dataBGrok 4.5HIT CRITICALDynamic Iceberg Sink (#13080) has `DynamicWriteResultAggregator.open()`
apache/iceberg#10351→#16237dataBGrok 4.5HIT CRITICALKafka Connect `Coordinator.commit` (#10351) wraps `doCommit` in `catch (Exception e) { LOG.warn("Commit…
FasterXML/jackson-databind#5639→#5858correctnessAGrok 4.5MISS empty findingsPR #5639 taught `TypeFactory._fromParamType` to resolve unbounded wildcards to the type variable's…
apache/camel#23121→#23130correctnessAGrok 4.5HIT HIGH#23121 (watch mode) adds a field `final AtomicBoolean running = new AtomicBoolean(true)` and…
apache/camel#20100→#24255correctnessAGrok 4.5MISS adjacent only#20100 (CAMEL-22740) introduced `SmbOperations.atomicRenameFile` calling `src.rename(to)` with the path…
apache/commons-lang#1561→#1749correctnessAGrok 4.5MISS adjacent only`BitField.getValue(int|long)` shifts with arithmetic `>>`. When the field mask sits on the top bit of…
apache/flink#24812→#28762correctnessAGrok 4.5HIT HIGH`ForStDBBunchPutRequest.buildSerializedValue` (new in #24812 Map Async State API) serializes user…
apache/kafka#18115→#21167correctnessAGrok 4.5HIT HIGH#18115 (KAFKA-18015 / byDuration auto.offset.reset) on `TimeoutException` during duration seek does…
apache/logging-log4j2#319→#4125correctnessAGrok 4.5HIT HIGH#319 added app
apache/lucene#15171→#16377correctnessAGrok 4.5MISS adjacent onlyDefault `VectorScorer.bulk(matchingDocs)` (added in #15171) calls `iterator.nextDoc()` during…
apache/lucene#13032→#15702correctnessAGrok 4.5HIT HIGH#13032 rewrote the constructor to avoid a double `bytesStartArray.bytesUsed()` call: `final Counter…
apache/ozone#10469→#10756correctnessAGrok 4.5MISS empty findings#10469 removes `OMClientRequest.getUserIfNotExists` (the getCurrentUser / OM-address fallback) and…
apache/camel#24557→#24695securityAGrok 4.5HIT MEDIUMCAMEL-23974 / #24557 “Pass OAuth credentials from ZeebeComponent to ZeebeService” makes…
apache/iceberg#14059→#16023securityAGrok 4.5MISS empty findingsDeprecation cleanup (#14059) inlined 6-arg `fetchToken(...)` on non-exchange refresh paths with…
apache/james-project#2985→#3029securityAGrok 4.5MISS adjacent onlyJAMES-4193 / #2985 introduces `TCNativeEncryptionFactory` (BoringSSL via Netty tcnative). When…
apache/pulsar#17238→#18252securityAGrok 4.5HIT HIGH#17238 adds admin `updateProperties` and gates it with `validateTopicOperationAsync(topicName,…
elastic/elasticsearch#58942→#59693securityAGrok 4.5HIT HIGH#58942 changes submit-async-search authorization to always succeed with `IndexAuthorizationResult(true,…
keycloak/keycloak#48320→#49613securityAGrok 4.5MISS adjacent onlyORGANIZATIONS FGAP resource type (#48320) wired `OrganizationMemberResource.getOrganizations` with…
keycloak/keycloak#37038→#50914securityAGrok 4.5MISS adjacent onlyGroups resource type / FGAP evaluation (#37038) left `GroupResource.getSubGroups` gated only by…
keycloak/keycloak#49653→#50538securityAGrok 4.5HIT HIGHCACHELESS single-use object JPA provider (#49653) implements `put()` with `lifespanSeconds > 0`…
apache/flink#19701→#28489performanceAGrok 4.5MISS empty findingsRocksDB native Statistics metrics (#19701 / FLINK-24786) construct a Java `Statistics` wrapper and null…
apache/flink#24880→#28251performanceAGrok 4.5MISS adjacent onlyManual SST compaction Compactor (#24880 / FLINK-26050) calls…
apache/lucene#15971→#16316performanceAGrok 4.5MISS empty findings#15971 “Eliminate redundant cardinality() pass” moves…
apache/lucene#15592→#15687performanceAGrok 4.5HIT HIGH#15592 “Optimize DocIdSetIteratorAcceptDocs#cost” (sold-as-faster filtered search) stops materializing…
apache/paimon#8567→#8691performanceAGrok 4.5MISS empty findings#8567's `AvroBytesArray` "optimize" does not keep the original Avro payload; it decodes every element…
apache/pinot#16344→#17489performanceAGrok 4.5MISS adjacent onlyCommit-time compaction (#16344) teaches `SizeBasedSegmentFlushThresholdComputer` to prefer…
elastic/elasticsearch#127849→#130576performanceAGrok 4.5MISS empty findings#127849 “Optimize ordinal inputs in Values aggregation” (sold-as-faster; 461ms→192ms for 10k groups)…
google/guava#7181→#7198performanceAGrok 4.5MISS empty findings#7181's latest `Iterators.singletonIterator` micro-optimization (rewritten state machine / allocation…
apache/pinot#11200→#12611concurrencyAGrok 4.5MISS adjacent: double-count stats, not CME on shared _docIdSetsAndDocIdSet/OrDocIdSet.iterator() mutates shared _docIdSets list while getNumEntriesScannedInFilter…
apache/pulsar#24551→#24569concurrencyAGrok 4.5HIT target recall via concurrency: Case 5 recursive cancel does not release reentranpendingReadOpMutex cancelPendingReadRequest recursion / concurrent cancel vs delay-task → infinite…
apache/pulsar#15067→#15971concurrencyAGrok 4.5MISS adjacent: non-monotonic persistent mark-delete, not triggerComplete deadlockinternalMarkDelete skip path calls mdEntry.triggerComplete() synchronously → re-enter dispatcher locks…
hazelcast/hazelcast#8269→#8318concurrencyAGrok 4.5HIT target recall via concurrency: cleanWaitersAndSignalsFor NPEs after forceUnlock LockStoreImpl.cleanWaitersAndSignalsFor NPE when lock removed by LocalLockCleanupOperation on same…
trinodb/trino#26602→#26708concurrencyAGrok 4.5HIT target recall via concurrency: removeTask check-then-act on isDestroyed races; dremoveTask destroy() outside global lock without idempotent destroy → concurrent cancel double-destroy…
apache/dubbo#16014→#16039concurrencyAGrok 4.5HIT target recall via concurrency: streamChannelFuture demoted from final without voTripleClientCall.start initStream before this.stream assign → onReady race sees null stream
elastic/elasticsearch#149319→#152031concurrencyAGrok 4.5MISS adjacent: cancel/queue cleanup, not STOPPED/onRecoveryComplete racepeer-recovery pending queue drain after STOPPED; onRecoveryComplete can start recovery against stopped…
debezium/debezium#4877→#7000concurrencyAGrok 4.5HIT target recall via concurrency: stop() closes Redis client before draining offsetRedisOffsetBackingStore reconnect nulls client while load/save use it → NPE infinite loop (non-volatile…
apache/druid#11492→#19446concurrencyAGrok 4.5HIT target recall via concurrency: locationIterators HashMap and cyclic iterators shLocalIntermediaryDataManager locationIterators plain HashMap raced by concurrent BatchAppenderator…
apache/pulsar#19817→#19844concurrencyBGrok 4.5HIT target recall via concurrency: revalidate queues on itself when a pending op is ResourceLock pendingOperationFuture incompletable / revalidation race under concurrent invalidation
apache/helix#1753→#3052concurrencyAGrok 4.5HIT target recall via concurrency: synchronized on Optional field that is reassignedOptional.empty() used as synchronized monitor — JVM singleton locks all DistClusterControllerStateModel…
apache/helix#1564→#2698concurrencyAGrok 4.5MISS adjacent: latch/preemption issues, not DEFAULT_PRIORITY_INT=-1DEFAULT_PRIORITY_INT=-1 causes false preemption and CountDownLatch(-1) non-owner unlock path
eclipse-vertx/vert.x#5084→#6112concurrencyAGrok 4.5HIT target recall via concurrency: Treiber-stack push CASes head before linking nextHybridJacksonPool CAS-publishes stack node before newHead.next = next → concurrent pop detaches stack
alibaba/nacos#10555→#14927concurrencyAGrok 4.5MISS adjacent: multiTaskExecutor leak/sync notify, not HashMap TOCTOUmultiTaskExecutor HashMap containsKey/put TOCTOU → duplicate executors / thread leak
apache/rocketmq#4313→#10614concurrencyAGrok 4.5HIT target recall via concurrency: Async request fires RequestCallback from send sucasync request callback executeRequestCallback on send success → premature null + double-fire with…
apache/bookkeeper#2842→#3503concurrencyBGrok 4.5MISS adjacent: election lifecycle races, not dual close of ledgerAuditorManagerledgerAuditorManager closed in both shutdown() and submitShutdownTask() → repeated concurrent close
apache/paimon#2568→#8684concurrencyBGrok 4.5HIT target recall via concurrency: establishConnection aborts after close and leavesNetworkClient.sendRequest non-atomic CHM get/put orphans concurrent ServerConnection → Netty channel…
apache/iceberg#13400→#14824concurrencyBGrok 4.5HIT target recall via concurrency: ScanTaskIterable.close() is a no-op; workers keepScanTaskIterable workers race on queue empty / activeWorkers termination without poison pill
eclipse-vertx/vert.x#3731→#6170concurrencyAGrok 4.5HIT target recall via concurrency: Waiter remove leaves links live; cancel can revivSimpleConnectionPool Recycle/ConnectSuccess poll waiters without disposed=true → Cancel…
apache/helix#2560→#3058concurrencyBGrok 4.5MISS no finding names maintainer defectsubscribeLeadershipChanges missing re-register of listeners after expire before leader recreate
apache/bookkeeper#1722→#4829dataAGrok 4.5MISS no finding names maintainer defectTxnImpl reuses one TxnRequest ByteBuf across silent gRPC retries → drained slices corrupt protobuf on…
apache/bookkeeper#2457→#4731dataAGrok 4.5HIT target recall via data: List-ledgers scan stops after first metadata rangeSyncLedgerIterator.hasNext returns false when currentRange exhausted without checking next ZK ledger…
debezium/debezium#3982→#7654dataAGrok 4.5HIT target recall via data: Reconnect path abandons Jedis clients under indefinite oRedisSchemaHistory.recoverRecords returns early on first deserialize IOException → silent…
debezium/debezium#4201→#7640dataBGrok 4.5HIT target recall via data: recoveryAttempts never resets after successful pollsRocketMQ schema history recoveryAttempts never resets after progress → false abort on large/slow history
debezium/debezium#7052→#7591dataBGrok 4.5MISS no finding names maintainer defectrowCountForTableChunked uses unquoted getQualifiedTableName → crash on names needing quotes
apache/paimon#4380→#6173dataAGrok 4.5HIT target recall via data: One physical file backs many buckets’ changelog metasprecommit-compact invents fake segment filenames; checkFilesExistence fails recovery on non-existent…
elastic/elasticsearch#23665→#23832performanceAGrok 4.5HIT target recall via performance: Every primary index now prepares/parses the documTransportShardBulkAction always double-parses on primary after mapping update split (#23665); fix…
apache/pinot#18852→#18930dataBGrok 4.5HIT target recall via data: HNSW extract leaves docId mapping inside Lucene directorstoreInSegmentFile=true probes legacy on-disk vector index; non-local segment dirs fail instead of…
apache/iceberg#12672→#16263dataBGrok 4.5HIT target recall via data: first_row_id assignment corrupts under projected reuseCoManifest merge reassigns firstRowId on EXISTING entries instead of preserving them (v3 row-lineage)
elastic/elasticsearch#80286→#90017performanceAGrok 4.5MISS no finding names maintainer defectFields API shared cache checked per-doc not per-segment → text fields latency regression
apache/logging-log4j2#1203→#4089correctnessAGrok 4.5HIT target recall via correctness: inUse left true when isEnabled rejects — breaks sSLF4JLogger.atFatal() copy-pasted as atLevel(Level.TRACE) instead of FATAL
apache/commons-lang#1650→#1747correctnessAGrok 4.5HIT target recall via correctness: register() before hashCode() zeroes nested reflecHashCodeBuilder.append(Object) shares ThreadLocal REGISTRY with reflectionAppend → cycle guard drops…
netty/netty#15413→#16188correctnessAGrok 4.5HIT target recall via correctness: ReadOnlyAbstractByteBuf CCE when Duplicated/ReadOReadOnlyAbstractByteBuf route uses instanceof AbstractByteBuf alone → CCE on custom unwrap…
redis/jedis#4405→#4575correctnessAGrok 4.5MISS no finding names maintainer defectCombiner.addParams counts only getOwnArgs size then appends YIELD_SCORE_AS outside count → Redis…
alibaba/fastjson2#3340→#7617correctnessAGrok 4.5MISS no finding names maintainer defectJSONB ASM minCapacity inverted (group.start/end) under-counts BC_OBJECT frame → AIOOBE on large UTF-16…
apache/camel#17352→#24745correctnessBGrok 4.5HIT target recall via correctness: Eager idempotent remove omits isIdempotent() checeager idempotent key drain only on Deque overload; List overload leaves keys after poll exception →…
apache/flink#27655→#28226correctnessAGrok 4.5HIT target recall via design: ApplicationExceptionsMessageParameters is unused by heApplicationExceptionsMessageParameters maxExceptions never read — handler typed on parent params…
hibernate/hibernate-orm#6814→#6996correctnessAGrok 4.5HIT target recall via correctness: Treated path copies keep pre-reparent NavigablePagetNavigablePathCopy misses EntityIdentifierNavigablePath peel/rebuild → wrong SQM path for id joins
debezium/debezium#5437→#7624dataBGrok 4.5MISS no finding names maintainer defectprovide.transaction.metadata=true mid-tx restart BEGIN replay wipes restored offset counters
apache/paimon#7860→#8232dataBGrok 4.5HIT target recall via data: stageReplace mutates live table with no-op abortREPLACE truncate then self-ref RTAS plans against empty live table → commits empty (data loss)
quarkusio/quarkus#42134→#55308securityAGrok 4.5MISS no finding names maintainer defectPulsarClientConfigCustomizer never calls enableTlsHostnameVerification — silently skipped despite TLS…
keycloak/keycloak#40006→#50699securityBGrok 4.5HIT target recall via security: email_verified claim applied without requiring a nonOIDC broker trustEmail reads email_verified only from ID token while email may come from userinfo…
keycloak/keycloak#47029→#50744securityAGrok 4.5HIT target recall via security: Temp-client policy conversion omits service-account Client Admin API v2 getProposedOldRepresentation realm.addClient temp without manage-clients…
netty/netty#15919→#16990securityAGrok 4.5MISS no finding names maintainer defectaddCredentials dropped on default OPENSSL server branch — dual-cert config silently no-ops
apache/knox#1265→#1307securityAGrok 4.5HIT target recall via security: Iceberg REST SSL keyed off HiveServer2 flag, not MetIceberg REST scheme uses hiveserver2_enable_ssl instead of hive_metastore_enable_ssl → wrong-resource…
