Policy result for this exact artifact
Exact artifact intelligence
trivy-vulnerability-scanner
aquasecurityofficial.trivy-vulnerability-scanner@1.8.11Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyaquasecurityofficialvs-marketplaceArtifact
421289db1a46d354Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
73/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
8 contextual groups kept separate
Power describes access, not intent
7 behavior groups need context before approval.
Source writes credential-related data to VS Code configuration.
421289db1a46d354144f4539dd86218ab4b94c13098fdf4ef4ee1b44a7179d02Build 2c024e5d1553 · ruleset 2026.07.19
Evidence that drives review
Source writes credential-related data to VS Code configuration.
1 observed location · review evidence
Call target resolved via computed member access: zo[...](...) (line 2)
12 observed locations · review evidence
adm-zip@0.5.16 has 1 OSV finding(s). Version match: range-derived.
2 observed locations · review evidence