apache/gluten
67.5
Adequate · 29 July 2026
164.7k
lines of production code
Scala
with Java
2
measurements over time
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 65 → 67 (+2.3)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.
Lenses
- Code Health 99 → 99 (-0.0)
- Architecture 99 → 93 (-6.4)
- Maturity 74 → 76 (+2.2)
- Readiness 66 → 71 (+4.9)
- Security 54 → 56 (+2.5)
Resolved (78)
- Change coupling: ColumnarBuildSideRelation.scala ↔ UnsafeColumnarBuildSideRelation.scala (backends-velox/src/main/scala/org/apache/spark/sql/execution/ColumnarBuildSideRelation.scala)
- Change coupling: Metrics.java ↔ OperatorMetrics.java (backends-velox/src/main/java/org/apache/gluten/metrics/Metrics.java)
- Change coupling: Metrics.java ↔ VeloxMetricsApi.scala (backends-velox/src/main/java/org/apache/gluten/metrics/Metrics.java)
- Change coupling: OperatorMetrics.java ↔ VeloxMetricsApi.scala (backends-velox/src/main/java/org/apache/gluten/metrics/OperatorMetrics.java)
- Change coupling: Parameterized.java ↔ Queries.java (tools/gluten-it/common/src/main/java/org/apache/gluten/integration/command/Parameterized.java)
- Change coupling: Spark33Shims.scala ↔ Spark34Shims.scala (shims/spark33/src/main/scala/org/apache/gluten/sql/shims/spark33/Spark33Shims.scala)
- Change coupling: Spark33Shims.scala ↔ Spark35Shims.scala (shims/spark33/src/main/scala/org/apache/gluten/sql/shims/spark33/Spark33Shims.scala)
- Change coupling: Spark34Shims.scala ↔ Spark35Shims.scala (shims/spark34/src/main/scala/org/apache/gluten/sql/shims/spark34/Spark34Shims.scala)
- Change coupling: Spark40Shims.scala ↔ Spark41Shims.scala (shims/spark40/src/main/scala/org/apache/gluten/sql/shims/spark40/Spark40Shims.scala)
- Change coupling: VeloxCelebornColumnarShuffleWriter.scala ↔ ColumnarShuffleWriter.scala (backends-velox/src-celeborn/main/scala/org/apache/spark/shuffle/VeloxCelebornColumnarShuffleWriter.scala)
- Dependency hygiene not measured — no supported dependency manifest was read
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 58 more
New (99)
- Boundary-crossing change coupling: CHExpressionTransformer.scala ↔ SparkPlanExecApi.scala (backends-clickhouse/src/main/scala/org/apache/gluten/expression/CHExpressionTransformer.scala)
- Boundary-crossing change coupling: CHIteratorApi.scala ↔ WholeStageZippedPartitionsRDD.scala (backends-clickhouse/src/main/scala/org/apache/gluten/backendsapi/clickhouse/CHIteratorApi.scala)
- Boundary-crossing change coupling: VeloxIntermediateData.scala ↔ ExpressionNames.scala (backends-velox/src/main/scala/org/apache/gluten/utils/VeloxIntermediateData.scala)
- Build action pinned to a mutable branch
- Change coupling clique: SharedLibraryLoaderCentos7.scala, SharedLibraryLoaderCentos8.scala, SharedLibraryLoaderCentos9.scala, SharedLibraryLoaderDebian11.scala, SharedLibraryLoaderDebian12.scala, SharedLibraryLoaderUbuntu2004.scala, SharedLibraryLoaderUbuntu2204.scala (backends-velox/src/main/scala/org/apache/gluten/spi/SharedLibraryLoaderCentos7.scala)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (backends-clickhouse/src/main/java/org/apache/gluten/vectorized/LowCopyNettyShuffleInputStream.java)
- Duplicated block (10 lines × 2) (gluten-flink/planner/src/main/java/org/apache/flink/table/planner/plan/nodes/exec/stream/StreamExecGlobalWindowAggregate.java)
- Duplicated block (10 lines × 2) (gluten-flink/planner/src/main/java/org/apache/gluten/velox/KafkaSourceSinkFactory.java)
- Duplicated block (10 lines × 2) (gluten-flink/runtime/src/main/java/org/apache/gluten/table/runtime/operators/GlutenSourceFunction.java)
- Duplicated block (11 lines × 2) (gluten-arrow/src/main/java/org/apache/spark/sql/execution/unsafe/UnsafeByteArray.java)