apache/shiro#2711→#2807securityBGrok 4.5MISS adjacent: session attribute migration, not getSession(false) null NPE on login(nsession-fixation beforeSuccessfulLogin getSession(false) without null guard → login(null, token) NPE
apache/flink#24079→#25509performanceAGrok 4.5HIT target recall via correctness: seek() skips available() on the compression delegCompressibleFSDataInputStream.seek always skip(available) even uncompressed → multi-second S3 restore…
elastic/elasticsearch#60196→#60276performanceAGrok 4.5MISS empty findingschangeCollector gated on supportsIncrementalBucketUpdate so date-histogram-only pivots full-rescan each…
elastic/elasticsearch#57241→#57438performanceAGrok 4.5HIT target recall via performance: No-filter path always wraps FilteredOrdinals; losglobal-ords terms rewrite drops single-valued-ords + no-filter specializations → multi-valued path…
elastic/elasticsearch#101538→#112558performanceAGrok 4.5HIT target recall via design: Identical health-support gate repeated in three servicexpensive clusterHasFeature(SUPPORTS_HEALTH) ahead of cheap local-master checks on…
AsyncHttpClient/async-http-client#2104→#2243securityAGrok 4.5HIT incomplete-wiring fresh-pair HIT (endpoint ID JSSE arm)#2104 removes shared setEndpointIdentificationAlgorithm from SslEngineFactoryBase and restores it only…
apache/ozone#10111→#10165securityAGrok 4.5HIT incomplete-wiring fresh-pair HIT (DEFAULT protocol gate)setEnabledProtocols only applies setIncludeProtocols when value != SSL_ENABLED_PROTOCOLS_DEFAULT;…
apache/camel#20912→#24690securityAGrok 4.5HIT incomplete-wiring fresh-pair HIT (MSK callback omitted)saslAuthType convenience never sets OAuth/MSK callback handlers on the default path (AWS_MSK_IAM omits…
redis/jedis#4263→#4424securityAGrok 4.5MISS incomplete-wiring fresh-pair MISS (fromURI credential wipe)StandaloneClientBuilder.fromURI overwrites clientConfig, wiping credentials so default builder never…
netty/netty#10296→#10401securityAGrok 4.5HIT OPENSSL tickets only on REFCNT not default OPENSSL#10296 wires session-ticket enablement via setTicketKeys only on OPENSSL_REFCNT constructors;…
apache/pinot#8207→#17760securityAGrok 4.5HIT server GrpcSslContexts.configure wipes sslProviderServer sets .sslProvider then GrpcSslContexts.configure(builder) without provider — silently forces…
apache/ratis#1462→#1511securityAGrok 4.5HIT TlsConf provider/ciphers ignored on Netty DataStream#1462 adds TlsConf SslProvider/protocols/ciphers applied only via GrpcUtil; DataStream NettyUtils never…
apache/zookeeper#2009→#2270securityBGrok 4.5MISS adjacent SSL; not OCSP un-gated on JDK#2009 multi-provider OpenSSL support calls enableOcsp unconditionally; JDK default + ocsp=true throws.…
fabric8io/kubernetes-client#7875→#7908securityAGrok 4.5MISS empty findingsVert.x 5.1 WebSocket TLS arm drops trust/key material; HTTP path still applies TLS
streamthoughts/jikkou#427→#761securityAGrok 4.5MISS adjacent SSL password NPE; not authMethod trust gateSSLConfig applied only when authMethod=SSL; basicAuth/none leaves sslTrustStoreLocation configured but…
apache/camel#23771→#23777concurrencyAGrok 4.5HIT HIGHCAMEL-23686 "lighten" DefaultUnitOfWork replaced ConcurrentLinkedDeque<Route>
apache/pinot#7707→#13916concurrencyAGrok 4.5HIT HIGH#7707 made LiteralTransformFunction cache result arrays and explicitly left them non-volatile…
apache/pinot#8083→#8160concurrencyAGrok 4.5HIT HIGH#8083 moved Thrift serialization out of the per-channel synchronized send path: added a single…
apache/camel#11243→#24717concurrencyAGrok 4.5HIT HIGHCAMEL-19811 restore multi-shard handling switched currentShardIterator to
apache/flink#22987→#28315concurrencyAGrok 4.5HIT HIGHFLINK-32583 "fix deadlock" introduced responseChannelFutures
elastic/elasticsearch#149987→#150789concurrencyAGrok 4.5HIT HIGHSingle async cancel/complete race in StreamingHttpResultPublisher.
hazelcast/hazelcast#7635→#7806concurrencyAGrok 4.5HIT HIGH#7635 stopped cleaning dead-connection invocations synchronously on channel close and moved cleanup to…
apache/pinot#12292→#16339concurrencyAGrok 4.5HIT HIGH#12292 adds a process-wide ServerRateLimiter that all realtime consumers share, wrapping a single…
apache/pulsar#7255→#26046concurrencyAGrok 4.5HIT HIGH#7255 introduced FunctionMetaDataManager.exclusiveLeaderProducer as a plain (non-volatile) Producer…
apache/kafka#16848→#18997concurrencyAGrok 4.5HIT HIGH#16848 (KAFKA-17305) adds kraft.version to finalized features and reads
quarkusio/quarkus#52632→#54588correctnessAGrok 4.5HIT HIGH#52632 ("Vert.x 4.5.25 optimizations") loads `VertxServiceProvider` / `VerticleFactory` at build time…
apache/pulsar#25211→#25223correctnessAGrok 4.5HIT HIGH#25211 rewrote `AdminProxyHandler#createHttpClient` to `super.createHttpClient()` + thin…
opensearch-project/OpenSearch#22404→#22486correctnessAGrok 4.5HIT HIGH#22404 added recursion depth guards *and* lowered Jackson `StreamReadConstraints` /…
micrometer-metrics/micrometer#4867→#7657correctnessAGrok 4.5HIT HIGH#4867 added `DefaultExemplarSamplerFactory` with `ConcurrentMap<double[], ExemplarSamplerConfig>…
apache/lucene#16177→#16253correctnessAGrok 4.5HIT HIGH#16177 unified doc-values range evaluation onto a single two-phase `DocValuesRangeIterator` with bulk…
apache/maven-resolver#435→#1915correctnessAGrok 4.5HIT HIGHIPC named locks (#435, MRESOLVER-499) register a SIGTSTP ignore handler under `if…
quarkusio/quarkus#54991→#55227correctnessAGrok 4.5HIT HIGHGizmo 2 migration (#54991) left `RepositoryMethodsImplementor.implementIterable()` generating…
apache/camel#22300→#24823correctnessAGrok 4.5HIT HIGH#22300 (CAMEL-23264) stores `SplitFailureTracker` as a plain exchange property…
apache/pinot#12766→#12791correctnessAGrok 4.5HIT HIGH#12766 made `PinotTaskManager` multi-database-aware and added
apache/kafka#16730→#19507correctnessAGrok 4.5HIT HIGHKAFKA-17203 / #16730 fixed producer leaks by routing more close paths
apache/pinot#12502→#18952dataAGrok 4.5HIT CRITICAL#12502 added `addColumnMinMaxValueWithoutDictionary` for raw (no-dictionary) columns. For BYTES it…
apache/paimon#6804→#8500dataAGrok 4.5HIT HIGH#6804 renames GlobalIndexBatchScan → DataEvolutionBatchScan and adds `withShard(...)` that **returns**…
apache/paimon#7305→#7953dataAGrok 4.5HIT CRITICAL#7305 optimizes data-evolution scan with large rowRanges and rewrites `wrap` to derive the split range…
trinodb/trino#24172→#29212dataAGrok 4.5HIT HIGH#24172 added Iceberg `$entries` / `$all_entries` system tables and wrote
apache/druid#18053→#18059dataAGrok 4.5HIT HIGH#18053 added `getFieldLogicalType` for nested JSON/complex columns to
apache/pinot#16307→#16835dataAGrok 4.5MISS adjacent dangling-task gate; not IdealState delete retry#16307 added task-data cleanup as part of table deletion and removes
apache/pinot#16254→#17218dataAGrok 4.5HIT HIGHRecord-transform refactor #16254 changed continue-on-error behavior for
apache/druid#19193→#19238dataAGrok 4.5HIT HIGHOptional MSQ groupBy row combiner #19193 built dimension/value selectors
apache/hudi#6847→#8658dataAGrok 4.5HIT HIGH#6847 multi-table `InProcessLockProvider` stores base-path→lock in a
apache/paimon#7121→#7409dataBGrok 4.5HIT HIGHRow-tracking commit path `RowTrackingCommitUtils.assignSnapshotId` (#7121) only special-cases…
AsyncHttpClient/async-http-client#2203→#2244securityAGrok 4.5HIT HIGHPR #2203 escapes `"` / CR / LF only in multipart Content-Disposition `name` and `filename`, leaving…
quarkusio/quarkus#41501→#55211securityAGrok 4.5HIT HIGHPR #41501 adds `HttpCertificateUpdateEventListener` that on certificate reload calls…
redis/jedis#3980→#4495securityAGrok 4.5HIT HIGHPR #3980 adds `SslOptions` with default `SslVerifyMode.FULL` (endpoint identification) but refactors…
AsyncHttpClient/async-http-client#2154→#2235securityAGrok 4.5HIT HIGHPR #2154 implements RFC 7804 SCRAM-SHA-256 and adds `processScramAuthenticationInfo` that verifies…
quarkusio/quarkus#38608→#45578securityAGrok 4.5HIT HIGH#38608 adds TlsCertificateReloader for quarkus.http.ssl.certificate.reload-period.
apache/nifi#11257→#11396securityAGrok 4.5MISS adjacent HTTPS fail-open; not non-token factory wiring#11257 (NIFI-15948) switches HashiCorp Vault TLS to SSLContextProvider and
apache/hadoop#8300→#8357securityBGrok 4.5HIT HIGHPR #8300 (YARN-11937) adds reverse-proxy redirect support so Yarn Proxy can 302 to Knox tracking URLs…
AsyncHttpClient/async-http-client#2148→#2236securityBGrok 4.5HIT HIGHPR #2148 rewrites Digest to RFC 7616, replacing `match()` with `matchParam()` that returns unquoted…
apache/pinot#12611→#15756performanceAGrok 4.5HIT HIGH#12611 rewrote OrDocIdSet/AndDocIdSet iterator collection to fix ConcurrentModificationException…
elastic/elasticsearch#90612→#90804performanceAGrok 4.5HIT MEDIUM#90612 made knn/vector searches cancellable via ExitableDirectoryReader. ExitableVectorValues called…
elastic/elasticsearch#58744→#60591performanceAGrok 4.5HIT HIGH#58744 extracted continuous-transform change collection into CompositeBucketsChangeCollector. For…
elastic/elasticsearch#25726→#25872performanceBGrok 4.5HIT HIGH#25726 refactors field expansion for match / multi_match / query_string (`default_field: *` /…
apache/flink#25859→#26180performanceBGrok 4.5HIT HIGHAdaptiveSkewedJoinOptimizationStrategy (#25859 / FLINK-36629) retains fine-grained…
elastic/elasticsearch#139973→#144863performanceBGrok 4.5HIT HIGH#139973 “ESQL: Split aggs results” emits hash-agg results in maxPageSize chunks (safer vs giant wire…
apache/kafka#6832→#7671performanceBGrok 4.5HIT HIGHKIP-392 fetch-from-followers (#6832) introduced follower last-seen highwatermark handling that called…
apache/hbase#3807→#7629concurrencyAGrok 4.5MISS adjacent sink races; not null-on-drop NPE#3807 (HBASE-26407) introduces RegionReplicaSinkWriter for sinking WAL
apache/iceberg#12197→#13718correctnessAGrok 4.5MISS adjacent ClassCast SigV4; not OAuth scope orderAuth Manager enablement #12197 rewrote `S3V4RestSignerClient.authSession()`
netty/netty#8393→#8484correctnessAGrok 4.5HIT HIGHOptimization #8393 ("Exploit PlatformDependent.allocateUninitializedArray
apache/kafka#19802→#20600concurrencyAGrok 4.5HIT HIGH#19802 (KAFKA-17747 [5/N]) moves creation of the soft-state configured
apache/pinot#18337→#18669correctnessAGrok 4.5MISS v2 files isolation/offset/timeout residuals#18337 rewrote `KafkaPartitionLevelConsumer.fetchMessages` (kafka 3.0 + 4.0) to skip re-seek when the…
apache/camel#19376→#22520correctnessAGrok 4.5MISS Findings flag toStreamCache NPE on null entity and narrow StreamCache #19376 (CAMEL-22414) added `CxfConverter.toStreamCache(Response)` that converts the entity via…
opensearch-project/OpenSearch#19006→#21534correctnessAGrok 4.5HIT HIGH#19006 changed `ScriptedMetricAggregator.buildAggregation` from `StreamOutput.checkWriteable(result)`…
apache/rocketmq#9566→#10616correctnessAGrok 4.5HIT MEDIUM#9566 moved `notifyMessageArriveInBatch=true` from `RocksDBMessageStore` ctor into…
apache/logging-log4j2#2853→#4074correctnessBGrok 4.5MISS v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)#2853 migrated `Rfc5424Layout` configuration to the builder pattern (`@PluginBuilderAttribute`) while…
apache/pinot#18621→#18842correctnessBGrok 4.5MISS v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)#18621 adds `mergeDataTablesOnly` / `mergeOnDataTable` that must keep aggregate state intermediate for…
apache/pinot#11839→#11971correctnessBGrok 4.5MISS EPOCH WEEKS NPE and Object return-type discussion are adjacentdateTimeConvert return type cast regression from #11839.
apache/paimon#4177→#8611correctnessBGrok 4.5HIT HIGHMigrate action factories parse optional `--parallelism` with unguarded Integer.parseInt(null).
redisson/redisson348f78a1→#7158correctnessAGrok 4.5MISS v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)Direct commit "Fixed - UUID serialization by Jackson codecs. #6828" (2026-01-21, no PR) adds…
redisson/redissona46673c1→#7229correctnessAGrok 4.5HIT HIGHCommit "Fixed - RMultimap.fastRemoveValue() method added. #5064" (2023-05-25, no PR) adds…
apache/accumulo#5357→#5366dataAGrok 4.5HIT CRITICALUpgradeCoordinator progress tracking (added in #5357) compared stored ZooKeeper/root/metadata progress…
apache/kafka#13843→#14457dataAGrok 4.5MISS v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)AbstractFetcherThread was changed so partition fetch state (including lag) still updates when…
apache/bookkeeper#3205→#3998dataAGrok 4.5MISS v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)TriggerGCService (force GC HTTP API on ledger storage) was extended to accept optional…
apache/hudi#10173→#10379dataAGrok 4.5HIT HIGH`HoodieConversionUtils.fromProperties` was changed from mapping each entry with…
elastic/elasticsearch#22593→#56527dataAGrok 4.5MISS v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)Source-filtering in `XContentMapValues` (document `_source` transform on read path) was changed so…
apache/druid#18095→#18557dataAGrok 4.5HIT HIGHMSQ worker cancellation switched to interrupts (#18095). `RunWorkOrder.stop` / `stopUnchecked` could…
apache/druid#16911→#17088dataAGrok 4.5MISS Findings are limitHint int overflow / SuperSorter hard-enforceFrameChannelMerger (MSQ global-sort / frame merge path) used `remainingChannels` as a count of non-null…
apache/flink#15495→#27501dataAGrok 4.5MISS Findings about window property grouping ordinals and late-slice timers`TimeWindowUtils.getNextTriggerWatermark()` (event-time window aggregate state/timer path) was…
opensearch-project/OpenSearch#12503→#13486dataBGrok 4.5MISS Only design@LOW on hasInnerHits lazy alloc"Removing unused fetch sub phase processor initialization" skipped initializing fetch sub-phase…
apache/pulsar#23931→#24089dataBGrok 4.5HIT HIGHManaged-ledger entry-count estimation was made "more accurate" (#23931) but used `currentLedger` /…
alibaba/nacos#11536→#14750concurrencyAGrok 4.5MISS v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)FailoverReactor.isFailoverSwitch(String) uses non-atomic containsKey(serviceName) then…
