About immutable reports
Future scans cannot replace the findings, coverage, ruleset, or artifact hash shown on this URL.
- Scan
3fe45368-af07-40b4-bef5-b690e2f91de3- Artifact
d755728fcd9d…9307fdcf
SonarQube for IDE
SonarSource.sonarlint-vscode@5.5.0Completed analysis for this exact extension version. Use the summary below to decide what your team should do next.
Analysis completed without actionable evidence or unapproved baseline changes.
- Required action
- Proceed under normal extension controls
Hash-pinned as a security tool control case. The exact artifact identity matches the frozen cohort; the current decision above comes only from this scan's evidence.
No evidence currently requires review.
Required analysis completed without evidence that crosses the active review policy.
Analysis completed without actionable evidence or unapproved baseline changes.
This result applies only to the scanned artifact SHA-256, not to future releases or a publisher generally.
Approval can proceed under your organization’s normal extension controls.
Required analysis completed for this exact artifact; evidence remains scoped to scanner coverage.
- 1Artifact boundExtension, version, hash, and scan identity fixed
- 2Analysis checkedExecutable-file coverage
- 3Evidence grouped0 actionable · 18 contextual
- 4Policy appliedExact-release ruleset evaluated
- 5No known concernCurrent decision for this artifact
Diagnostic risk index for this exact artifact — not a probability of malice.
Policy result for this exact artifact
7/7 required analyzers completed
Diagnostic index, not probability
18 contextual notes kept separate
Power describes access, not intent
No behavior group currently requires review.
Analysis completed without actionable evidence or unapproved baseline changes.
d755728fcd9d87b122717b34868fc5a88908b571432e387f9f601f229307fdcfBuild 6aab1d4caaf6 · ruleset 2026.07.24-policy-v3-calibration.6