Exact artifact intelligence

SonarQube for IDE

SonarSource.sonarlint-vscode@5.5.0
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
SonarSourcevs-marketplaceArtifact d755728fcd9d87b1
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

58/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups6

11 contextual groups kept separate

Capabilities12

Power describes access, not intent

Why this outcome

6 behavior groups need context before approval.

@xmldom/xmldom@0.8.11 has 5 OSV finding(s). Version match: range-derived.

Exact artifactd755728fcd9d87b122717b34868fc5a88908b571432e387f9f601f229307fdcf

Build 8c83a1c11c79 · ruleset 2026.07.19

Evidence that drives review
MEDIUM
@xmldom/xmldom@0.8.11 has 5 OSV finding(s). Version match: range-derived.

4 observed locations · review evidence

MEDIUM
Extension contributes agent-facing capability: languageModelTools.

1 observed location · review evidence

MEDIUM
Agent-facing tool surface can run shell or process commands.

1 observed location · review evidence