netty/netty#13237→#15927concurrencyAGrok 4.5MISS shipped v0.38.9 sliceNonStickyEventExecutorGroup.NonStickyOrderedEventExecutor, when hitting maxTaskExecutePerRun, clears…
apache/camel#14161→#24731concurrencyBGrok 4.5HIT HIGHTemporaryQueueReplyManager.TemporaryReplyQueueDestinationResolver.resolveDestinationName check-then-act…
apache/kafka#17562→#21279concurrencyBGrok 4.5MISS Findings focus on requestInFlight wedge on unexpected response typesRPCProducerIdManager.maybeRequestNextBlock() calls sendRequest() then unconditionally…
apache/kafka#21279→#22204concurrencyBGrok 4.5MISS Findings note request-path backoff clear fixed and residual timeout/coResidual race in RPCProducerIdManager after #21279: maybeRequestNextBlock still reads backoffDeadlineMs…
apache/helix#2558→#2814concurrencyBGrok 4.5MISS Findings are HashSet races, close CME, isLeader NPELeaderElectionClient ConnectStateListener only recreated participant ephemeral nodes on…
apache/camel#14999→#24766concurrencyBGrok 4.5HIT HIGHAbstractBeanProcessor.getCustomAdapter: non-volatile processor/lookupProcessorDone plus incomplete…
elastic/elasticsearch#147691→#147796concurrencyAGrok 4.5MISS v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)PlainCompressionCodecFactory used plain HashMap + computeIfAbsent for lazy codec (de)compressors.…
apache/druid#12663→#19497concurrencyAGrok 4.5HIT MEDIUMLazy ORC init moved FileSystem classloader-sensitive init into OrcInputFormat.initialize(conf) and…
apache/ozone#6690→#10351concurrencyAGrok 4.5HIT HIGHMappedBufferManager (new in HDDS-10488) caches mapped buffers as WeakReference<ByteBuffer> in a…
elastic/elasticsearch#141373→#152214concurrencyBGrok 4.5MISS Findings note system-user readiness privilege and prepareForShutdown sSigtermTerminationHandler.blockTermination registers cluster-state listener before seeding…
keycloak/keycloak#49892→#50961securityAGrok 4.5MISS v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)PR #49892 adds SCIM protection for administrative users/groups (`isAdminUser` / `isAdminGroup` on User…
keycloak/keycloak#47838→#50567securityAGrok 4.5MISS shipped v0.38.9 slicePR #47838 adds the AuthZEN **Evaluations** (batch) endpoint and authenticates with…
keycloak/keycloak#46561→#50872securityBGrok 4.5MISS Findings cover SCIM filter queryPR #46561 adds SCIM PATCH support (`AbstractScimResourceTypeProvider.patch`) that iterates every…
keycloak/keycloak#34568→#50486securityBGrok 4.5MISS Findings are ADMIN_FINE_GRAINED_AUTHZ_V2 feature-flag not consulted / Under FGAP v2, `GroupResource.addChild` required manage on the **parent** only. When reparenting an…
apache/ranger29038c4f81→#1011securityAGrok 4.5MISS Findings name download flag defaulting to general unauth boolean (wideCommit `29038c4f81` (RANGER-3623) adds `failUnauthenticatedDownloadIfNotAllowed()` and config…
apache/hadoopc39e9fc9→#8465securityAGrok 4.5HIT HIGHCommit `c39e9fc9` (HADOOP-15169) adds `HttpServer2.setEnabledProtocols` but gates Jetty include/exclude…
apache/kafka#16669→#17305securityBGrok 4.5HIT HIGHKIP-853 storage-tool flags PR stopped processing SCRAM bootstrap arguments.
apache/druid#15287→#16525concurrencyAGrok 4.5HIT HIGHAzure client upgrade introduced AzureClientFactory with `cachedBlobServiceClients = new HashMap<>()`…
opensearch-project/OpenSearch#22229→#22231concurrencyBGrok 4.5MISS Findings name incomplete parentTask wiring (QueryRequestContextSingle async cancel race on AnalyticsQueryTask. Task is registered cancellable (taskManager.register)…
apache/lucene#14363→#16142performanceAGrok 4.5MISS Empty findings across performance/correctness/design#14363 implements `DisjunctionDISIApproximation.docIDRunEnd()` by calling…
apache/iceberg#15448→#16284performanceAGrok 4.5MISS v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)#15448 introduces `SerializableFileIOWithSize` to pass a serializable FileIO on Spark’s read path but…
elastic/elasticsearch#110633→#136625performanceAGrok 4.5MISS v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)#110633 (manage_roles / regex has-privilege style checks) builds index-group automatons via…
elastic/elasticsearch#135886→#138711performanceBGrok 4.5MISS Findings are missingValue#135886 wires `index.sort.*` settings through `stringListSettingWithDefaultProvider` / listSetting…
apache/paimon#3209→#7910performanceAGrok 4.5MISS Correctness flags LazyField unsynchronized concurrent first get (race #3209 introduces `LazyField<T>` with `private final Supplier<T> supplier` retained forever after…
elastic/elasticsearch#145676→#145779performanceAGrok 4.5MISS Sole finding is INT4 bulk-sparse query size check using packed length BBQ/INT4 bulk scorers scored via `IndexInputUtils.withSlice(input, input.length(), …)`, mapping (or…
elastic/elasticsearch#90672→#91462performanceAGrok 4.5HIT MEDIUM#90672 “Refactor & tidy up uses of Strings class” rewrites `hasText`/`validFileName` to…
micrometer-metrics/micrometer#3959→#6363concurrencyBGrok 4.5MISS v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)Incomplete ConcurrentHashMap migration: ExponentialHistogram OTLP support added IndexProviderFactory…
apache/bookkeeper#4285→#4737concurrencyBGrok 4.5MISS Findings praise writeAndFlush failure calling errorOut (hang fix) and PerChannelBookieClient.readV3Response does completionObjects.get(key), schedules async handler that may…
quarkusio/quarkus#54084→#55041concurrencyBGrok 4.5HIT MEDIUMResidual half-close vs onMessage race on gRPC @RunOnVirtualThread under unified HTTP transport.…
apache/hudi#7267→#11668dataAGrok 4.5MISS v2 still cites FileUtilHoodieSnapshotExporter was changed from `SaveMode.Overwrite` to `SaveMode.ErrorIfExists` while…
apache/accumulo#5621→#5631dataAGrok 4.5MISS empty findings#5621 made `ColumnFamilySkippingIterator.seek` call `range.bound(minCF, maxCF)` to narrow seeks. When…
elastic/elasticsearch#150027→#154280dataAGrok 4.5MISS Only flags skipper intoBitSet missing iterDoc>=upTo early return vs noIncomplete fix of TSDB doc-values range `intoBitSet`: #150027 fixed position-contract issues on some…
apache/hudi#6266→#18887dataAGrok 4.5HIT HIGHWhen `MARKERS.type` is absent, `MarkerBasedRollbackUtils.getAllMarkerPaths()` tries DIRECT markers and…
apache/ozone#8926→#9262dataAGrok 4.5HIT HIGHHDDS-13520 (#8926) reworked SCM block-deletion retry (always retry; drop max-retry skip). In…
apache/pulsar#24833→#25066concurrencyBGrok 4.5HIT HIGHPIP-442 (#24833) adds AsyncSemaphoreImpl with update(permit, newPermits) that can race: if a permit is…
opensearch-project/OpenSearch#18523→#19766dataBGrok 4.5MISS empty findingsExplicit index resolution API regressed empty index expressions from IndexNotFoundException to…
elastic/elasticsearch#147038→#154325dataBGrok 4.5MISS Only a design note that selective reading is blocked / RowRanges partiPageColumnReader (page-level Parquet batch reader) skip path: when a page is fully excluded,…
apache/lucene#14135→#16252correctnessAGrok 4.5HIT MEDIUM#14135 implements `intoBitSet` on `RoaringDocIdSet` / `IntArrayDocIdSet`. Once iteration reaches…
quarkusio/quarkus#41547→#42400correctnessAGrok 4.5MISS Flags singleResultOptional, count() cast, RuntimeException rewrite, ge#41547 migrates Panache to `SelectionQuery`/`MutationQuery`. The entityClass overload of…
apache/rocketmq#4809→#10579correctnessAGrok 4.5HIT HIGH#4809 introduces `DefaultElectPolicy` with comparator `(int) (y.getMaxOffset() - x.getMaxOffset())`…
opensearch-project/OpenSearch#17447→#22390correctnessAGrok 4.5MISS Flags finalizePreviousRange with counter==0 / compare() advancing acti#17447 adds filter-rewrite sub-aggregation support (`SubAggRangeCollector` +…
apache/kafka#21795→#22491correctnessAGrok 4.5HIT MEDIUM#21795 (KAFKA-17411 offset-management fixes) **adds**…
apache/commons-lang6941f81cd321→#1697correctnessAGrok 4.5MISS Builder nullIsLess/ignoreCase miswire and equals(String) NPE onlyDirect commit "Add Strings and refactor StringUtils" (2024-09-21, no PR) adds…
hazelcast/hazelcast#22942→#25114correctnessBGrok 4.5HIT HIGH#22942 moves pre-join/event registration into `OnJoinOp` carried on `JoinRequest` and makes…
elastic/elasticsearch#137367→#152293correctnessBGrok 4.5MISS Group-by-all plan rewrite, _timeseries encoding, Values(tsAgg) shape, #137367 ships ESQL `GROUP BY ALL` / bare time-series aggs. `TranslateTimeSeriesAggregate` still throws…
apache/pinot#18996→#19017correctnessBGrok 4.5MISS Pending buffer alias, weight validation, Accumulator dual surface (asB#18996 optimizes TDigest aggregation with `PercentileTDigestAccumulator` (capacity-preserving serialize…
elastic/elasticsearch#142493→#150319performanceAGrok 4.5MISS Notes removal of postInitializeCompetitiveIterator early-empty prune a#142493 implements `setScorer()` on the skipper competitive-iterator builder and removes…
apache/pinot#12437→#18892performanceAGrok 4.5MISS limit+negative index semantics and argument-order footguns only#12437 adds the 4-arg `splitPart(input, delimiter, limit, index)` scalar used on high-QPS…
elastic/elasticsearch#89047→#94159performanceAGrok 4.5HIT HIGH#89047 removes ES’s internal `shortcutTotalHitCount` optimization, relying on Lucene `Weight#count` /…
opensearch-project/OpenSearch#15579→#21350performanceAGrok 4.5MISS shipped v0.38.9 slice#15579 extracts `RemoteFsTimestampAwareTranslog` and implements remote-purge cleanup with…
elastic/elasticsearch#97972→#151815performanceAGrok 4.5MISS Correctness notes nested FlatteningXContentParser wrappers for prefix #97972 implements `subobjects:false` flattening via `FlatteningXContentParser` and…
apache/druid#19357→#19439performanceAGrok 4.5HIT MEDIUM#19357 batches small SpillingGrouper spill runs by **always** writing each spill to a temp file, then…
apache/iceberg#10755→#16691performanceAGrok 4.5HIT MEDIUM#10755 adds `cleanExpiredMetadata` / remove-unused-specs on expire-snapshots by scanning **every…
apache/kafka#17149→#22572performanceAGrok 4.5HIT MEDIUM#17149 introduces `PersisterStateBatchCombiner` with a TreeSet-based iterative overlap merge…
elastic/elasticsearch#107567→#108179performanceAGrok 4.5MISS shipped v0.38.9 slice#107567 adds synthetic-source ignored-value tracking (`IgnoredSourceFieldMapper`) and…
elastic/elasticsearch#138159→#139203performanceBGrok 4.5MISS empty findings#138159 unifies last-value downsampling producers onto `FormattedDocValues` for all field kinds…
keycloak/keycloak#47073→#50847securityAGrok 4.5HIT MEDIUMPR #47073 enforces SCIM admin roles/permissions and implements `getAll` as `getModels(...).map(m ->…
opensearch-project/OpenSearch#22075→#22118securityAGrok 4.5MISS empty findings#22075 changes `analytics.delegation.<backend>.blocked_predicates` defaults from empty to non-empty for…
keycloak/keycloak#45285→#49886securityAGrok 4.5MISS Findings cover CIMD executor soft-fail when feature off, scheme/SSRF/rPR #45285 adds Persistent CIMD (Client ID Metadata Document) client creation. Public clients created…
AsyncHttpClient/async-http-client6b2fbb7f→#2224securityAGrok 4.5MISS Findings discuss default strip on cross-domain redirects, same-origin Commit `6b2fbb7f` "Strip credentials on cross-domain redirects and HTTPS-to-HTTP downgrades" clears…
apache/cxf2b160783→#3240securityAGrok 4.5HIT CRITICALCommit `2b160783` (CXF-6909, closes #137) adds JCache OAuth data providers with `isExpired` implemented…
keycloak/keycloak#48091→#50801securityBGrok 4.5MISS Findings cover null clientId on create, temp-client policy probes, andPR #48091 removes the legacy Client API v2 service and lands create/update on `DefaultClientService`…
netty/netty#14300→#14495concurrencyAGrok 4.5MISS Findings flag Magazine#14300 adds AdaptivePoolingAllocator.free() (via finalize) that sets freed=true and drains magazines.…
apache/ozone#10378→#10388concurrencyAGrok 4.5MISS Findings discuss post-desync shutdown vs concurrent start interleavingIncomplete deadlock fix residual. HDDS-14645 (#10378) removed synchronized from…
apache/camel#21538→#22492concurrencyAGrok 4.5MISS Only finding is instanceof SynchronousExecutorService brittleness for CAMEL-23030 (#21538) avoided StackOverflowError on aggregate completion with SynchronousExecutorService…
apache/iceberg#10691→#11781concurrencyAGrok 4.5MISS Findings cover close()/cancel Closeable leaks, ConcurrentLinkedQueue#10691 bounded ParallelIterable.queue to cap memory: when the queue is full, a Task yields and is…
apache/pinot#12274→#13360concurrencyAGrok 4.5HIT MEDIUMScalingThreadPoolExecutor (new in #12274) autoscales by rejecting when busy then re-queueing. Idle…
apache/pinot#15189→#15724concurrencyAGrok 4.5HIT HIGH#15189 added gauge observability for MSE query server threads as a plain int _currentQueryServerThreads…
apache/pinot#7720→#13916concurrencyAGrok 4.5HIT HIGH#7720 memoizes LiteralTransformFunction (and array/generate literals) in QueryContext so one instance…
apache/ozone#8157→#8381concurrencyAGrok 4.5HIT HIGHHDDS-12596 (#8157) enforced ozone.om.fs.snapshot.max.limit via OmSnapshotManager.snapshotLimitCheck…
alibaba/nacos#13604→#15067concurrencyAGrok 4.5HIT HIGH#13604 adds MemoryMcpCacheIndex with ReentrantReadWriteLock guarding updateIndex and clear via…
apache/pulsar#18390→#25644concurrencyAGrok 4.5HIT HIGHConcurrentLongHashMap.Section publishes keys/values/capacity as three separate volatile fields. #18390…
apache/bookkeeper#4066→#4771concurrencyAGrok 4.5HIT HIGHSame ConcurrentLongHashMap/Section torn-triple publish race as pulsar-25644. #4066 ported pulsar's…
apache/kafka#10960→#19972concurrencyBGrok 4.5MISS Findings only note split public getters re-reading the volatile Timest#10960 refactors LogSegment maxTimestampSoFar + offsetOfMaxTimestampSoFar into a single volatile…
apache/helix#2814→#3058concurrencyBGrok 4.5MISS Findings discuss concurrent leave while iterating _participantInfos an#2814 fixed participant ephemeral recreate on any CONNECTED (not only EXPIRED→CONNECTED) and…
