Static Scan Results
scanned 5h ago · by rust-scannerStatic analysis flagged 7 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Static reason
One or more suspicious static signals were detected.; previous stored version diff introduced dangerous source
Decision evidence
public snapshotBehavioral surface
ChildProcessEnvironmentVarsFilesystemNetworkShell
HighEntropyStringsUrlStrings
Source & flagged code
2 flagged · loading sourcesrc/executors/sandbox/sandbox.jsView file
•matchType = previous_version_dangerous_delta
matchedPackage = @abgov/nx-oc@12.15.1
matchedIdentity = npm:QGFiZ292L254LW9j:12.15.1
similarity = 0.933
summary = stored previous version shares package body but lacks this dangerous source file
High
Previous Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/executors/sandbox/sandbox.jsView on unpkg199patternName = generic_password
severity = medium
line = 199
matchedText = `--docke... ` +
Medium
Secret Pattern
Package contains a possible secret pattern.
src/executors/sandbox/sandbox.jsView on unpkg · L199Findings
1 High3 Medium3 Low
HighPrevious Version Dangerous Deltasrc/executors/sandbox/sandbox.js
MediumSecret Patternsrc/executors/sandbox/sandbox.js
MediumNetwork
MediumEnvironment Vars
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings