Back to extension profile
Immutable Deep Scan reportEvidence is locked to this exact artifact and scan.
About immutable reports

Future scans cannot replace the findings, coverage, ruleset, or artifact hash shown on this URL.

Scan
89b4073e-cbf7-4dbf-a67c-e970f5c0bd0a
Artifact
a06ce8efc863…73d79c36
Analysis Report

semgrep

semgrep.semgrep@1.17.0

Completed analysis for this exact extension version. Use the summary below to decide what your team should do next.

Scan resultReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

Required action
Record a team decision before approval
Export evidence
Decision nowThe extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.Exact artifact only
Actionable evidence117 contextual notes
Capabilities8Observed powers, not intent
Coverage100%Executable-file coverage
Package scope26019 dependencies
Frozen regression fixtureThis exact artifact is in the GuardRails regression corpus.

Hash-pinned as a security tool control case. The exact artifact identity matches the frozen cohort; the current decision above comes only from this scan's evidence.

semgrepvs-marketplaceVersion 1.17.0
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

What changed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

Why it matters

This result applies only to the scanned artifact SHA-256, not to future releases or a publisher generally.

Recommended action

Review the grouped evidence and record the accountable team decision before approval.

Analysis limits

Required analysis completed for this exact artifact; evidence remains scoped to scanner coverage.

  1. 1Artifact boundExtension, version, hash, and scan identity fixed
  2. 2Analysis checkedExecutable-file coverage
  3. 3Evidence grouped1 actionable · 17 contextual
  4. 4Policy appliedExact-release ruleset evaluated
  5. 5Review neededCurrent decision for this artifact
51/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Executable-file coverage
100

7/7 required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups1

17 contextual notes kept separate

Capabilities8

Power describes access, not intent

Why this outcome

1 behavior group needs context before approval.

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

Exact artifacta06ce8efc863025606cb98aff93f7f858121d90c88fb84df943e5d2073d79c36

Build 6aab1d4caaf6 · ruleset 2026.07.24-policy-v3-calibration.6

Evidence that drives review
LOW
Native binary dist/libs/libev.4.dylib has no companion checksum or signature file and no documented provenance.

6 observed locations · review evidence