apache/pinot#9801→#13104concurrencyBGrok 4.5MISS Findings name timeout finally vs late receiveDataTable double accountiSingle AdaptiveServerSelection in-flight counter race. #9801 wired ServerRoutingStatsManager into…
apache/kafka#21692→#21809concurrencyBGrok 4.5MISS api-ops notes OffsetCommit overwrites client topicId from metadata cac#21692 (KIP-1251 assignment epochs) adds topicId resolving for OffsetCommit in…
apache/pulsar#5604→#21333concurrencyBGrok 4.5MISS Findings cover asyncOpen signature break, cursorLedgerStat refresh rac#5604 introduces Supplier<Boolean> mlOwnershipChecker and calls ledger.mlOwnershipChecker.get()…
alibaba/nacos#11856→#14927concurrencyBGrok 4.5HIT MEDIUMClientWorker.ConfigRpcTransportClient.multiTaskExecutor is a plain HashMap with non-atomic…
apache/iceberg#12496→#16880dataAGrok 4.5HIT MEDIUMParquet variant metrics upper-bound truncation for BINARY used `BinaryUtil.truncateBinaryMin` instead…
apache/iceberg#13301→#14438dataAGrok 4.5MISS Adjacent rebind issues filed; case-insensitive bind not namedTime-travel scan rebound partition specs with `PartitionSpec.toUnbound().bind(snapshotSchema)`…
apache/iceberg#16818→#17002dataAGrok 4.5MISS FIXED_LEN decimal shredding not filed`VariantShreddingAnalyzer.createDecimalTypedValue` hard-coded `FIXED_LEN_BYTE_ARRAY` length 16 for…
apache/pinot#17593→#18840dataAGrok 4.5HIT MEDIUMPerformance cache of Protobuf field descriptors keyed invalidation on `descriptor.getFullName()`. After…
apache/bookkeeper#3783→#3919dataAGrok 4.5MISS writeBytes readerIndex not filed; recovery flags adjacentSingle-buffer packaging for small add requests used `buf.writeBytes(unwrapped)`, which advances the…
debezium/debezium#1090→#6498dataBGrok 4.5MISS Empty; treated as fixSnapshot path restored `SET TRANSACTION ISOLATION LEVEL REPEATABLE READ` after `FLUSH TABLES` but never…
trinodb/trino#29362→#30342dataBGrok 4.5MISS Empty; treated as fixFailed-write cleanup for Delta Lake deletion vectors: #29362 filtered out entire `DataFileInfo` entries…
hibernate/hibernate-orm#8057→#13038dataBGrok 4.5MISS unique/not-null property column drop not filed`HbmXmlTransformer` property transform path (completed in HHH-17429) drops **unique** and **not-null**…
apache/hudi#18224→#18689dataBGrok 4.5MISS string sequence compare not filedNew JsonKinesisSource treated Kinesis sequence numbers as decimal strings compared with…
apache/ozone#9472→#10260dataBGrok 4.5HIT MEDIUMSCM container health reporting after HDDS-14119: `RatisUnhealthyReplicationCheckHandler` incremented…
apache/pinot#18171→#19036correctnessAGrok 4.5MISS INT×INT→DOUBLE not filedIn `BaseBinaryArithmeticScalarFunction.functionInfoForTypes`, PR #18171 inserted an…
apache/kafka#22479→#22849correctnessAGrok 4.5MISS hiResClockMs not filedShare-group DLQ produce path (KAFKA-20613) stamps every DLQ `SimpleRecord` with `time.hiResClockMs()`…
apache/lucene#16050→#16105correctnessAGrok 4.5MISS doc < upTo off-by-one not filed; density bulk-set adjacent`BatchDocValuesRangeIterator#intoBitSet` (added by SIMD/bulk range PR #16050) advances past a YES block…
apache/lucene#16069→#16199correctnessAGrok 4.5MISS Empty#16069 loads dense filters via `intoBitSet` inside `MaxScoreBulkScorer` windows. When a dense filter…
FasterXML/jackson-databind#5988→#5990correctnessAGrok 4.5MISS PTV EnumSet rejection not filedCVE-oriented #5988 validated **generic type parameters** via `PolymorphicTypeValidator`. Enum element…
apache/pinot#13943→#19003correctnessBGrok 4.5MISS withNewTableOptions option-drop not filed; double-get/matches adjacent`PinotImplicitTableHintRule.withNewTableOptions` (introduced in #13943 colocated-without-hints)…
apache/druid#19460→#19702correctnessBGrok 4.5MISS stale row-id supplier not filedClustered-segment factories from #19460 implemented `getRowIdSupplier()` / vector inspectors by…
quarkusio/quarkus#48445→#54864correctnessBGrok 4.5HIT HIGHDev Services model refactor (#48445) introduced `DevServicesResultBuildItem.discovered()`, which needs…
apache/calcite#4068→#5034correctnessAGrok 4.5MISS EmptyCALCITE-6709 rewrote `TRIM` parsing so that the branch with BOTH/LEADING/ TRAILING requires `<FROM>`…
spring-projects/spring-kafka#4360→#4431correctnessAGrok 4.5HIT LOWNew Streams recovering handlers (`RecoveringProcessingExceptionHandler` / production sibling) build the…
spring-projects/spring-kafka#4469→#4505correctnessAGrok 4.5MISS Empty`KafkaMessageListenerContainer.handleAsyncFailure` (after #4469) no longer re-queues…
redisson/redisson874588fa394c→#7035correctnessAGrok 4.5HIT MEDIUM`MasterSlaveConnectionManager.detectCluster()` switched single-node cluster detection from `MGET` to a…
apache/logging-log4j2a1b952bd472d→#4125correctnessAGrok 4.5MISS retry break-then-error not filed; retryCount dual-path adjacent`KafkaAppender.append` app-level retry loop does `tryAppend` then `break` on success, but control still…
redis/jedis#4226→#4547correctnessBGrok 4.5HIT HIGH`TrackingConnectionPool` / Connection builder path initializes a pooled `Connection` twice…
apache/paimon#1535→#7333performanceAGrok 4.5MISS removeIf O(n·m) not filed; dual full scan adjacent#1535 adds incremental tag-read planning in `SnapshotReaderImpl` and deduplicates before/after manifest…
apache/pinot#18033→#18067performanceAGrok 4.5MISS no-dict decompress cost not filed#18033 extends `PinotSegmentSorter.getSortedDocIds` to no-dictionary columns via new…
apache/druid#12600→#12679performanceAGrok 4.5HIT LOW#12600 widens `SqlSegmentsMetadataQuery` OVERLAPS SQL with extra OR bounds (`minmatch`/`maxmatch`) so…
apache/pulsar#18987→#18997performanceAGrok 4.5HIT MEDIUM#18987 makes `ServerCnx.handleAck` copy `CommandAck` before async work (`new…
apache/ozone#668→#9633performanceAGrok 4.5HIT MEDIUM#668 (HDDS-3139) changes `PipelinePlacementPolicy` to sort healthy datanodes by pipeline load via…
apache/hudi#4480→#10130performanceAGrok 4.5HIT MEDIUM#4480’s bucket-index abstraction for simple/consistent hashing tags records with an eager Spark action…
elastic/elasticsearch#133446→#134481performanceBGrok 4.5MISS Empty#133446 stops sharing Lucene `Weight` across ES|QL Drivers to fix a serverless NPE (`bulkScorer` null…
apache/camel#16105→#24736securityAGrok 4.5HIT MEDIUMPR #16105 adds camel-amqp SSL (`useSsl` + store options) and, when `useSsl=true`, always appends all…
keycloak/keycloak#7679→#49791securityAGrok 4.5MISS brute-force lockout skip not filed; other CIBA issues adjacentPR #7679 lands Client-Initiated Backchannel Authentication including…
AsyncHttpClient/async-http-client67f1cd669630→#2234securityAGrok 4.5MISS Empty`NettyRequestFactory.newNettyRequest` always calls `addAuthorizationHeader(...…
apache/cxf52bdff074019→#3317securityAGrok 4.5HIT MEDIUMCommit `52bdff0740` makes JWT Authorization Request (JAR) claims overwrite outer form parameters…
apache/pulsar#9275→#26046concurrencyAGrok 4.5MISS volatile exclusiveLeaderProducer not filed; other leadership races adjacentFunctionMetaDataManager.exclusiveLeaderProducer is the sole leadership signal (non-null ⇒ leader).…
apache/flink#13366→#28463concurrencyAGrok 4.5HIT MEDIUMFutureCompletingBlockingQueue (FLIP-27 split-fetcher → source-reader handover) #13366 rewrote the queue…
apache/bookkeeper#78→#4701concurrencyAGrok 4.5HIT MEDIUMHandleFactoryImpl.getHandle is the sole map that must return the *same* LedgerDescriptor instance so…
apache/helix#2844→#2934concurrencyAGrok 4.5HIT MEDIUMHelixGatewayServiceGrpcService (#2844 GatewayServiceManager work) stores per-instance StreamObserver in…
apache/ozone#1780→#10613concurrencyAGrok 4.5HIT MEDIUMDeletedBlockLogStateManagerImpl (#1780 HDDS-3205 DeleteBlock via Ratis) introduces deletingTxIDs =…
apache/kafka#14406→#21476concurrencyBGrok 4.5HIT MEDIUMAsyncKafkaConsumer fetch path races the application poll thread against a background thread that…
micronaut-projects/micronaut-core53f75c97884a→#12773securityAGrok 4.5HIT HIGHCommit `53f75c9788` ("Support SSL configuration per manual http service") adds…
SAP/cloud-security-services-integration-libraryc9061a3d70a0→#1979securityAGrok 4.5MISS EmptyCommit `c9061a3d` "Fix FIPS compatibility by using default KeyManagerFactory algorithm" drops SunX509…
elastic/elasticsearch#45272→#56090securityAGrok 4.5HIT MEDIUM#45272 adds `xpack.notification.email.ssl.*` and always installs SSLService socket factory when an…
AsyncHttpClient/async-http-client#2227→#2251concurrencyAGrok 4.5HIT MEDIUM#2227 replaces Thread.sleep busy-poll with an event-driven `http2ConnectionWaiters` registry in…
trinodb/trino1ef442738fc5→#22039performanceAGrok 4.5HIT LOWCommit `1ef442738f` ("Decide number of clients basing on average request size of client") reworks…
apache/pinot#14179→#19028dataBGrok 4.5MISS tryLock gates first-time snapshots not filed#14179 adds non-blocking `segmentLock.tryLock()` around upsert validDocIds snapshot writes (to avoid…
elastic/elasticsearch#150160→#152293correctnessBGrok 4.5MISS false ISE group-by-all not filedAfter #150160 moved `TranslateTimeSeriesAggregate` to the Analyzer, the rule still threw…
apache/pinot#17315→#17675securityAGrok 4.5HIT MEDIUM#17315 adds renewable TlsUtils SSL context to HttpsSegmentFetcher, but SegmentFetcherFactory still maps…
alibaba/nacos#14751→#15182concurrencyAGrok 4.5HIT MEDIUMResidual incomplete ConcurrentHashMap check-then-act. #14751 rewrote several naming-module…
alibaba/nacos#3654→#14779concurrencyAGrok 4.5HIT CRITICALIncomplete ConcurrentHashMap. #3654 (HTTPS client support) newly adds TlsFileWatcher with watchFilesMap…
elastic/elasticsearch#146780→#147796concurrencyBGrok 4.5HIT MEDIUMIncomplete ConcurrentHashMap / unsafe lazy map. #146780 (Hadoop-free Parquet path) introduces…
apache/pinot#9311→#13104concurrencyBGrok 4.5HIT HIGHTOCTOU / dual-path stats on one map of per-server counters. #9311 Adaptive Server Selection records…
apache/dubbo#9420→#9588concurrencyAGrok 4.5HIT MEDIUMResidual incomplete race fix (R2 exception). MetadataInfo.ServiceInfo#getMethodParameter lazy-inits…
apache/camel#21703→#22381concurrencyAGrok 4.5MISS no target match / cleared / emptySingle lock-order deadlock. CAMEL-20199 (#21703) replaced synchronized with ReentrantLock for…
apache/flink#22380→#22769concurrencyBGrok 4.5HIT MEDIUMSingle lock-order deadlock. FLINK-31773 (#22380) reworked DefaultLeaderElectionService lifecycle…
apache/hudi#17773→#19202concurrencyBGrok 4.5MISS no target match / cleared / emptyCross-thread close race on one iterator. #17773 adds Flink Source V2 stack (HoodieSourceSplitReader,…
apache/druid#8950→#19497concurrencyBGrok 4.5MISS no target match / cleared / emptyConcurrent init race on shared FileSystem. #8950 (native ORC batch ingestion) adds…
apache/bookkeeper#4609→#4737concurrencyAGrok 4.5HIT HIGHGet-then-async-then-remove race made fatal by recycle-null. #4609 (shared Netty recycler for…
lettuce-io/lettuce-core#3486→#3801correctnessAGrok 4.5HIT LOW#3486 (XREADGROUP CLAIM support) rewrote `StreamReadOutput.complete` to emit a `StreamMessage` when…
apache/commons-vfs#438→#773correctnessAGrok 4.5HIT LOW#438 (VFS-524 IPv6 URI parsing) taught `UriParser.decode` to set `ipv6Host=true` on any `[` and skip…
swagger-api/swagger-core#5004→#5205correctnessAGrok 4.5HIT MEDIUM#5004 adds `resolveArraySchemaWithCycleGuard` that calls `AnnotationsUtils.getArraySchema(...,…
apache/druid#15842→#19592correctnessAGrok 4.5HIT HIGH#15842 (Delta Kernel 3.1.0) rewrote `DeltaInputSourceIterator.hasNext` for multi-file scans: it took…
apache/pinot#14823→#15200correctnessAGrok 4.5HIT HIGH#14823 (MSQE cancellation + clientQueryId) makes engine `getRunningQueries()` return…
eclipse-store/store#755→#767correctnessAGrok 4.5HIT MEDIUM#755 (multi-channel GC pending-load gate) gives `StorageTaskBroker.Default` a **strong**…
apache/camel94847d8c4a84→#24802correctnessAGrok 4.5HIT HIGHCommit CAMEL-17049 (no PR; 2021-10-12) replaced `nestedParameters.putAll(this.parameters)` with a…
apache/pulsar#20607→#22685correctnessBGrok 4.5HIT MEDIUM#20607 adds `userCreatedProducerCount` and decrements it in `AbstractTopic.removeProducer`.…
apache/pinot#18237→#18941correctnessBGrok 4.5HIT MEDIUM#18237 adds `PlanNodeRoutingQueryBuilder` for MSE broker pruning. It folds every Filter/Project in the…
apache/camel#17092→#24746correctnessBGrok 4.5MISS no target match / cleared / empty#17092 (CAMEL-21733 Poll EIP DynamicAware) paths leave `GenericFileOnCompletion` re-evaluating the…
apache/hudi#4307→#8079dataBGrok 4.5HIT LOW`#4307` implemented `HoodieMetadataFileSystemView#reset`/`#sync` for metadata-table-backed FS views,…
apache/hudi#9723→#19075dataAGrok 4.5HIT LOWPartition TTL management `#9723` computes `ttlInMilis = writeConfig.getPartitionTTLStrategyDaysRetain()…
linkedin/venice#2468→#2622dataBGrok 4.5MISS findings lack GT keywords ['broker', 'fabric', 'global', 'source']Spark KIF repush enablement `#2468` sets source-broker address via `setInputConf()` into **both**…
opensearch-project/OpenSearch#19793→#22193dataBGrok 4.5HIT MEDIUM`#19793` removes legacy Elasticsearch version support so `Version.fromId()` throws…
apache/accumulo#6077→#6166dataAGrok 4.5HIT LOW`#6077` added `ServiceLock.deleteLock(..., path, ...)` that `zoo.recursiveDelete(path)` on the…
trinodb/trino#18332→#18789dataAGrok 4.5HIT LOWDelta Lake metadata-only DELETE pushdown `#18332` adds `executeDelete` for enforceable…
brettwooldridge/HikariCP60c4aa0fb1c1→#2346correctnessAGrok 4.5HIT HIGHCommit `60c4aa0` ("fixes #2323 … get/setSchema behavior") rewrote `ProxyConnection.setSchema` so…
apache/struts#1625→#1775concurrencyAGrok 4.5HIT MEDIUM#1625 (WW-5618) adds `StrutsJSONReader` with DoS limits (`maxDepth`/`maxElements`/…) and injects…
open-telemetry/opentelemetry-java#6924→#8504correctnessAGrok 4.5HIT MEDIUM#6924 adds default getters on `ReadWriteLogRecord` for binary compatibility.…
open-telemetry/opentelemetry-java#6429→#8493correctnessAGrok 4.5HIT MEDIUM#6429 "Low allocation OTLP logs marshaler" adds `LogStatelessMarshaler`, which passes the `TraceFlags`…
