Broad capability surfacePotentially unbounded loopBroad capability surfaceLow-confidence secret match
scanned 12d ago · partial·osv · gitleaks · opengrep · picklescan + heuristics·full breakdown in the Security tab ↓
Ray
Ray is a unified framework for scaling Python and AI/ML workloads across a cluster. It provides low-level distributed primitives (tasks, actors) and a rich library ecosystem — Ray Train, Ray Serve, Ray Tune, RLlib, and Ray Data — that handle the most common distributed AI use cases out of the box.
Key Features
Ray Train: distributed training for PyTorch, TensorFlow, XGBoost, LightGBM with fault tolerance
Ray Serve: production model serving with request batching, model composition, and autoscaling
Ray Tune: distributed hyperparameter search with Bayesian optimization and PBT
Ray Data: scalable data preprocessing pipelines for ML training
Scales from laptop to cluster: same code, no changes
Quick Start
import ray
ray.init()
@ray.remote
def process_batch(batch):
return [preprocess(item) for item in batch]
# Fan out 1000 tasks in parallel
futures = [process_batch.remote(batch) for batch in batches]
results = ray.get(futures)
Install via ai-supply
npx ai-supply add ray-distributed-computing
Curated mirror of the open-source Ray (Apache-2.0). Get it from the source.
✓ Security: Safe · 100100/100 · grade Ascanned 12d ago
✓ no compromise signals19 risk-surface · 6/20 OWASP controls flagged
Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.
What this capability can do · med confidence (static)
Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).
OWASP Top 10 for LLM Applications
⚠LLM05Improper Output Handlinghigh
Code that pipes model/user output into shell, eval, SQL or paths unsafely.