Exact artifact intelligence

snyk-vulnerability-scanner

snyk-security.snyk-vulnerability-scanner@2.31.0
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
snyk-securityvs-marketplaceArtifact 5e6ea92b390f7552
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

75/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups7

5 contextual groups kept separate

Capabilities5

Power describes access, not intent

Why this outcome

7 behavior groups need context before approval.

uuid@8.3.2 has 1 OSV finding(s). Version match: exact.

Exact artifact5e6ea92b390f755218f17b5fbee4273406909dbcf0bf33e273558546dc8998b4

Build fedc47d31ef5 · ruleset 2026.07.19

Evidence that drives review
HIGH
uuid@8.3.2 has 1 OSV finding(s). Version match: exact.

1 observed location · review evidence

MEDIUM
Extension creates a webview in out/snyk/common/views/summaryWebviewProvider.js without a detected Content-Security-Policy meta tag.

8 observed locations · review evidence

MEDIUM
Package defines a lifecycle script: vscode:uninstall.

1 observed location · review evidence