Exact artifact intelligence

semgrep

semgrep.semgrep@1.17.0
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
semgrepvs-marketplaceArtifact a06ce8efc8630256
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

55/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups8

11 contextual groups kept separate

Capabilities8

Power describes access, not intent

Why this outcome

8 behavior groups need context before approval.

Native binary dist/libs/libtree-sitter.0.22.dylib has no companion checksum or signature file and no documented provenance.

Exact artifacta06ce8efc863025606cb98aff93f7f858121d90c88fb84df943e5d2073d79c36

Build 2c024e5d1553 · ruleset 2026.07.19

Evidence that drives review
MEDIUM
Native binary dist/libs/libtree-sitter.0.22.dylib has no companion checksum or signature file and no documented provenance.

6 observed locations · review evidence

MEDIUM
@opentelemetry/auto-instrumentations-node@0.60.1 has 1 OSV finding(s). Version match: range-derived.

4 observed locations · review evidence

MEDIUM
Call target resolved via computed member access: n[...](...) (line 8)

3 observed locations · review evidence