registry  /  @tyleretters/discography  /  3.0.9

@tyleretters/discography@3.0.9

A canonical discography of the music of Tyler Etters.

Static Scan Results

scanned 2h ago · by rust-scanner

Static analysis flagged 9 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
SourceNo risky source behavior triggered.
Supply chain
HighEntropyStringsMinifiedUrlStrings
Manifest
CopyleftLicense
scanned 2 file(s), 637 KB of source, external domains: amazon.com, assets.the-rn.info, connectednesslocus.bandcamp.com, music.apple.com, nor.the-rn.info, northerninformation.bandcamp.com, open.spotify.com, soundcloud.com, stuxnet.bandcamp.com, stuxnet.me, synergybeat.bandcamp.com, theybecamewhattheybeheld.bandcamp.com, untitled.stream, www.amazon.com, www.deezer.com, www.youtube.com

Source & flagged code

4 flagged · loading source
dist/index.es.jsView file
5085patternName = private_key_openssh severity = critical line = 5085 matchedText = -----BEG...----
Critical
Critical Secret

Package contains a critical-looking secret pattern.

dist/index.es.jsView on unpkg · L5085
5085patternName = private_key_openssh severity = critical line = 5085 matchedText = -----BEG...----
Critical
Secret Pattern

OpenSSH private key in dist/index.es.js

dist/index.es.jsView on unpkg · L5085
dist/discography.ymlView file
2737patternName = private_key_openssh severity = critical line = 2737 matchedText = -----BEG...----
Critical
Secret Pattern

OpenSSH private key in dist/discography.yml

dist/discography.ymlView on unpkg · L2737
dist/index.umd.jsView file
23patternName = private_key_openssh severity = critical line = 23 matchedText = -----BEG...----
Critical
Secret Pattern

OpenSSH private key in dist/index.umd.js

dist/index.umd.jsView on unpkg · L23

Findings

4 Critical5 Low
CriticalCritical Secretdist/index.es.js
CriticalSecret Patterndist/index.es.js
CriticalSecret Patterndist/discography.yml
CriticalSecret Patterndist/index.umd.js
LowNon Install Lifecycle Scripts
LowScripts Present
LowHigh Entropy Strings
LowUrl Strings
LowCopyleft License