- Created
- 9 years ago
- Last commit
- 5 days ago
- Latest release
- v67.20.02 weeks ago
Security Findings
10pull_request_target with secrets
MaliciousLineage[.github/workflows/docOnlyAutoMerge.yml] pull_request_target with secrets
Suspicious outbound hosts7×
SuspiciousScannerOutbound URLs to non-allowlisted host(s): 794testsite.my.site.com, aura-oss-dev.herokuapp.com, html5doctor.com, www.ecma-international.org, www.iana.org
Outbound URLs to non-allowlisted host(s): blog.imperva.com, docs.oracle.com, encoding.spec.whatwg.org, heycam.github.io, html5doctor.com, sfdc.co, w3c.github.io, www.ecma-international.org
Outbound URLs to non-allowlisted host(s): adrianheine.de, dzone.com, marijnhaverbeke.nl, rreverser.com, www.ecma-international.org
Outbound URLs to non-allowlisted host(s): beautifier.io, drafts.csswg.org, googlechrome.github.io, help.yahoo.com, html.spec.whatwg.org, json-schema.org, r12a.github.io, registry.yarnpkg.com
Outbound URLs to non-allowlisted host(s): beautifier.io, drafts.csswg.org, googlechrome.github.io, help.yahoo.com, html.spec.whatwg.org, r12a.github.io, stackoverflow.com, tools.ietf.org
Outbound URLs to non-allowlisted host(s): daringfireball.net, microsoft.github.io, stackoverflow.com, tools.ietf.org, www.fileformat.info
Outbound URLs to non-allowlisted host(s): sfdc.co, w3c.github.io
Install-lifecycle script shipped
SuspiciousScannerpackage.json preinstall script is shipped (inert on VSIX install but a build-hygiene / dev-tooling tell): node ../../scripts/require-root-install.js