Exact artifact intelligence

GitHub Pull Requests

GitHub.vscode-pull-request-github@0.159.2026071604
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
GitHubvs-marketplaceArtifact 5e40bb78c3af7ad2
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

58/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups7

8 contextual groups kept separate

Capabilities9

Power describes access, not intent

Why this outcome

7 behavior groups need context before approval.

Call target resolved via computed member access: ThisExpression[...](...) (line 2616)

Exact artifact5e40bb78c3af7ad2df6c30d6c58a5f3b1c483e4151db3e07640007859e9e2907

Build fedc47d31ef5 · ruleset 2026.07.19

Evidence that drives review
MEDIUM
Call target resolved via computed member access: ThisExpression[...](...) (line 2616)

9 observed locations · review evidence

MEDIUM
Extension webview in dist/extension.js declares a Content-Security-Policy with an unsafe directive (unsafe-inline, unsafe-eval, or a wildcard script-src).

2 observed locations · review evidence

MEDIUM
Package defines a lifecycle script: postinstall.

1 observed location · review evidence