Static Scan Results
scanned 1d ago · by rust-scannerStatic analysis flagged 6 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Static reason
One or more suspicious static signals were detected.; previous stored version diff introduced dangerous source
Decision evidence
public snapshotBehavioral surface
ChildProcessFilesystemNetworkShell
HighEntropyStringsUrlStrings
Source & flagged code
2 flagged · loading sourcesrc/generators/sandbox/sandbox.jsView file
152patternName = generic_password
severity = medium
line = 152
matchedText = `--docke... ` +
Medium
Secret Pattern
Package contains a possible secret pattern.
src/generators/sandbox/sandbox.jsView on unpkg · L152src/utils/oc-utils.jsView file
•matchType = previous_version_dangerous_delta
matchedPackage = @abgov/nx-oc@12.13.0
matchedIdentity = npm:QGFiZ292L254LW9j:12.13.0
similarity = 0.759
summary = stored previous version shares package body but lacks this dangerous source file
High
Previous Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/utils/oc-utils.jsView on unpkgFindings
1 High2 Medium3 Low
HighPrevious Version Dangerous Deltasrc/utils/oc-utils.js
MediumSecret Patternsrc/generators/sandbox/sandbox.js
MediumNetwork
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings