Exact artifact intelligence

Language Support for Java(TM) by Red Hat

redhat.java@1.56.2026071508
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
redhatvs-marketplaceArtifact 1f6099292a4e811a
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

55/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups3

10 contextual groups kept separate

Capabilities7

Power describes access, not intent

Why this outcome

3 behavior groups need context before approval.

Call target resolved via computed member access: ThisExpression[...](...) (line 1)

Exact artifact1f6099292a4e811a6c437ef71ee25e4f1096a15aff88854822552e6b89161568

Build 8c83a1c11c79 · ruleset 2026.07.19

Evidence that drives review
MEDIUM
Call target resolved via computed member access: ThisExpression[...](...) (line 1)

6 observed locations · review evidence

MEDIUM
Code uses shell-style process execution.

1 observed location · review evidence

MEDIUM
Extension contains 116 packed artifacts (e.g. lombok/lombok-1.18.39-4050.jar).

1 observed location · review evidence