apache/httpcomponents-core#513→#674performanceAGrok 4.5HIT MEDIUM#513 (HTTPCORE-775) "fixed" `SSLIOSession::write` BUFFER_OVERFLOW by expanding the encrypted output…
resilience4j/resilience4j#1557→#2478correctnessAGrok 4.5HIT HIGH#1557 adds `HedgeConfig` + `Builder(HedgeConfig baseConfig)` used by `HedgeConfig.from(...)`. Copy ctor…
deephaven/deephaven-csv#309→#310performanceBGrok 4.5MISS no target match / cleared / empty#309 adds opt-in CSV escape-character support in `DelimitedCellGrabber` quoted/unquoted scan loops. The…
open-telemetry/opentelemetry-java#5246→#8565securityAGrok 4.5HIT MEDIUMWith only client mTLS configured (`setClientTls` / autoconfig key material, no custom trust store),…
fabric8io/kubernetes-client#3857→#7953correctnessAGrok 4.5HIT MEDIUMJDK HTTP client backend only calls `HttpRequest.Builder.method(...)` inside the `body != null` branch.…
zxing/zxing2179c52ee3→#2110securityAGrok 4.5HIT MEDIUM`URIResultParser.isPossiblyMaliciousURI` uses `USER_IN_HOST.find()` where `:` is inside the userinfo…
camunda/camunda#43503→#58326performanceAGrok 4.5HIT MEDIUM#43503 replaces top_hits aggregation with scroll in `ElasticsearchProcessStore.getProcessesGrouped` /…
hiero-ledger/hiero-mirror-node#12943→#13162performanceAGrok 4.5HIT LOW#12943 rewires web3 exchange-rate loading (`SystemFileLoader`, singletons, `ExchangeRateManager`) so…
elastic/elasticsearch#147176→#152938performanceBGrok 4.5HIT MEDIUM#147176 adds `ImplicitPrivilegesProvider` SPI. Providers receive stored…
eclipse-openj9/openj9#20111→#24042performanceAGrok 4.5MISS no target match / cleared / empty#20111 adds off-heap / dual-header awareness in DDR (`J9IndexableObjectHelper` et al.).…
apache/druid#16511→#16740performanceBGrok 4.5HIT LOW#16511 deserializes group-by dimensions over the wire into their **typed** complex forms via…
apache/knox#1258→#1300securityAGrok 4.5HIT MEDIUMPR #1258 adds `RolesLookupBypassControl` so internal Knox LDAP searches can skip the roles-rewrite…
AsyncHttpClient/async-http-client7136391a05→#2245securityAGrok 4.5HIT HIGH`perConnectionAuthorizationHeader` for origin KERBEROS/SPNEGO picks `proxyServer.getHost()` whenever a…
AsyncHttpClient/async-http-client63d4ba7702→#2239securityAGrok 4.5MISS no target match / cleared / empty`Uri` constructor sets `secured = HTTPS.equals(scheme) || WSS.equals(scheme)` (case-sensitive) while…
opensearch-project/OpenSearch#22073→#22245securityBGrok 4.5HIT MEDIUM#22073 installs process-wide `ObjectInputFilter` reject-all in `Bootstrap.setup()` only. Nodes started…
apache/struts#1657→#1773securityBGrok 4.5HIT MEDIUMAfter WW-5624, JSON body population authorized `@StrutsParameter` but still skipped the shared…
apache/cxf#3157→#3256securityBGrok 4.5HIT LOW#3157 sets `ACCESS_EXTERNAL_SCHEMA=""` so schema resolution routes through SchemaLSResourceResolver →…
eclipse-vertx/vertx-grpc#126→#285performanceAGrok 4.5HIT MEDIUMgRPC frame reassembly compact-every-frame super-linear cost
apache/iceberg#11656→#12305performanceAGrok 4.5MISS no target match / cleared / emptyParquet 1.15 no-arg builder loads full Hadoop Configuration on every reader init
apache/pulsar#17371→#25732correctnessAGrok 4.5MISS adjacent shadow lifecycle; retain leak not filedShadowReplicator.replicateEntries retains headersAndPayload ByteBuf before sendAsync; with…
eclipse-openj9/openj9#23890→#24049correctnessAGrok 4.5HIT HIGHpostCompilationTasks tracks unstored AOT bytes with ineligibleForRelocatableCompile ==…
apache/druid#14435→#14643concurrencyAGrok 4.5HIT HIGHKubernetesTaskRunner #14435 removed synchronized(tasks) around ConcurrentHashMap…
alibaba/nacos#9914→#14916concurrencyAGrok 4.5HIT HIGH#9914 adds CachedJwtTokenManager (token performance cache) with ConcurrentHashMap userMap/tokenMap and…
apache/pinot#14237→#18559concurrencyBGrok 4.5HIT HIGH#14237 reworked IdealStateGroupCommit failure handling (Entry._exception, re-queue processed entries)…
apache/camel#11275→#24872concurrencyBGrok 4.5MISS no target match / adjacent / empty#11275 ("make aws streaming thread safe") partially synchronized uploadAggregate batching but left…
opensearch-project/OpenSearch#20359→#22358concurrencyBGrok 4.5HIT HIGH#20359 stream-transport refactor reworks FlightTransportResponse and adds openAndPrefetchAsync:…
apache/camel#14823→#24727concurrencyBGrok 4.5HIT HIGH#14823 fixes getInOnlyTemplate to check inOnlyTemplate (was wrongly checking inOutTemplate) but leaves…
apache/hudi#17717→#18834concurrencyBGrok 4.5HIT HIGH#17717 made RocksDBDAO serializers ConcurrentHashMap to allow multi-threaded Timeline Service access…
elastic/elasticsearch#114719→#153213correctnessAGrok 4.5HIT HIGHInferenceWaitForAllocation.WaitingRequest derived deploymentId() from request.getId() (may be…
elastic/elasticsearch#146576→#148503correctnessAGrok 4.5HIT HIGHWith routing as sorted doc values, LuceneChangesSnapshot filled ParallelArray.routingOrdinals only on…
elastic/elasticsearch#142170→#148754correctnessAGrok 4.5HIT HIGHCanMatchPreFilterSearchPhase empty-shards short-circuit returned Collections.emptyMap() for…
apache/maven-resolver#1785→#1948correctnessAGrok 4.5HIT HIGHJettyTransporter set connectTimeout from getHttpRequestTimeout (same as requestTimeout), so connect…
trinodb/trino#22102→#30355correctnessAGrok 4.5HIT HIGHDelta Lake deletion-vector writer double-counted the 4-byte bitmap key in sizeInBytes…
apache/pinot#14229→#18959correctnessBGrok 4.5MISS no target match / adjacent / emptyJsonIndexConfig added _indexPaths (later _maxBytesSize) without equals/hashCode updates; configs…
apache/iceberg#11415→#15087dataAGrok 4.5MISS no target match / adjacent / emptyShreddedObject.SerializationState constructor param shreddedFields shadowed the instance field; partial…
apache/iceberg#11415→#17066dataAGrok 4.5MISS no target match / adjacent / emptyShreddedObject.put left prior remove marker in removedFields; remove-then-put made get/fieldNames…
apache/iceberg#11144→#17210dataAGrok 4.5HIT HIGHTableMaintenance.Builder defaulted uidSuffix to UUID.randomUUID(); Flink savepoint restore of…
apache/hive#5973→#6423correctnessAGrok 4.5MISS no target match / adjacent / emptyCREATE TABLE moved to DDLSemanticAnalyzerFactory but SemanticAnalyzer.materializeCTE still new…
camunda/camunda#41694→#44866performanceAGrok 4.5HIT HIGHIntent.fromProtocolValue linear enum scan after #41694 simplify; fix #44866 O(1) Int2ObjectHashMap.
apache/iceberg#5505→#8297performanceAGrok 4.5HIT HIGHDefaultCounter Math.addExact(counter.longValue(), amount) multi-thread hot path; fix removes addExact.
trinodb/trino#7875→#8559performanceAGrok 4.5MISS no target match / adjacent / emptyJdbcPageSink auto-commit simplify causes multi-commit write regression on MySQL/SQL Server.
elastic/elasticsearch#147562→#151102securityAGrok 4.5HIT HIGHDatasetRewriter FROM <dataset> rewrote with always-open auth predicate before security filter; any…
elastic/elasticsearch#142325→#148263securityAGrok 4.5HIT HIGHResumeBulkByScrollRequest lacked CompositeIndicesRequest and reindex/resume was missing from RBAC…
elastic/elasticsearch#147562→#149963securityBGrok 4.5MISS no target match / adjacent / emptyDatasetRewriter.mergeSettings flattened datasource secrets into plan/EXPLAIN-facing config so…
micrometer-metrics/micrometer#4506→#4985correctnessAGrok 4.5HIT HIGH#4506 switched AnnotationHandler from Class.getMethod to getDeclaredMethod so @MeterTag works on…
apache/pekko#3164→#3201securityAGrok 4.5MISS no target match / adjacent / empty#3164 (hostname verification for classic remoting) was based on a branch that predated #3165's…
ebean-orm/ebean#3794→#3819dataAGrok 4.5HIT HIGH#3794 (DbJson support for DTO queries) rewrote createJsonObjectMapperType to take DeployProperty and…
apache/logging-log4j2#3508→#3773correctnessAGrok 4.5HIT HIGH#3508 fixed shutdownHook=disable by restructuring LoggerContext.start(Configuration): it only…
spring-projects/spring-bootad79c373f827→#50301securityAGrok 4.5HIT HIGHCommit ad79c373 ("Add SNI support to web server SSL auto-configuration") adds SslServerCustomizer SNI…
apache/curator#520→#1293correctnessAGrok 4.5HIT HIGH#520 (CURATOR-729 PersistentWatcher dead-loop fix) registers a CuratorListenable listener in…
apache/james-project#3065→#3069dataAGrok 4.5HIT HIGH#3065 improved mailbox rename by preloading the mailbox and children then renaming via…
ebean-orm/ebean#3779→#3790correctnessBGrok 4.5MISS no target match / adjacent / empty#3779 redesigned query metric/plan labels for secondary loads. Inline SQL comment labels that…
fabric8io/kubernetes-client#7898→#7920concurrencyAGrok 4.5HIT HIGH#7898 adds WatchRequestState.startedAtNs as a plain long, written in startWatch() *after* the volatile…
apache/kafka#17021→#21989performanceAGrok 4.5HIT HIGHKIP-1076 (#17021) adds StreamsThreadMetricsDelegatingReporter on stream-thread create but never removes…
trinodb/trino#18719→#30359performanceBGrok 4.5HIT HIGHAlluxio cache (#18719) AlluxioInputHelper always allocates a per-input page-sized readBuffer for…
elastic/elasticsearch#152515→#154280correctnessAGrok 4.5HIT HIGH#152515 rewrites TSDB numeric range as TwoPhaseIterator.intoBitSet but the no-skipper path does not cap…
open-telemetry/opentelemetry-java#7291→#8497correctnessAGrok 4.5HIT HIGH#7291 refactored Prometheus label conversion and JSON-encoded array point attributes, but left…
micronaut-projects/micronaut-core#12678→#12788correctnessAGrok 4.5HIT HIGH#12678 adds ApplicationContextConfigurationDelegate for CDI/bootstrap wrapping but does not forward…
quarkusio/quarkus#54245→#54832correctnessBGrok 4.5HIT HIGH#54245 migrates K8s/OpenShift volume generation to Fabric8 builders; secret/ConfigMap volume items…
elastic/elasticsearch#127661→#154644correctnessAGrok 4.5MISS no target match / adjacent / emptyMATCH_PHRASE (#127661) pushdown treats potentially unmapped fields as Lucene match_phrase, silently…
keycloak/keycloak#50315→#50415correctnessBGrok 4.5MISS no target match / adjacent / empty#50315 widens client-secret-rotation timestamps int→long (Y2K38) but breaks config/default paths that…
linkedin/venice#2809→#2927dataAGrok 4.5MISS no target match / adjacent / empty#2809 fixed one EOP leader-to-local latestProcessedVtPosition corruption but left a residual race:…
apache/ozone#2733→#10324concurrencyBGrok 4.5HIT HIGH#2733 adopts Hadoop EC CoderUtil with a static emptyChunk buffer. Concurrent ECKeyOutputStreams with…
alibaba/nacos#9461→#15226concurrencyBGrok 4.5MISS no target match / adjacent / emptyMaintainer-cited residual of #9461 null-guard pattern: ConfigRpcTransportClient.checkListenCache uses…
apache/pulsar#14648→#18818correctnessAGrok 4.5MISS no target match / adjacent / empty#14648 reworked LinuxBrokerHostUsageImpl NIC-speed handling; overrideBrokerNicSpeedGbps stopped being…
apache/iceberg#13191→#13386correctnessAGrok 4.5MISS no target match / adjacent / empty#13191 context-aware REST response parsing added an abstract method on BaseHTTPClient, breaking…
apache/pinot#16035→#17181performanceAGrok 4.5MISS no target match / adjacent / emptyPinotJoinPushTransitivePredicatesRule added default-on in #16035. On complex multi-predicate joins it…
quarkusio/quarkus#47414→#55353securityBGrok 4.5HIT HIGHDevMCP (#47414) exposes DevUI capabilities as an MCP server in dev mode but was not wired through the…
spring-projects/spring-kafka#3996→#4460correctnessBGrok 4.5MISS no target match / adjacent / emptyJackson 3 type-mapper (#3996) reverse lookup keyed on Class<?> identity misses when producer…
elastic/elasticsearch#128531→#129107performanceAGrok 4.5MISS no target match / adjacent / empty#128531 made Limit combine small pages into larger ones to cut exchange overhead, but combined pages…
debezium/debezium#7471→#7488dataAGrok 4.5HIT HIT quote-backed (data)#7471 switched USE db in getEstimatedTableSize to execute() which commits and ends the snapshot…
hazelcast/hazelcast#11660→#12545performanceAGrok 4.5HIT HIT quote-backed (performance)Cleanup of ConcurrencyUtil.getOrPutSynchronized(..., ContextMutexFactory, ...) always called…
keycloak/keycloak#49975→#50223securityAGrok 4.5MISS no target match / adjacent / empty#49975 hardens SCIM ScimRealmResourceFactory bearer auth (500→401 when unauthenticated) but still…
apache/struts#1653→#1737securityAGrok 4.5MISS no target match / adjacent / emptySibling XSS encoding: #1653 HTML-encodes PostbackResult form action. ServletRedirectResult.sendRedirect…
spring-projects/spring-kafka#4382→#4435correctnessAGrok 4.5HIT HIT quote-backed (correctness)#4382 makes getStreamsConfiguration return this.properties.clone(); null properties → NPE. Fix #4435…
linkedin/venice#2840→#2927concurrencyAGrok 4.5HIT HIT quote-backed (concurrency)#2840 reverts the prior offset-corruption fix, re-landing leader VT offset updates that branch on live…
hazelcast/hazelcast#21517→#24844concurrencyAGrok 4.5HIT HIT quote-backed (concurrency)#21517 adds PartitionContainer.cleanUpOnMigration that filters maps via getRecordStore(mapName), which…
trinodb/trino#29763→#29877dataAGrok 4.5HIT HIT quote-backed (data)#29763 fixed nested-field equality-delete key collisions but left FlatEqualityDeleteFilter building…
keycloak/keycloak#46019→#46622performanceAGrok 4.5HIT HIT quote-backed (performance)RealmCacheSession.prepareCachedRealm gained a master-admin-role up-to-date check that, for every…
swagger-api/swagger-core#4975→#5005correctnessAGrok 4.5HIT HIT quote-backed (correctness)#4975 rewrites AnnotatedType.equals/hashCode dropping schemaProperty → property vs subtype cache…
FasterXML/jackson-databind#5772→#5853correctnessAGrok 4.5MISS no target match / adjacent / empty#5772 always type-wraps object-id references; for As.PROPERTY inclusion breaks…
hibernate/hibernate-orm#3498→#3694correctnessAGrok 4.5MISS shipped v0.38.12 slice (campaign stays MISS)PR #3498 added temp-table column annotations via column.getSqlTypeCode(metadata) without null-guard.…
apache/accumulo#1008→#1012correctnessAGrok 4.5HIT HIT quote-backed (correctness)#1008 adds Property.resolve() using isPropertySet and switches tablet WAL max via table config that did…
