Exact artifact intelligence

trivy-vulnerability-scanner

aquasecurityofficial.trivy-vulnerability-scanner@1.8.11
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
aquasecurityofficialvs-marketplaceArtifact 421289db1a46d354
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

73/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups7

8 contextual groups kept separate

Capabilities6

Power describes access, not intent

Why this outcome

7 behavior groups need context before approval.

Source writes credential-related data to VS Code configuration.

Exact artifact421289db1a46d354144f4539dd86218ab4b94c13098fdf4ef4ee1b44a7179d02

Build 2c024e5d1553 · ruleset 2026.07.19

Evidence that drives review
HIGH
Source writes credential-related data to VS Code configuration.

1 observed location · review evidence

MEDIUM
Call target resolved via computed member access: zo[...](...) (line 2)

12 observed locations · review evidence

MEDIUM
adm-zip@0.5.16 has 1 OSV finding(s). Version match: range-derived.

2 observed locations · review evidence