CRIT
MINED005
[MINED005] Lua Loadstring: loadstring/load executes Lua code. Code injection.
src/cli/show_config.zig:74
CRIT
MINED005
[MINED005] Lua Loadstring: loadstring/load executes Lua code. Code injection.
src/cli/edit_config.zig:72
CRIT
MINED005
[MINED005] Lua Loadstring: loadstring/load executes Lua code. Code injection.
pkg/opengl/glad.zig:15
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:1377
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:1346
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:1311
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:1263
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:1228
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:1191
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:1137
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:1077
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:1014
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:946
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:906
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:824
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:791
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:762
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:685
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:645
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:609
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:564
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:530
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:413
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:375
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:335
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:269
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:233
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_AUTH_TOKEN` on a `pull_request` trigger: This wo…
.github/workflows/test.yml:175
HIGH
MINED108
[MINED108] `self.safe_literal_eval` used but never assigned in __init__: Method `process_…
src/font/nerd_font_codegen.py:161
HIGH
MINED108
[MINED108] `self.resolve_symbol` used but never assigned in __init__: Method `process_pat…
src/font/nerd_font_codegen.py:166
HIGH
MINED108
[MINED108] `self.safe_literal_eval` used but never assigned in __init__: Method `resolve_…
src/font/nerd_font_codegen.py:120
HIGH
MINED108
[MINED108] `self.safe_literal_eval` used but never assigned in __init__: Method `resolve_…
src/font/nerd_font_codegen.py:121
HIGH
MINED108
[MINED108] `self.process_patch_entry` used but never assigned in __init__: Method `visit_…
src/font/nerd_font_codegen.py:115
HIGH
MINED108
[MINED108] `self.visit_setup_patch_set` used but never assigned in __init__: Method `visi…
src/font/nerd_font_codegen.py:93
HIGH
MINED108
[MINED108] `self.generic_visit` used but never assigned in __init__: Method `visit_Assign…
src/font/nerd_font_codegen.py:86
HIGH
MINED011
[MINED011] Scala Get On Option: Option.get throws NoSuchElementException on None. Use get…
src/apprt/gtk/class/surface_scrolled_wi…:153
HIGH
MINED011
[MINED011] Scala Get On Option: Option.get throws NoSuchElementException on None. Use get…
src/apprt/gtk/class/inspector_window.zig:146
HIGH
MINED011
[MINED011] Scala Get On Option: Option.get throws NoSuchElementException on None. Use get…
src/apprt/gtk/class/config.zig:104
HIGH
MINED002
[MINED002] Dart Null Bang: value! throws on null. Use ?. or null check.
src/config/command.zig:98
HIGH
MINED002
[MINED002] Dart Null Bang: value! throws on null. Use ?. or null check.
src/apprt/gtk/portal.zig:38
HIGH
MINED002
[MINED002] Dart Null Bang: value! throws on null. Use ?. or null check.
pkg/wuffs/src/swizzle.zig:9
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
pkg/breakpad/build.zig:94
HIGH
MINED008
[MINED008] Swift Force Unwrap: optional! crashes on nil. Use guard let or if let.
macos/Sources/Helpers/PermissionRequest…:61
HIGH
MINED008
[MINED008] Swift Force Unwrap: optional! crashes on nil. Use guard let or if let.
macos/Sources/Helpers/Extensions/NSImag…:11
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
pkg/fontconfig/test.zig:49
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
macos/Sources/Ghostty/Ghostty.MenuShort…:60
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
macos/Sources/Features/Terminal/Window …:47
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
macos/Sources/Features/Terminal/Termina…:64
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
macos/Sources/Features/Custom App Icon/…:41
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
macos/Sources/Features/About/AboutView.…:6
HIGH
DKR014
Dockerfile copies the entire context without .dockerignore
src/build/docker/debian/Dockerfile:37
HIGH
MINED126
[MINED126] Workflow container/services image `ghcr.io/flathub-infra/flatpak-github-action…
.github/workflows/flatpak.yml:20
HIGH
MINED115
[MINED115] Action `DeterminateSystems/nix-installer-action` pinned to mutable ref `@main`…
.github/workflows/release-tip.yml:857
HIGH
MINED115
[MINED115] Action `DeterminateSystems/nix-installer-action` pinned to mutable ref `@main`…
.github/workflows/release-tip.yml:660
HIGH
MINED115
[MINED115] Action `DeterminateSystems/nix-installer-action` pinned to mutable ref `@main`…
.github/workflows/release-tip.yml:404
HIGH
MINED115
[MINED115] Action `DeterminateSystems/nix-installer-action` pinned to mutable ref `@main`…
.github/workflows/release-tip.yml:312
HIGH
MINED115
[MINED115] Action `DeterminateSystems/nix-installer-action` pinned to mutable ref `@main`…
.github/workflows/release-tag.yml:146
HIGH
MINED115
[MINED115] Action `DeterminateSystems/nix-installer-action` pinned to mutable ref `@main`…
.github/workflows/test.yml:1593
HIGH
MINED115
[MINED115] Action `DeterminateSystems/nix-installer-action` pinned to mutable ref `@main`…
.github/workflows/test.yml:1371
HIGH
MINED115
[MINED115] Action `DeterminateSystems/nix-installer-action` pinned to mutable ref `@main`…
.github/workflows/test.yml:1131
HIGH
MINED115
[MINED115] Action `DeterminateSystems/nix-installer-action` pinned to mutable ref `@main`…
.github/workflows/test.yml:1071
HIGH
MINED115
[MINED115] Action `DeterminateSystems/nix-installer-action` pinned to mutable ref `@main`…
.github/workflows/test.yml:639
HIGH
MINED115
[MINED115] Action `DeterminateSystems/nix-installer-action` pinned to mutable ref `@main`…
.github/workflows/test.yml:329
HIGH
SEC020
[SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-b…
src/apprt/gtk/portal.zig:10
HIGH
SEC005
[SEC005] Command Injection Risk: Unsafe shell execution or eval of user input.
