registry  /  orez  /  0.4.33

orez@0.4.33

PGlite-powered zero-sync development backend. No Docker required.

Static Scan Results

scanned 5d ago · by rust-scanner

Static analysis flagged 9 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessCryptoDynamicRequireEnvironmentVarsFilesystemNetworkShellWebSocket
Supply chain
HighEntropyStringsUrlStrings
Manifest
WildcardDependency
scanned 96 file(s), 1.19 MB of source, external domains: 127.0.0.1, orez-do-backend.local, orez.local

Source & flagged code

2 flagged · loading source
dist/bench/proxy-throughput.bench.jsView file
181patternName = generic_password severity = medium line = 181 matchedText = const pa...rd';
Medium
Secret Pattern

Package contains a possible secret pattern.

dist/bench/proxy-throughput.bench.jsView on unpkg · L181
dist/worker/zero-cache-embed.jsView file
139// so we resolve the full filesystem path and import directly. L140: const { createRequire } = await import('node:module'); L141: const require = createRequire(import.meta.url);
Medium
Dynamic Require

Package source references dynamic require/import behavior.

dist/worker/zero-cache-embed.jsView on unpkg · L139

Findings

5 Medium4 Low
MediumSecret Patterndist/bench/proxy-throughput.bench.js
MediumDynamic Requiredist/worker/zero-cache-embed.js
MediumNetwork
MediumEnvironment Vars
MediumWildcard Dependency
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings