DevDb
A zero-config extension that displays your database records right inside VS Code and provides tools and affordances to aid development and debugging.
- Created
- 3 years ago
- Last commit
- last month
- Latest release
- v3.0.95 months ago
Security Findings
23Dynamic exec of remote content (VSX)
SuspiciousScannerDownload-and-execute in node_modules/@vscode/sqlite3/build/Release/obj/global_intermediate/sqlite-autoconf-3390400/ltmain.sh: chmod +x
node_modules/@vscode/sqlite3/build/Release/obj/global_intermediate/sqlite-autoconf-3390400/ltmain.sh
Dynamic exec of remote content (VSX)
SuspiciousScannerDownload-and-execute in node_modules/@vscode/sqlite3/build/Release/obj/global_intermediate/sqlite-autoconf-3390400/tea/configure: chmod +x
node_modules/@vscode/sqlite3/build/Release/obj/global_intermediate/sqlite-autoconf-3390400/tea/configure
Dynamic exec of remote content (VSX)
SuspiciousScannerDownload-and-execute in node_modules/@vscode/sqlite3/build/Release/obj/global_intermediate/sqlite-autoconf-3390400/aclocal.m4: chmod +x
node_modules/@vscode/sqlite3/build/Release/obj/global_intermediate/sqlite-autoconf-3390400/aclocal.m4
Hardcoded secrets/API keys12×
SuspiciousScannerSecret Keyword: funct...****
Secret Keyword: usern...****
Secret Keyword: apiKe...****
Secret Keyword: strin...****
Secret Keyword: ER_PA...****
Secret Keyword: ER_MU...****
Secret Keyword: EE_UN...****
Secret Keyword: ER_UN...****
Secret Keyword: ER_CL...****
Secret Keyword: ER_RE...****
Private Key: BEGIN...****
Private Key: PuTTY...****
dist/extension.js
Hardcoded secrets/API keys2×
SuspiciousScannerSecret Keyword: Enter...****
Basic Auth Credentials: ****
ui-shell/dist/assets/index-Blj8aFgG.js
Hardcoded secrets/API keys
SuspiciousScannerSecret Keyword: ****
node_modules/@vscode/sqlite3/build/Release/obj/global_intermediate/sqlite-autoconf-3390400/tea/configure
Hardcoded secrets/API keys
SuspiciousScannerSecret Keyword: ****
node_modules/@vscode/sqlite3/build/Release/obj/global_intermediate/sqlite-autoconf-3390400/configure
Sensitive file access3×
SuspiciousScannerAccess to sensitive file: homedir(),t.slice(1)):t}function iTi(t){let e=ose(process.env.DOTENV_CONFIG_DEBUG||t&&t.debug),r=ose(process.env.DOTENV_...
Access to sensitive file: homedir(),"AppData","Local","ddev","ddev.exe"),RY.join(SL.homedir(),"AppData","Roaming","ddev","ddev.exe")];break;case"d...
Access to sensitive file: ~/.ssh
Install-lifecycle script shipped
SuspiciousScannerpackage.json postinstall script is shipped (inert on VSIX install but a build-hygiene / dev-tooling tell): node scripts/sync-bun-lockfile.js