Static Scan Results
scanned 5h ago · by rust-scannerStatic analysis flagged 21 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
13 flagged · loading sourcePackage contains a critical-looking secret pattern.
dist/src/yaml/steps/xcode.jsView on unpkg · L289RSA private key in dist/src/yaml/steps/xcode.js
dist/src/yaml/steps/xcode.jsView on unpkg · L289Package source references a known benign dynamic code generation pattern.
dist/src/yaml/fidelity-input-digest.test.jsView on unpkg · L35Package source references weak cryptographic algorithms.
dist/src/yaml/fidelity-input-digest.test.jsView on unpkg · L14This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.cjsView on unpkgSource contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
dist/cli.cjsView on unpkg · L1Package source references dynamic require/import behavior.
dist/cli.cjsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/yaml/env-resolver.jsView on unpkg · L8RSA private key in dist/src/yaml/steps/bitrise-ssh.test.js
dist/src/yaml/steps/bitrise-ssh.test.jsView on unpkg · L26RSA private key in dist/src/yaml/steps/bitrise-ssh.test.js
dist/src/yaml/steps/bitrise-ssh.test.jsView on unpkg · L39RSA private key in dist/src/yaml/steps/bitrise-ssh.test.js
dist/src/yaml/steps/bitrise-ssh.test.jsView on unpkg · L159RSA private key in dist/src/yaml/steps/bitrise-ssh.js
dist/src/yaml/steps/bitrise-ssh.jsView on unpkg · L39OpenSSH private key in dist/src/yaml/steps/bitrise-ssh.js
dist/src/yaml/steps/bitrise-ssh.jsView on unpkg · L45