- Created
- 9 years ago
- Last commit
- 5 days ago
- Latest release
- v67.20.02 weeks ago
Security Findings
13pull_request_target with secrets
MaliciousLineage[.github/workflows/docOnlyAutoMerge.yml] pull_request_target with secrets
Hardcoded secrets/API keys4×
SuspiciousScannerSecret Keyword: strin...****
Secret Keyword: numbe...****
Secret Keyword: profi...****
Secret Keyword: heade...****
dist/index.js
Hardcoded secrets/API keys
SuspiciousScannerSecret Keyword: newPa...****
dist/templates/project/angularextapp/_p_/_m_/_w_/_a_/src/app/_f_/authentication/utils/auth-validators.ts
Hardcoded secrets/API keys5×
SuspiciousScannerSecret Keyword: numbe...****
Secret Keyword: ****
Secret Keyword: profi...****
Secret Keyword: heade...****
Secret Keyword: strin...****
dist/web/index.js
Sensitive file access
SuspiciousScannerAccess to sensitive file: homedir(),t.SFDX_STATE_FOLDER)}static get SF_DIR(){return $7e.join(j4t.homedir(),t.SF_STATE_FOLDER)}static get DIR(){ret...
Install-lifecycle script shipped
SuspiciousScannerpackage.json preinstall script is shipped (inert on VSIX install but a build-hygiene / dev-tooling tell): node ../../scripts/require-root-install.js