apache/bookkeeper#4462→#4701concurrencyAGrok 4.5HIT HIT quote-backed (concurrency)HandleFactoryImpl.getHandle: putIfAbsent without using winner; concurrent create returns wrong…
apache/ozone#9150→#9810dataAGrok 4.5MISS no target match / adjacent / emptyisSnapshotPurged() returned true when snapshot chain tableKey was null, so orphan-version cleanup…
apache/pinot#16615→#17723correctnessAGrok 4.5MISS shipped v0.38.12 slice (campaign stays MISS)#16615 adds disableSummary so rebalance can skip summary (summaryResult=null). Later…
keycloak/keycloak#49962→#50275securityAGrok 4.5HIT HIT quote-backed (security)#49962 rewrites SCIM discovery permissions and updates SchemaResourceTypeProvider.getAll() to…
apache/bookkeeper#1289→#4305concurrencyAGrok 4.5MISS no target match / adjacent / emptySingleDirectoryDbLedgerStorage.swapWriteCache clears hasFlushBeenTriggered before isFlushOngoing=true →…
elastic/elasticsearch#112026→#150789concurrencyAGrok 4.5MISS no target match / adjacent / emptyStreamingHttpResultPublisher.ApacheClientBackpressure: pauseProducer vs shutdownProducer TOCTOU under…
ebean-orm/ebean#3301→#3382dataAGrok 4.5MISS no target match / adjacent / emptyBulk update clear of PersistenceContext (#3301/#3295) removes parent before OneToMany lazy load when…
ebean-orm/ebean#3824→#3849dataAGrok 4.5MISS no target match / adjacent / emptyquery.exists() emits select exists(...) invalid as scalar on SQL Server/Oracle; wrap with case-when (+…
keycloak/keycloak#33326→#50098securityAGrok 4.5MISS no target match / adjacent / emptyAfter #33326 migrates FolderTheme.getResourceAsStream through ResourceLoader.getFileAsStream (normalize…
apache/cloudstack#12014→#13452correctnessAGrok 4.5HIT HIT quote-backed (correctness)#12014 always builds DataCenterDeployment with srcHost.clusterId for migration listing; previously…
apache/pinot#17892→#18139correctnessAGrok 4.5HIT HIT quote-backed (correctness)#17892 ServerGrpcChannelBackoffResetHandler else-branch always treats non-INIT as CALLBACK and…
ebean-orm/ebean#3324→#3818dataAGrok 4.5MISS no target match / adjacent / emptyON_CONFLICT_NOTHING parent insert can return 0 rows while cascade still inserts children → FK…
apache/doris#46879→#47409correctnessAGrok 4.5MISS no target match / adjacent / empty#46879 doDistribute early-returns when FE computes result in cloud mode without setting…
camunda/camunda#56690→#58110securityAGrok 4.5HIT HIT quote-backed (security)#56690 migrates Group processors to PermissionsBehavior.isAuthorized. Siblings…
apache/rocketmq#7500→#10517performanceAGrok 4.5HIT HIT quote-backed (performance)#7500 adds TransactionMetricsFlushService whose run loop only calls waitForRunning inside the…
apache/pinot#11092→#18089correctnessAGrok 4.5MISS shipped v0.38.12 slice (campaign stays MISS)#11092 multi-strategy FUNNEL_COUNT extractors dereference null DictIdsWrapper when WHERE empties…
elastic/elasticsearch#154186→#154476correctnessAGrok 4.5MISS no target match / adjacent / empty#154186 wraps SearchExecutionContext in EsqlSearchExecutionContext without registering…
apache/tika#2882→#2888correctnessAGrok 4.5MISS no target match / adjacent / emptyInteraction #2878 utf8Tolerated + #2882 mojibuster default → UTF-8 false positive on short Latin-1…
apache/cxf#646→#3297securityBGrok 4.5MISS no target match / adjacent / emptyDynamic Client Registration accepted client-requested OAuth scopes without allowlist validation…
elastic/elasticsearch#145628→#154447correctnessBGrok 4.5MISS no target match / adjacent / empty#145628 stores primaryTerm in failedShardsCache but resolves term at cache-update time from current…
apache/hudi#17694→#19126dataBGrok 4.5MISS no target match / adjacent / empty#17694 enabled MAP/ARRAY nested col-stats on schema/Parquet paths; MOR log-append AvroRecordContext…
camunda/camunda#53724→#57829correctnessBGrok 4.5MISS no target match / adjacent / empty#53724 priority job CF changes insert path; pre-8.10 job event appliers replay via new path → state…
camunda/camunda#56526→#58415correctnessBGrok 4.5MISS no target match / adjacent / empty#56526 routes post-importer-queue writes by partitionId; archiver treated any processedCount !=…
apache/kafka#13267→#22204concurrencyBGrok 4.5MISS no target match / adjacent / emptyRPCProducerIdManager: race between maybeRequestNextBlock and response-handler backoff clear → premature…
elastic/elasticsearch#79279→#148179securityBGrok 4.5HIT HIT quote-backed (security)#79279 lands ModifyDataStreams admin API (add/remove backing indices). Authorization treated it as a…
linkedin/venice#2821→#2838dataBGrok 4.5MISS no target match / adjacent / empty#2821 adds VPJ external-storage dual-write with a single global storageMode broadcast to all executors…
elastic/elasticsearch#120302→#128687performanceBGrok 4.5MISS no target match / adjacent / emptyDATE_TRUNC arbitrary-interval support threaded a multiplier into every DateTimeUnit.roundFloor path,…
apache/activemq-artemis#4724→#6480concurrencyBGrok 4.5HIT HIT quote-backed (concurrency)MQTTStateManager.getSessionState ConcurrentHashMap containsKey+get/put during link-steal → NPE
apache/pekko#1990→#3007concurrencyBGrok 4.5HIT HIT quote-backed (concurrency)#1990 migrates AbstractNodeQueue to VarHandle but uses plain VarHandle.get for tail/next reads — no…
apache/struts#1765→#1777securityBGrok 4.5MISS no target match / adjacent / empty#1765 adds WebJars static serving through DefaultStaticContentLoader/DefaultWebJarUrlProvider without…
apache/pulsar#9973→#24639concurrencyBGrok 4.5HIT HIT quote-backed (concurrency)MetadataStoreCacheLoader concurrent ChildrenChanged updates race availableBrokers list
netty/netty#10331→#10528performanceBGrok 4.5MISS no target match / adjacent / emptyNative SSLEngine session-cache support (#10331) landed client/server external session-cache wiring.…
micronaut-projects/micronaut-core#12636→#12729correctnessBGrok 4.5MISS no target match / adjacent / empty#12636 Introspected.Property + @JsonProperty mapping treats Groovy property fields as field accessors…
alibaba/nacos#3809→#14928concurrencyBGrok 4.5MISS no target match / adjacent / emptyClientServiceIndexesManager.removeSubscriberIndexes: non-atomic remove+isEmpty+map.remove loses…
apache/pinot#10322→#10432concurrencyBGrok 4.5MISS no target match / adjacent / emptyGrpcSendingMailbox: cancel races first onNext on unstarted gRPC stream after mailbox leak/cancel rework
FasterXML/jackson-databind#4988→#5844correctnessBGrok 4.5MISS no target match / adjacent / empty#4988 changes _constructStdTypeResolverBuilder signature; xml format module override breaks. Fix #5844…
apache/hudi#11084→#12325performanceAGrok 4.5HIT HIT quote-backed (performance)#11084 (HUDI-7660) rewrites RowDataKeyGen to cut excess StringBuilder/deleteCharAt work but introduces…
crate/crate#17946→#19449correctnessAGrok 4.5HIT HIT quote-backed (correctness)#17946 parallelized stale-index deletion and only schedules next cleanup on successful delete; a failed…
ebean-orm/ebean#2646→#2666correctnessAGrok 4.5HIT HIT quote-backed (correctness)#2646 made DeployInheritInfo.compareTo sort by discriminatorStringValue for deterministic DDL. Children…
apache/rocketmq#3619→#3632correctnessAGrok 4.5MISS shipped v0.38.12 slice (campaign stays MISS)#3619 rewrote buildStatsKey to pre-size StringBuilder with topic.length()+group.length(). When topic or…
apache/pulsar#13023→#15162performanceAGrok 4.5MISS no target match / adjacent / empty#13023 forces triggerListener onto internalPinnedExecutor (and makes messageReceived call…
apache/logging-log4j2#315→#4125correctnessAGrok 4.5MISS no target match / adjacent / empty#315 added KafkaAppender retryCount. On successful retry the loop break's out of the while but still…
apache/struts#1773→#1784securityAGrok 4.5MISS no target match / adjacent / empty#1773 adds accepted-name/ParameterNameAware filtering to JSONInterceptor but evaluates allowlist checks…
micro-manager/micro-manager#2377→#2378correctnessAGrok 4.5MISS no target match / adjacent / empty#2377 replaced JComboBox ActionListeners with PopupMenuListener snapshot logic to stop spurious…
apache/helix#2604→#2669concurrencyAGrok 4.5HIT HIT quote-backed (concurrency)filterOutEvacuatingInstances does instanceConfigMap.get(instance).getInstanceOperation() without…
ebean-orm/ebean#3759→#3847correctnessAGrok 4.5HIT HIT quote-backed (correctness)#3759 made DatabaseFactory.create() with register(true) return the already-registered Database under…
powsybl/powsybl-open-loadflow#1394→#1461correctnessAGrok 4.5HIT HIT quote-backed (correctness)#1394 changed equation derivative term sort from variable.getRow() to variable.hashCode(). Hash order…
Jikoo/OpenInv#311→#414correctnessAGrok 4.5HIT HIT quote-backed (correctness)#311 extracted per-inventory match into SearchHelper.findMatch but left break in the outer player loop…
apache/pekko#3030→#3373performanceAGrok 4.5HIT HIT quote-backed (performance)#3030's releaseStage() nulls connection refs during finalization and sets a pendingFinalization flag…
micronaut-projects/micronaut-core#12632→#12740correctnessAGrok 4.5MISS no target match / adjacent / empty#12632 made RequestBeanAnnotationBinder skip instantiation whenever no request values bound (if…
opensearch-project/OpenSearch#4041→#22376correctnessAGrok 4.5HIT HIT quote-backed (correctness)#4041 made ReplicationCheckpoint Comparable with return isAheadOf(other) ? -1 : 1 — equal checkpoints…
apache/helix#2180→#2776correctnessAGrok 4.5HIT HIT quote-backed (correctness)#2180 reused the builder-supplied ZkClient in BestPossibleExternalViewVerifier. Callers often configure…
apache/paimon#6354→#8305dataAGrok 4.5MISS no target match / adjacent / empty#6354 adds parent_id to Iceberg snapshots but hardcodes null in createMetadataWithoutBase; after…
apache/pinot#16812→#18850dataAGrok 4.5MISS no target match / adjacent / emptygetValidDocIdsType overrides user SNAPSHOT to SNAPSHOT_WITH_DELETE when delete enabled; compaction…
apache/pulsar#23236→#25732correctnessAGrok 4.5MISS no target match / adjacent / empty#23236 deserializes ShadowReplicator source entries with empty payload while still retain()ing…
crate/crate#17943→#19326performanceAGrok 4.5HIT HIT quote-backed (performance)#17943 re-implemented bulk BackoffPolicy on streams and changed aggressiveness of retries for…
grpc/grpc-java#7696→#7778correctnessAGrok 4.5HIT HIT quote-backed (correctness)#7696 xDS CDS parsing for EDS clusters only added edsServiceName to edsResources when non-empty. When…
ebean-orm/ebean#2309→#2316correctnessAGrok 4.5MISS shipped v0.38.12 slice (campaign stays MISS)#2309's ScalarTypeJsonList/Set.formatValue called value.isEmpty() without null check. Setting a JSON…
apache/beam#31128→#31685correctnessAGrok 4.5MISS no target match / adjacent / empty#31128 added queryTempProject to BigQueryIO TypedRead config translation and always read…
apache/pinot#10000→#10356performanceAGrok 4.5HIT HIT quote-backed (design)#10000 adds AggregationFunctionUtils.buildFilteredAggTransformPairs for filtered aggs + GROUP BY. The…
apache/logging-log4j2#3199→#3418performanceAGrok 4.5MISS no target match / adjacent / empty#3199 introduces InternalLoggerRegistry.computeIfAbsent that takes the write lock and then calls…
resilience4j/resilience4j#672→#824correctnessAGrok 4.5MISS no target match / adjacent / empty#672 added weighted permits to AtomicRateLimiter; nanosToWaitForPermission used truncating integer…
ebean-orm/ebean#2617→#2763correctnessAGrok 4.5MISS no target match / adjacent / empty#2617 added JsonContext.toJson(bean, targetBean) but property jsonRead paths still used setValue…
apache/beam#36631→#38894correctnessAGrok 4.5MISS no target match / adjacent / empty#36631 abort-on-close path throws ReadLoopAbortedException (extends InterruptedException) then re-sets…
powsybl/powsybl-core#2648→#2733correctnessAGrok 4.5HIT HIT quote-backed (correctness)#2648 made 3-winding transformer ratedS optional in CGMES import but InterpretedWinding.ratedS stayed…
linkedin/venice#2704→#2788correctnessAGrok 4.5MISS no target match / adjacent / empty#2704's createStoreMetadataFetcher hard-wires D2TransportClient(clientConfig.getD2Client(),…
debezium/debezium#6222→#6313performanceAGrok 4.5HIT HIT quote-backed (performance)#6222 centralized sensitive-data logging through Loggings helpers used on hot enqueue/convert paths.…
fabric8io/kubernetes-client#4365→#4643concurrencyAGrok 4.5MISS no target match / adjacent / empty#4365 added Watcher exception-handler support and reworked…
alibaba/nacos#9820→#14988concurrencyAGrok 4.5HIT HIT quote-backed (concurrency)ConfigChangeConfigs.configPluginProperties: non-volatile Map reassigned on ServerConfigChangeEvent +…
apache/paimon#3739→#8788dataAGrok 4.5MISS no target match / adjacent / emptycreateWithDeleteManifestFileMetas keeps entry.snapshotId() on DELETED entries (add snapshot) instead of…
ebean-orm/ebean#2411→#2437dataAGrok 4.5HIT HIT quote-backed (data)#2411 introduced weak-reference BeanRef persistence context for streaming queries. When a key is put…
apache/druid#19571→#19615dataAGrok 4.5MISS no target match / adjacent / empty#19571 adds DimensionValueSetShardSpec for streaming segments; upgrade path in…
elastic/elasticsearch#149063→#154675correctnessAGrok 4.5MISS no target match / adjacent / empty#149063 (No subobjects for columnar modes) made strict columnar modes throw MapperParsingException on…
linkedin/venice#2444→#2800dataAGrok 4.5MISS no target match / adjacent / empty#2444 adds blobDbEnabled getters/setters but omits cloneVersion copy; every RMW via ZK clone wipes…
keycloak/keycloak#30966→#50182securityAGrok 4.5HIT HIT quote-backed (security)#30966 SD-JWT verification: validateViaRecursiveDisclosing inserts each Disclosure with…
micronaut-projects/micronaut-core#10402→#12753securityAGrok 4.5HIT HIT quote-backed (security)#10402 lands pure-Java DefaultServerCookieEncoder/DefaultClientCookieEncoder that concatenate cookie…
