Static Scan Results
scanned 1d ago · by rust-scannerStatic analysis flagged 8 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Static reason
One or more suspicious static signals were detected.
Decision evidence
public snapshotBehavioral surface
DynamicRequireEnvironmentVarsFilesystem
HighEntropyStringsUrlStrings
Source & flagged code
2 flagged · loading sourcedist/server-dir/runtime/tx.jsView file
1Object.defineProperty(exports, Symbol.toStringTag, { value: "Module" });
L2: require("../../_virtual/_rolldown/runtime.js");
L3: const require_request_getRequestConditions = require("../../request/getRequestConditions.js");
Medium
Dynamic Require
Package source references dynamic require/import behavior.
dist/server-dir/runtime/tx.jsView on unpkg · L1dist/config.jsView file
295package = gt-next; repositoryIdentity = gt; dependency = @generaltranslation/compiler
L295: if (mergedConfig.experimentalCompilerOptions?.type === "babel") try {
L296: const { webpack: gtUnplugin } = require("@generaltranslation/compiler");
L297: webpackConfig.plugins.unshift(gtUnplugin(mergedConfig.experimentalCompilerOptions || {}));
High
Copied Package Dependency Bridge
Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/config.jsView on unpkg · L295Findings
1 High3 Medium4 Low
HighCopied Package Dependency Bridgedist/config.js
MediumDynamic Requiredist/server-dir/runtime/tx.js
MediumEnvironment Vars
MediumStructural Risk Force Deep Review
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings