Exact artifact intelligence

GitLens — Git supercharged

eamodio.gitlens@2026.7.160544
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
eamodiovs-marketplaceArtifact 20a80baa19fbeb69
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

61/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups4

8 contextual groups kept separate

Capabilities5

Power describes access, not intent

Why this outcome

4 behavior groups need context before approval.

Call target resolved via computed member access: i[...](...) (line 5)

Exact artifact20a80baa19fbeb69f75121bb209f8944ac6223dd0a28c6133884a8fbce2bfd1f

Build fedc47d31ef5 · ruleset 2026.07.19

Evidence that drives review
MEDIUM
Call target resolved via computed member access: i[...](...) (line 5)

31 observed locations · review evidence

MEDIUM
Runtime dependency @gitkraken/commit-graph is loaded from a mutable or non-registry source: workspace:*.

9 observed locations · review evidence

MEDIUM
Extension creates a webview in dist/browser/gitlens.js without a detected Content-Security-Policy meta tag.

2 observed locations · review evidence