Policy result for this exact artifact
Exact artifact intelligence
GitLens — Git supercharged
eamodio.gitlens@2026.7.160544Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyeamodiovs-marketplaceArtifact
20a80baa19fbeb69Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
61/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
8 contextual groups kept separate
Power describes access, not intent
4 behavior groups need context before approval.
Call target resolved via computed member access: i[...](...) (line 5)
20a80baa19fbeb69f75121bb209f8944ac6223dd0a28c6133884a8fbce2bfd1fBuild fedc47d31ef5 · ruleset 2026.07.19
Evidence that drives review
Call target resolved via computed member access: i[...](...) (line 5)
31 observed locations · review evidence
Runtime dependency @gitkraken/commit-graph is loaded from a mutable or non-registry source: workspace:*.
9 observed locations · review evidence
Extension creates a webview in dist/browser/gitlens.js without a detected Content-Security-Policy meta tag.
2 observed locations · review evidence