ClickHouse/clickhouse-java#2579→#2629correctnessAGrok 4.5MISS no target match / adjacent / empty#2579's JDBC-v2 parser work added DriverProperties.SQL_PARSER allowed values via List.of(...). List.of…
apache/paimon#3731→#5209dataBGrok 4.5MISS no target match / adjacent / emptyIcebergCommitCallback not wired into DropPartition's AbstractFileStore#newCommit(commitUser)…
apache/doris#56423→#64412correctnessAGrok 4.5HIT HIT quote-backed (correctness)#56423 adds baseViewsOneLevel on MTMVRelation without null-safe getter. Pre-feature MTMVs load null →…
alibaba/nacos#13001→#15002concurrencyAGrok 4.5HIT HIT quote-backed (concurrency)NacosServerAuthConfig.authPluginProperties: non-volatile map reassignment from refresh +…
OpenIdentityPlatform/OpenDJ7e3a75903159→#651securityAGrok 4.5MISS no target match / adjacent / emptyCVE-2026-46495 hardening commit set both jmx.remote.rmi.server.credential.types and…
apache/cxf#3126→#3294securityBGrok 4.5MISS no target match / adjacent / empty#3126 hardens JwtAccessTokenValidator with issuer + JwtUtils.validateTokenClaims (expiry/nbf/audience)…
opensearch-project/OpenSearch#22021→#22148concurrencyBGrok 4.5MISS no target match / adjacent / emptyRefresh flushQueue: if writer.flush() throws, writer is not closed → NativeFSLockFactory LOCK_HELD leak…
apache/pekko#3035→#3116concurrencyBGrok 4.5MISS no target match / adjacent / empty#3035 moved LazyDispatch scheduling state to a VarHandle-backed field but instance access modes were…
elastic/elasticsearch#115667→#120617securityBGrok 4.5HIT HIT quote-backed (security)#115667 adds index-mode LOOKUP loading via AbstractLookupService: index privilege check then…
vert-x3/vertx-ignite#158→#165concurrencyBGrok 4.5HIT HIT quote-backed (concurrency)#158 switched subscription-map updates to Ignite map.invoke for linear-time search, but registration…
ebean-orm/ebean#2996→#3006correctnessAGrok 4.5HIT HIT quote-backed (correctness)RawSql + default select: after #2996, DefaultServer still setDefaultSelectClause for LAZY *ToOne so…
ebean-orm/ebean#2978→#3014correctnessAGrok 4.5HIT HIT quote-backed (correctness)CallStack(List<StackFrame>) hashes StackFrame.hashCode() which is identity-based → unstable AutoTune…
testcontainers/testcontainers-java#7714→#7820correctnessAGrok 4.5HIT HIT quote-backed (correctness)GenericContainer.setImage only updates ContainerDef; this.image stale so create still uses old image
apache/kafka#22493→#22529concurrencyAGrok 4.5MISS adjacent AllBrokers retry; close race emptyStale-leader recovery re-enqueues via runnable during AdminClient.close grace → rejected instead of…
apache/amoro#4182→#4185concurrencyAGrok 4.5MISS empty trio — treated as Iceberg 1.7 fixops.current→refresh made createTable post-create commit race background tableExplorerScheduler → dual…
FasterXML/jackson-databind#3724→#5974securityAGrok 4.5MISS adjacent dual-path ignore; not naming-strategy CVERecord @JsonIgnore recorded under pre-rename name; PropertyNamingStrategy rename leaves ignore set…
apache/paimon#5751→#8783dataAGrok 4.5HIT HIT quote-backed (data)FileRewriteCompactTask never attaches CompactDeletionFile after DV rewrite — orphan DV index metadata
ebean-orm/ebean#3155→#3223dataAGrok 4.5MISS adjacent IdBinder residual; not Formula matchIdClass name-match treated @Formula properties as imported matches → INSERT with formula placeholders…
elastic/elasticsearch#94564→#120133performanceAGrok 4.5MISS adjacent unconditional scoring; not two-phase advanceMatchedQueriesPhase Scorer.iterator().advance walks expensive two-phase second phase (e.g. geo) →…
apache/pulsar#21081→#21647performanceAGrok 4.5HIT HIT quote-backed (performance)phaseTwoLoop skip arm for messageId<=lastCompacted never m.close() → RawMessage/ByteBuf leak on…
quarkusio/quarkus#30620→#30709correctnessAOpus 5HIT HIT quote-backed (correctness)BuildTimeConfigurationReader.ReadResult.run() drops the `continue` after each pattern-map match but…
apache/kafka#12366→#13723correctnessAOpus 5HIT HIT quote-backed (correctness)MirrorConnectorConfig.sourceConsumerConfig(Map) was rewritten from…
apache/iceberg#10433→#11335correctnessAOpus 5HIT HIT quote-backed (correctness)S3InputStream's new Failsafe RetryPolicy hooks the stream re-open on .onFailure(failure ->…
apache/flink#25130→#25569correctnessAOpus 5HIT HIT quote-backed (correctness)SplitFetcherManager.close(long) gained a drain task whose loop body is…
apache/solr#1827→#2045correctnessAOpus 5HIT HIT quote-backed (correctness)RequestUtil.processParams' JSON "query" branch unconditionally does newMap.put(QueryParsing.DEFTYPE,…
apache/ozone#8557→#10850correctnessAOpus 5HIT HIT quote-backed (correctness)S3LifecycleConfiguration.convertFromOzoneExpiration does `if (ozoneExpiration.getDays() > 0)` on a…
camunda/camunda#35742→#58075dataBOpus 5HIT HIT quote-backed (data)The ES 8.16.6 Java client migration replaced the exact JsonData.of(long) range bound in…
trinodb/trino#13757→#14094performanceAOpus 5HIT HIT quote-backed (performance)ParquetReader's `private final long[] maxBytesPerCell` became a Map<Integer,Long> initialised empty,…
trinodb/trino#12968→#21445performanceAOpus 5HIT HIT quote-backed (performance)EventListenerManager.queryCompleted(QueryCompletedEvent) became queryCompleted(Function<Boolean,…
trinodb/trino#15374→#15552performanceAOpus 5HIT HIT quote-backed (performance)PR #15374 added lib/trino-parquet/.../reader/ChunkedInputStream.java, whose whole purpose is reading a…
quarkusio/quarkus#33984→#41049correctnessBOpus 5HIT HIT quote-backed (correctness)QuteProcessor#validateExpressions' new 'register all param declarations as targets of implicit value…
quarkusio/quarkus#43308→#44817correctnessAOpus 5HIT HIT quote-backed (correctness)MethodsCandidate.isShared(EvalContext) loops over context.getParams() and does `if (param.isLiteral())…
spring-projects/spring-bootb02f7ddea361→?correctnessAOpus 5HIT HIT quote-backed; validity SKIP-unresolvable (commit-sha fix)ServletContextInitializers#configureSessionCookie replaced the `.as(Object::toString)` mapping with…
spring-projects/spring-framework41cd6879bde4→?correctnessAOpus 5HIT HIT quote-backed; validity SKIP-unresolvable (commit-sha fix)MimeTypeUtils#parseMimeTypeInternal's quoted-pair fix changed `else if (ch == '"')` to `else if (ch ==…
spring-projects/spring-frameworke58ba2c66593→?correctnessBOpus 5HIT HIT quote-backed; validity SKIP-unresolvable (commit-sha fix)DefaultRestClient gained `isStreamingResult(Object result)` returning (result instanceof InputStream ||…
apache/pulsar#11737→#12993concurrencyAOpus 5HIT HIT quote-backed (concurrency)PR #11737 added `this.recycle();` inside OpAddEntry.failed(). OpAddEntry is a Netty Recycler-pooled…
apache/bookkeeper#2794→#3513concurrencyBOpus 5HIT 2-of-3; correctness cleared the blocking closePR #2794 added a private closeLedgerHandle() to LedgerOpenOp that calls the BLOCKING lh.close() (its…
mybatis/mybatis-3#3349→#3375dataAOpus 5HIT 2-of-3; design cleared it on the top-level joinerXMLScriptBuilder.parseDynamicTags added `if (data.trim().isEmpty()) { continue; }` before building a…
mybatis/mybatis-3#2804→#2841dataAOpus 5HIT 3/3 on the shared-helper blast radius that forced the revertMapperBuilderAssistant.resolveResultJavaType changed constructor-arg type resolution from…
apache/hudi#755→#927dataBOpus 5HIT 3/3 on copy-on-get losing the avro read schemaSerializableConfiguration.get() returns `new Configuration(configuration)` — a fresh defensive copy per…
apache/pulsar#20337→#20369concurrencyBOpus 5HIT 3/3 sweep on the brokerMeta empty-path leak#20337 added brokerMeta = payload.readRetainedSlice(...) to RawBatchConverter.rebatchMessage. The extra…
micronaut-projects/micronaut-core#5306→#5467concurrencyBOpus 5HIT 3/3 on the shared static SafeConstructor; 2 under-rated MEDIUMThe startup-performance refactor hoisted the SnakeYAML SafeConstructor into a `private static final`…
apache/kafka#16837→#17434correctnessBOpus 5HIT 2-of-3; api-ops considered the timer and declined itKafkaRaftClient.pollFollowerAsVoter gained an else-if arm whose body is the only caller of…
apache/iceberg#11052→#11274correctnessBOpus 5HIT 3/3 on the overrideConfiguration Consumer overload clobberS3FileIOProperties.applyRetryConfigurations(T builder) calls builder.overrideConfiguration(config ->…
apache/flink#22928→#22977correctnessBOpus 5HIT 3/3 on both halves + the compiled-plan serde gapDefaultCatalogTable gained a @Nullable Long snapshot field and a 5-arg constructor. Both copy()…
trinodb/trino#9766→#10954performanceBOpus 5HIT 1-of-3; only the owning finder saw the per-request parser rebuild#9766 "Update to latest JWT apis" rewrote every Jwts.parser() call site to…
trinodb/trino#13178→#13415performanceCOpus 5HIT 1-of-3; owning finder sized the ~2.5-3x hash-memory regression#13178 added specialized hash-table/pages-index classes for the single-bigint-column join key path. The…
apache/solr#529→#3259performanceCOpus 5MISS correctness cleared the file as a faithful port; WEAK adjudicationValueSourceRangeFilter.ValueSourceRangeWeight.scorer — #529 rewrote the class onto ConstantScoreWeight…
datahub-project/datahub#10932→#11309correctnessBOpus 5HIT 2-of-3; design cleared the dual pathescapeForwardSlash() dropped one escaping level in two files but left the consumer constant…
quarkusio/quarkus#34420→#35555correctnessAOpus 5HIT 3/3 on both null arms incl. the Gizmo.equals operand orderValueResolverGenerator.java — "use shared constants for booleans, enums and nulls" added two return…
apache/kafka#13424→#13548correctnessAOpus 5HIT 3/3 on the namespacedUrl typo the split diff hidKIP-875 split DistributedHerder's task-config publishing into publishConnectorTaskConfigs(...) and the…
apache/seatunnel#11127→#11165correctnessBOpus 5HIT 3/3 on the enforcement regression; all 3 missed the URL-validator armPR #11127 made FactoryUtil.createOptionalCatalog() enforce optionRule() during catalog creation. Fix PR…
spring-projects/spring-framework6e9758700a49→?correctnessAOpus 5MISS api-ops named it in its attestation and triaged it away as LOW/NITServerSentEvent.java#BuilderImpl — the SSE hardening adds checkEvent(id)/checkEvent(event) where…
mybatis/mybatis-3#3247→#3334dataAOpus 5HIT 3/3 on the narrowed java.sql.Date return typePR 3247 ('encapsulation code to method level for reuse') refactored DateOnlyTypeHandler, replacing…
apache/shardingsphere#35520→#35527dataAOpus 5HIT 3/3 on the inlined parse binding to the param, not the fieldIn ShardingSpherePreparedStatement's private constructor, #35520 replaced the helper call…
apache/shardingsphere#38411→#38455dataBOpus 5HIT 2-of-3; design cleared it as "a clear improvement"#38411 changed WithSegmentBinder.bind's third argument from an externalTableBinderContexts map to the…
keycloak/keycloak#40272→#40964securityAOpus 5HIT 3/3 on the unguarded feature-dependent flow stepsDefaultAuthenticationFlows.browserFlow() unconditionally appends two AuthenticationExecutionModel steps…
keycloak/keycloak#46062→#48835securityAOpus 5HIT 3/3; WEAK adjudication (fix cites the issue, not the PR)The new OrganizationGroupMembershipMapper.resolveFromRequestedScopes(...) does `OrganizationScope scope…
keycloak/keycloak#29967→#33797securityAOpus 5HIT 3/3 on the wrong instanceof receiver in the docker filterThe DPoP epic added `.filter(mapper -> mapper instanceof DockerAuthV2AttributeMapper)` to…
jenkinsci/jenkins#7398→#10065securityBOpus 5HIT 1-of-3; security finder framed the narrowing as a BENEFITPR #7398 rewrote ZipExtractionInstaller.DescriptorImpl.doCheckUrl from the protocol-agnostic…
apache/uniffle#2735→#2737concurrencyAOpus 5HIT 2-of-3; correctness framed it as a leak, not the deadlock#2735 added an Optional<Semaphore> segmentPermits to DecompressionWorker to cap in-flight decompressed…
apache/gravitino#8553→#9086concurrencyAOpus 5HIT 2-of-3; WEAK adjudication (issue names file, not PR)#8553 added AuthorizationRequestContext.java with a loadRole(Runnable) method whose body is a…
apache/pulsar#23062→#24401concurrencyBOpus 5MISS 3/3 CLEARED the executor downgrade that arms the deadlock#23062 added TableView.java whose readLatest(String topic) drives snapshot replay through a private…
apache/pulsar#23901→#23958concurrencyCOpus 5MISS full weight — pattern predates #23901 but the async limiter arms it; 3/3 ran the inversion check and cleared it#23901 rewrote PendingReadsManager.PendingRead, introducing attach(CompletableFuture<List<EntryImpl>>)…
FasterXML/jackson-databind#4467→#4744correctnessAOpus 5HIT 2-of-3; design cleared the hunk as correctPropertyBuilder.buildWriter handles JsonInclude.Include.NON_DEFAULT in two modes the surrounding code…
open-telemetry/opentelemetry-java#4325→#8613correctnessAOpus 5HIT 3/3; WEAK adjudication stratum (fix never cites the intro PR)ArrayBasedTraceStateBuilder.remove(String) — #4325 replaced physical list removal with a tombstone…
testcontainers/testcontainers-java#2473→#2490correctnessBOpus 5HIT 3/3, each enumerating the same four broken modulesThe refactor moved per-module port exposure out of the start-time configure() hook into constructors,…
apache/lucene#1017→#11825performanceAOpus 5HIT 1-of-3; correctness+design both cleared the un-hoisted visitorIn lucene/core/src/java/org/apache/lucene/document/SpatialQuery.java, #1017's own diff deleted the…
apache/druid#6677→#8024performanceBOpus 5HIT 3/3; WEAK adjudication (maintainer issue comment, not the fix body)#6677 ('FileUtils: Sync directory entry too on writeAtomically') re-routed CompressionUtils.zip(...)…
opensearch-project/security#1698→#2052securityAOpus 5HIT 3/3; OVERSIZED 62-file intro (R1+R8) + a disclosed fabricated-payload incidentIn src/main/java/org/opensearch/security/tools/SecurityAdmin.java, method execute(String[]), the…
apache/seatunnel#3499→#5579correctnessAOpus 5HIT 2-of-3; design cleared the inverted order; WEAK adjudication stratumSeaTunnelRowDebeziumDeserializationConverters.convert(): `Object fieldValue = struct.get(fieldName);`…