- Duplicated block (11 lines × 2) (gluten-flink/planner/src/main/java/org/apache/flink/table/planner/plan/nodes/exec/stream/StreamExecGlobalWindowAggregate.java)
- Duplicated block (11 lines × 2) (gluten-substrait/src/main/java/org/apache/gluten/substrait/rel/SortRelNode.java)
- Duplicated block (12 lines × 2) (gluten-substrait/src/main/java/org/apache/gluten/substrait/rel/CrossRelNode.java)
- Duplicated block (12 lines × 3) (gluten-flink/planner/src/main/java/org/apache/flink/table/planner/plan/nodes/exec/stream/StreamExecCalc.java)
- Duplicated block (13 lines × 2) (backends-clickhouse/src/main/java/org/apache/gluten/vectorized/LowCopyFileSegmentShuffleInputStream.java)
- Duplicated block (13 lines × 2) (backends-velox/src/main/java/org/apache/gluten/columnarbatch/VeloxColumnarBatches.java)
- Duplicated block (13 lines × 2) (gluten-arrow/src/main/java/org/apache/spark/sql/execution/unsafe/UnsafeByteArray.java)
- Duplicated block (13 lines × 2) (gluten-flink/planner/src/main/java/org/apache/flink/table/planner/plan/nodes/exec/stream/StreamExecJoin.java)
- Duplicated block (14 lines × 2) (gluten-flink/planner/src/main/java/org/apache/flink/table/planner/plan/nodes/exec/stream/StreamExecGroupAggregate.java)
- …and 79 more
Changes since last survey
- 51 commits — 46 feature/other, 5 fixes
By area
- .github/workflows — 12 commits
- backends-velox/src — 7 commits
- gluten-core/src — 5 commits
- gluten-substrait/src — 5 commits
- (root) — 3 commits
- ep/build-velox — 3 commits
- tools/workload — 3 commits
- cpp/core — 2 commits
- gluten-flink/ut — 2 commits
- gluten-ut/spark40 — 2 commits
- backends-velox/pom.xml — 1 commit
- backends-velox/src-uniffle — 1 commit
- cpp-ch/local-engine — 1 commit
- cpp/velox — 1 commit
- dev/vcpkg — 1 commit
- docs/velox-backend-limitations.md — 1 commit
- shims/common — 1 commit
Notable commits
- fix: Fix ut failure due to hadoop version update (#12644)
- fix: [GLUTEN-12594][VL] Fix incorrect task attempt ID used for Uniffle block IDs
- fix: [GLUTEN-12621][CORE] Fix NoSuchElementException in untracked memory mode without off-heap size (#12622)
- fix: [VL] Fix build issues reported by weekly jobs (#12321)
- fix: [VL] Fix password leak in debug-mode config logging (#12606)
- change: Bump actions/checkout from 4 to 7 (#12637)
- change: Bump actions/download-artifact from 4 to 8 (#12635)
- change: Bump actions/github-script from 7 to 9 (#12519)
- change: Bump actions/setup-java from 4 to 5 (#12515)
- change: Bump actions/stale from 8 to 10 (#12639)
- change: Bump actions/upload-artifact from 4 to 7 (#12634)
- change: Bump gitpython in /tools/workload/benchmark_velox/analysis (#12646)
- change: Bump mistune in /tools/workload/benchmark_velox/analysis (#12620)
- change: Bump org.apache.maven.plugins:maven-compiler-plugin from 3.8.1 to 3.15.0 (#12576)
- change: Bump org.apache.maven.plugins:maven-surefire-plugin from 3.3.0 to 3.5.6 (#12578)
- change: Bump org.apache.parquet:parquet-hadoop from 1.15.2 to 1.17.1 (#12579)
- change: Bump org.xerial:sqlite-jdbc from 3.50.3.0 to 3.53.2.0 (#12577)
- change: Bump pillow in /tools/workload/benchmark_velox/analysis (#12591)
- change: [CORE][VL] Add configuration for maximum input partitions in V2 batch scans (#12589)
- change: [FLINK] Support ORC filesystem sink format (#12327)
- …and 31 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
apache/gluten was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 July 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 7ae4ea3c8aa64eb2f9468e84a0788ca536bdec40 — the exact code this score is about.
- Scored under rubric-2026.08.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.