Static Scan Results
scanned 6h ago · by rust-scannerStatic analysis flagged 6 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Static reason
One or more suspicious static signals were detected.
Decision evidence
public snapshotBehavioral surface
ChildProcessEnvironmentVarsFilesystem
HighEntropyStringsMinifiedUrlStrings
Source & flagged code
1 flagged · loading sourcedist/plugins/update-notifier/update-notifier-plugin.jsView file
1package = @visulima/cerebro; repositoryIdentity = visulima; dependency = @visulima/colorize
L1: import{c as A}from"../../packem_shared/runtime-process-Dmz0vCJy.js";var R={},c,C;function p(){return C||(C=1,c=[{name:"Agola CI",constant:"AGOLA",env:"AGOLA_GIT_REF",pr:"AGOLA_PULL...
High
Copied Package Dependency Bridge
Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/plugins/update-notifier/update-notifier-plugin.jsView on unpkg · L1Findings
1 High2 Medium3 Low
HighCopied Package Dependency Bridgedist/plugins/update-notifier/update-notifier-plugin.js
MediumEnvironment Vars
MediumStructural Risk Force Deep Review
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings