Static Scan Results
scanned 3h ago · by rust-scannerStatic analysis flagged 11 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
7 flagged · loading sourcePackage contains a critical-looking secret pattern.
bin/go/src/crypto/x509/platform_root_key.pemView on unpkg · L1EC private key in bin/go/src/crypto/x509/platform_root_key.pem
bin/go/src/crypto/x509/platform_root_key.pemView on unpkg · L1Package source references a known benign dynamic code generation pattern.
bin/go/src/internal/trace/traceviewer/static/webcomponents.min.jsView on unpkg · L10Package ships non-JavaScript build or shell helper files.
bin/go/lib/time/update.bashView on unpkgPackage ships compressed or archive-like blobs.
bin/go/lib/time/zoneinfo.zipView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
bin/go/lib/time/zoneinfo.zipView on unpkg