About immutable reports
Future scans cannot replace the findings, coverage, ruleset, or artifact hash shown on this URL.
- Scan
a3f5f30f-a37d-417e-b3f3-932b6332a251- Artifact
5e40bb78c3af…9e9e2907
GitHub Pull Requests
GitHub.vscode-pull-request-github@0.159.2026071604Completed analysis for this exact extension version. Use the summary below to decide what your team should do next.
Analysis completed without actionable evidence or unapproved baseline changes.
- Required action
- Proceed under normal extension controls
Hash-pinned as a credential sensitive case. The exact artifact identity matches the frozen cohort; the current decision above comes only from this scan's evidence.
No evidence currently requires review.
Required analysis completed without evidence that crosses the active review policy.
Analysis completed without actionable evidence or unapproved baseline changes.
This result applies only to the scanned artifact SHA-256, not to future releases or a publisher generally.
Approval can proceed under your organization’s normal extension controls.
Required analysis completed for this exact artifact; evidence remains scoped to scanner coverage.
- 1Artifact boundExtension, version, hash, and scan identity fixed
- 2Analysis checkedExecutable-file coverage
- 3Evidence grouped0 actionable · 17 contextual
- 4Policy appliedExact-release ruleset evaluated
- 5No known concernCurrent decision for this artifact
Diagnostic risk index for this exact artifact — not a probability of malice.
Policy result for this exact artifact
7/7 required analyzers completed
Diagnostic index, not probability
17 contextual notes kept separate
Power describes access, not intent
No behavior group currently requires review.
Analysis completed without actionable evidence or unapproved baseline changes.
5e40bb78c3af7ad2df6c30d6c58a5f3b1c483e4151db3e07640007859e9e2907Build 6aab1d4caaf6 · ruleset 2026.07.24-policy-v3-calibration.6