Grade — how directly the defect sits on the introducing diff: A a pointable wrong line, B in the added code but subtler, C the wrongness lives in a file the diff doesn't touch. Two candidates were dropped before scoring as mis-attributed by the fix PR (verified byte-identical to their parent) and aren't counted. Raw data (JSON) →

◆

How it improves

A miss on a mined pair isn't a dead end — the maintainers already adjudicated it, so it's a training signal. Each upgrade below was driven by a specific missed regression from the table above, and validated against clean code before it shipped.

missed incomplete wiring / O(n·m) purge / clear-then-fail os-15579 · keycloak-47838 · netty-13237 · es-107567 v0.38.9

Incomplete control arm + List bulk ops + residual races

Mined MISSes on batches 54–63 clustered on three shapes: a new security control that never arms on the default path; List.removeAll(List) / always-on expensive work left outside the guarding conditional; and clearing a lifecycle flag before fallible work. Shipped failure patterns + brief hooks (and dual-path incomplete-fix for correctness). Blind A/B recovered four motivating pairs (os-15579, keycloak-47838, netty-13237, es-107567). es-150027 dual-path still partial — sibling early-return filed, maintainer maxDoc cap not yet.

missed multi-sibling residual pinot-7707 · nacos-14751 · pinot-12502 · es-112026 v0.38.11

Multi-sibling residual + dual-path + empty-then-remove

Rate-decade MISSes and high-HIT re-runs clustered on multi-sibling intros: finders filed a real secondary bug and missed the maintainer residual (CHM empty-then-remove after a partial race fix, dual-path TLS/ClientAuth, continueOnError drop, inverted compare). The finder prompt now prioritizes those residual families after any first finding; concurrency/correctness/security briefs name the tells. Clean fixture 0 FPs; historical pre→post product rescore recovered 6/18 prior flips; generalization on banked MISSes es-112026 and ozone-9150. Does not claim residual rate decades are fixed — only this pattern family.

missed null on a newly opened path ebean-2309 · rocketmq-3619 · paimon-6046 · beam-24757 · quarkus-26783 v0.38.12

Null on a path this PR newly opens

Correctness MISSes clustered on ordinary NPEs: a diff introduces a branch or helper that assumes non-null (isEmpty(), .length(), unbox, method call) while a flag-off, upgrade, or sibling arm can still supply null. The correctness brief and failure catalog now name that tell explicitly. Clean fixture 0 FPs; same-day A/B OLD 4/5 → NEW 5/5 (rocketmq NEW-only lift on topic/group pre-size); fresh unseen pairs 4/6 HIT (paimon-6046, doris-22923, beam-24757, quarkus-26783). Campaign motivating pairs stay MISS in the headline count.

missed the severityapache/pulsar #24784, #24533v0.37.2

Severity, rated by consequence

The reviewer flagged a shutdown-path resource leak but rated it LOW. Now a throw on a cleanup or shutdown path is rated by what it costs on an unclean shutdown, not by how rarely it fires — and a defect that's inert under the default config but live under a supported extension point isn't discounted for that alone.

missed the raceapache/pulsar #25352v0.37.3

Async lifecycle interleavings

A change moved producer-creation callbacks onto an executor; a client timeout‑then‑retry then raced the delayed callback into building an orphan producer. Now, when a diff shifts async timing around a request lifecycle, the reviewer enumerates the out-of-diff events — timeout, cancel, retry, close — that could newly interleave.

missed the orderingapache/pulsar #20990v0.37.5

Reordered side effects

A moved decrement ran an unblock check before the count it reads was updated, leaving a consumer blocked forever at a boundary config. Now a diff that changes when a side effect happens relative to code that observes it is checked against every intermediate reader.

missed the stalenessapache/pulsar #22411 · elasticsearch #138489v0.38.1

Stale snapshot across a concurrent writer

An optimistic-lock version snapshot was moved to after the value it guards, so a concurrent writer could slip in between. Now the reviewer treats “safely published” as an answer to torn reads, not staleness: a snapshot read against a companion updated non-atomically can be stale even under a lock.

missed the breadthapache/camel #22490v0.38.4

Deserialization allow-list breadth

A hardening change added a deserialization filter, and the reviewer accepted it as “better than none.” But a recursive java.** / javax.** allow-list still admits DNS/SSRF and JNDI gadget classes. Now the reviewer knows an allow-list isn't safe just for being narrower than nothing — it has to enumerate the concrete types the endpoint deserializes.

missed the costapache/hadoop #1932 · apache/lucene #13199v0.38.5

Performance, waved through as a constant factor

A genuinely super‑linear or wasteful operation sat right on the diff — a buffer that reallocated on nearly every append, a search tree built eagerly and usually never touched — but the reviewer dismissed it as “still geometric” or “just caching.” Now a dismissal owes the same rigor as a finding: before waving a cost through, the reviewer reads the actual growth target instead of assuming it, asks whether a cached value is really used, and names the caller that makes a path hot — because assuming the benign case is how these regressions ship.

missed the second resourcekeycloak #6912 (CVE‑2026‑9099)v0.38.6

Authorization on every resource, not just the named one

A group‑reparent endpoint checked manage permission on the destination parent but not on the group being moved, so an admin over one low‑privilege group could pull a privileged group beneath it and inherit its members. Now, for a handler that moves, reparents, links, merges, or grants across two resources, the reviewer enumerates every resource whose state changes and confirms each client‑supplied id is authorized — a check on the operation's named object doesn't cover a second one it acts on. Validated on a second, unseen operation: the same edit caught the identical gap in Keycloak's scope‑mapping endpoints (CVE‑2026‑9795).

missed the complete under lockapache/kafka #17957v0.38.7

Complete the future after the unlock, not inside it

A share‑partition init path re‑acquired the write lock in whenComplete (correct for state) and then called future.complete while still holding that lock. Dependent stages re‑entered other locks and deadlocked. The reviewer treated “re‑lock in whenComplete” as hygiene and cleared the real defect. Now completing a future (or counting down a latch) inside a locked region is an explicit finding: re‑lock to mutate state is fine; release the lock, then complete. Validated on a second, unseen surface: Pulsar's synchronized completeHandleFuture (same mechanism, different product).

missed the schema-sized walkelastic/elasticsearch #112173v0.38.8

Linear over a mapping-sized set is not free

Synthetic‑source reconstruction started calling advanceToDoc on every registered stored‑field loader for every document — including empty ones. The cost is linear, so the reviewer waved it through as a constant factor dominated by the existing field walk. Under hundreds of mapped fields that second full pass is a real per‑hit regression. Now a dismissal of “only linear” has to name both the multiplier and the call frequency: new O(|F|) work on a proven per‑doc path, where |F| scales with the mapping, is a finding. A/B on the motivating miss recovered it @MEDIUM; the clean fixture still produced zero performance findings.

Every edit was A/B-tested on the real diff that motivated it and checked against clean code for new false positives before shipping.

01

The two-sided result

A useful reviewer has to do both jobs. Measured separately, on independent code.

Question A · recall

Catches real bugs

2 / 2 caught

Two bugs that Apache maintainers had found and fixed were reintroduced by reversing their fix. The swarm flagged both, and a skeptic agent confirmed each against the code — grading one more severe than the maintainers' own PR title had.

Question B · precision / false-positive rate

Stays quiet on clean code

5 / 5 looks good

Five real PRs reviewed as submitted returned LOOKS GOOD on all five, with zero false positives — surfacing only three minor, accurate, low-severity notes.

02

Recall — the two reintroduced bugs

Each finding survived an adversarial verifier told to refute it, before it counted.

dolphinscheduler #18331 concurrency REQUEST CHANGES ▸ refutation attempted → CONFIRMED

A shared static HashMap reverted from ConcurrentHashMap

The map is mutated by synchronized login/logout but iterated lock-free by a Kerberos-renewal daemon. All 5 of 5 finders independently flagged the ConcurrentModificationException race; the verifier confirmed it HIGH. Notably it reasoned that the sibling map was correctly left a HashMap — so it understood the model, not just the pattern.

Tell-tale: the finders rediscovered the exact regression test Apache added in the real fix — without ever being told this was a concurrency change.

dolphinscheduler #18300 security · IDOR BLOCKED ▸ refutation attempted → CONFIRMED ×2

Dropped access-token owner check → account takeover

The pre-fix code looked guarded. Two independent finders traced the guard to a dead end — permissionCheck(...) { return true; } — and followed the chain to a token→identity join, concluding any user could mint a token for an admin. Both verifiers confirmed CRITICAL by quoting that one-line method. Gated verdict: BLOCKED.

Deeper than the fix: the maintainers' PR title was the terse "enforce access token owner checks" — the swarm surfaced it as a critical privilege-escalation chain, and its recommended fix matched what they shipped.

03

Precision — five PRs reviewed as submitted

Already merged and human-reviewed. The right answer is mostly "looks good" — the test is whether it agrees, quietly.

Pull requestTypeVerdictGating findings (verified)Non-gating
#18284
apache/dolphinscheduler
feature LOOKS GOOD 1 LOW — real N+1 in a loop.
1 pre-existing issue correctly dropped.
3 low/nit
#18296
apache/dolphinscheduler
fix LOOKS GOOD — 1 nit
#10091
halo-dev/halo
feature LOOKS GOOD 1 LOW — real plugin-lifecycle race. 2 low/nit
#16309
apache/dubbo
fix LOOKS GOOD 1 LOW — real uncaught-exception path. 3 low/nit
#39072
apache/shardingsphere
fix LOOKS GOOD — 2 low/nit

Across all five, the gating reviewers raised only a handful of findings — every one LOW, every one real, none refuted — plus one pre-existing issue correctly attributed to history, not the diff. Re-running the whole batch reproduced the result: 5 / 5 LOOKS GOOD and zero false positives again. The exact minor notes shifted between runs — the finders are independent and stochastic — but the verdict did not. The non-gating notes are grounded consistency questions — sentinel 0 vs -1, a duplicated host:port heuristic, test-naming drift — not bug claims. (Table shows a representative run.)

04

The harder setting — four large PRs, reviewed whole

Beyond the seven above, and not reverse-of-fix: four big PRs from top-tier Apache projects — 1,300 to 5,700 lines — reviewed exactly as shipped, nothing planted, by the full eight-finder swarm. Two surfaced real, verified issues the maintainers had merged, with the verifier refuting the weak ones; one high-stakes serializer came back LOOKS GOOD; and the largest — 5,700 lines, three times the rest — still isolated a single precise, verified concern amid five clean finders. The anti-noise claim under its stiffest test.

kafka #22652 performance · concurrency APPROVE WITH CONCERNS ▸ 2 MEDIUM confirmed · 2 claims killed

An interactive-query snapshot copies every key to return one

Transactional in-memory window/session stores for Kafka Streams. The IQ snapshot deep-copy bounds only by timestamp, then copies the whole key cross-section — so a single-key fetch(key) materializes the entire store, under a lock that also stalls the writer. Two independent reviewers — performance and concurrency — hit the same code from different angles, each grading it MEDIUM. The tell: caught by comparing against Kafka's own sibling class, which already bounds the copy correctly.

Verification earned its keep: two more claims were raised and killed — one refuted (the proposed fix wouldn't compile against the reused iterators) and one dropped as pre-existing, so the author isn't blamed for inherited behavior.

pulsar #26117 performance APPROVE WITH CONCERNS ▸ 1 MEDIUM confirmed · 2 CRITICALs chased & refuted

A hot-path allocation the old code had avoided

A new bitmap abstraction migrating broker hot paths. On the message-delivery path, the new drainTo builds a full removal-set and andNots it even when the bitmap is fully drained and immediately thrown away — where the pre-change code dropped it with zero allocation. The new performance reviewer caught it by diffing old against new behaviour; the verifier confirmed it MEDIUM.

No crying wolf: the two tempting CRITICAL hypotheses — a 64-bit→32-bit data-loss on upgrade, and a lost-atomicity race across the migrated call sites — were both investigated and refuted with evidence (the persisted format is byte-identical; every migrated site kept its existing lock). One verifier even tried to escalate a LOW and honestly held it at LOW.

flink #28709 checkpoint serialization LOOKS GOOD ▸ 0 gating findings · 2 design LOWs

The most dangerous diff — reviewed whole, and quiet

A fix to Flink's checkpoint-metadata serializer, where getting the on-disk format wrong means unrestorable state — exactly the high-stakes change that tempts a reviewer to find something. At 1,800 lines it cleared the partition guard, but its ~330 lines of production code are one tightly-coupled unit, so the swarm chose to review it whole rather than split the serialize/deserialize seam that mattered most. Between them the six gating reviewers attacked every failure mode a format change invites — wire-format compatibility (checked byte-for-byte), a path-equality misclassification, a deliberately-skipped channel-state path, the claimed-savepoint lifecycle — and each independently found it sound. No gating finding; two non-blocking design suggestions.

Quiet on clean — at scale: the convergence is the signal. Four reviewers independently landed on the same soft spot — a safe default guarded by a doc-comment, not the type system — so it reads as a courteous LOW, not a manufactured blocker. Three finders even hit transient infra failures mid-run and were resumed from their transcripts: degraded gracefully, nothing silently dropped.

druid #19535 async cache · reference lifecycle APPROVE WITH CONCERNS ▸ 1 MEDIUM confirmed · 5 of 8 finders clean

The biggest diff yet — 5,700 lines — and one precise concern, not noise

On-demand partial segment loading in Druid's cache manager: reference-counted holds, a download thread pool, and an async cursor-holder contract spanning three modules. At 5,748 lines across 64 files — roughly three times the Flink diff — it was reviewed whole, because the reference-hold seam that carries the risk crosses the very module boundaries a split would sever. Five of the eight finders came back clean after deep tracing — concurrency verified the hold-release handshake never frees a segment mid-read, which would segfault a memory-mapped reader. The one gating find came from data: a bootstrap-restored cache entry whose range reader throws on every download, so after a restart a query for not-yet-cached bytes of a partially-loaded segment fails hard — an untested path the author's own mitigation didn't cover. The verifier chased the chain across four files and confirmed it MEDIUM.

Discipline at maximum scale: on a change this intricate — reference counting, a download pool, memory-mapped reads — the clean finders declined to invent bugs: security dismissed a textbook path-traversal shape after tracing the filename to a compile-time constant; performance refused a “won't-scale” guess on an off-by-default path. One real MEDIUM, one accurate LOW observability note, four grounded design questions — and zero false gating findings on the largest diff tested.

05

How it was measured

recall setup

Reverse-of-fix

Took a bug maintainers had fixed and reverted their fix — the real buggy code, no engineered answer — then reviewed the resulting diff.

precision setup

As submitted

Reviewed five real merged PRs exactly as their authors opened them, full swarm, nothing planted.

the gate

Adversarial verify

Every gating finding went to a separate skeptic agent instructed to refute it against the code. Only survivors count.

scoring

Hand-scored, conservative

Each surviving finding judged real or false by hand; anything borderline counted as a false positive, so the number is a floor.

read this before quoting the numbers

What this does & doesn't prove

  • N is small — seven PRs. This is an existence result, not a rate.
  • Thin precision denominator — the "3 / 3" rests on three low-severity findings; it says the tool doesn't cry wolf, not that it's flawless.
  • The clean PRs test false positives, not recall — being already-reviewed, they held no medium-or-worse bugs to catch. Recall evidence is the two reintroductions only.
  • Reverse-of-fix is the easier setting — the bug is the whole diff. The four large-PR runs (section 04) probe the harder case — 1,300–5,700-line as-shipped PRs — where three surfaced real MEDIUMs (efficiency, correctness, a restart-path failure) and one came back clean; but none faced a planted critical, so they test noise-resistance and live-bug recall, not a critical-catch rate.
  • The large-PR verdicts are qualitative — the findings on the three flagged PRs were hand-read against the diff. Strong that they're real and the weak ones were refuted; not a precision rate. The Druid MEDIUM in particular is a static trace of an untested restart path — a reproducing test would seal it.
  • Run-to-run variance — re-running the whole batch reproduced the verdict (5× LOOKS GOOD, zero false positives), but the specific minor LOW/nit notes shifted. The finders are stochastic: the headline is stable, the noise floor isn't.
the defensible claim
Ran it on 7 real Apache/Halo PRs it had never seen. On two where I reintroduced a bug maintainers had fixed, it caught both and adversarially confirmed them — flagging one as a critical account-takeover the PR had understated. On five as-merged PRs it said "looks good" on all five, with zero false positives. Then on four large PRs (1,300–5,700 lines) from Kafka, Pulsar, Flink and Druid, it surfaced real efficiency and correctness issues maintainers had already merged — the verifier refuting the weak ones — while a high-stakes checkpoint-serialization fix came back a clean "looks good." On the largest, a 5,700-line Druid cache change, five of eight finders stayed quiet while one traced a real post-restart failure to a path the author's tests missed.
the tool behind this test JRS — Java Review Swarm How it works, what it costs, and how to run it on your own pull requests.