src/os/xdg.zig:106
MED
DKR003
Dockerfile base image uses the latest tag
src/build/docker/lib-c-docs/Dockerfile:4
MED
DKR007
Docker build context has no .dockerignore
.dockerignore
MED
DKR001
Docker final stage has no non-root USER
src/build/docker/lib-c-docs/Dockerfile:26
MED
DKR001
Docker final stage has no non-root USER
src/build/docker/debian/Dockerfile:2
MED
AGT015
Remote install command pipes network code directly to a shell
.github/workflows/release-tip.yml:97
MED
AGT015
Remote install command pipes network code directly to a shell
.github/workflows/release-tag.yml:299
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
example/zig-vt/src/main.zig:8
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
example/zig-vt-stream/src/main.zig:6
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
example/zig-formatter/src/main.zig:6
LOW
AIC003
Duplicated implementation block across source files
macos/Sources/Helpers/Cursor.swift:30
LOW
AIC003
Duplicated implementation block across source files
macos/Sources/Features/AppleScript/Scri…:55
LOW
AIC003
Duplicated implementation block across source files
macos/Sources/Features/AppleScript/Scri…:15
LOW
AIC003
Duplicated implementation block across source files
macos/Sources/Features/AppleScript/Scri…:31
LOW
AIC003
Duplicated implementation block across source files
macos/Sources/Features/AppleScript/Scri…:15
LOW
AIC003
Duplicated implementation block across source files
macos/Sources/Features/AppleScript/Scri…:29
LOW
AIC003
Duplicated implementation block across source files
macos/Sources/Features/AppleScript/Scri…:11
LOW
AIC003
Duplicated implementation block across source files
macos/Sources/Features/AppleScript/Scri…:10
LOW
AIC003
Duplicated implementation block across source files
macos/Sources/Features/App Intents/Focu…:10
LOW
AIC007
Generated build artifact directory is present at repository root
dist:1
INFO
MINED098
[MINED098] Global Scope Pollution: Attaching libraries/objects directly to the global win…
src/apprt/ipc.zig:98
INFO
MINED049
[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout.
src/apprt/gtk/portal.zig:10
INFO
MINED051
[MINED051] Csharp Null Forgive: x! tells compiler "definitely not null" — bypasses nullab…
src/config/command.zig:98
INFO
MINED051
[MINED051] Csharp Null Forgive: x! tells compiler "definitely not null" — bypasses nullab…
src/apprt/gtk/portal.zig:38
INFO
MINED051
[MINED051] Csharp Null Forgive: x! tells compiler "definitely not null" — bypasses nullab…
pkg/wuffs/src/swizzle.zig:9
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
src/extra/sublime.zig:7
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
pkg/macos/foundation/url.zig:71
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
pkg/glslang/shader.zig:25
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
pkg/glslang/program.zig:37
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
pkg/freetype/Library.zig:74
INFO
MINED059
[MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message.
pkg/fontconfig/lang_set.zig:37
INFO
MINED059
[MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message.
pkg/fontconfig/init.zig:27
INFO
MINED059
[MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message.
pkg/fontconfig/char_set.zig:37
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
src/apprt/gtk/ext/slice.zig:54
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
pkg/fontconfig/build.zig:142
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
pkg/afl++/build.zig:24
INFO
MINED070
[MINED070] Zig Undefined Init: var x: T = undefined leaves memory uninitialized. Often a …
pkg/fontconfig/config.zig:26
INFO
MINED070
[MINED070] Zig Undefined Init: var x: T = undefined leaves memory uninitialized. Often a …
pkg/fontconfig/common.zig:93
INFO
MINED070
[MINED070] Zig Undefined Init: var x: T = undefined leaves memory uninitialized. Often a …
example/zig-formatter/src/main.zig:19
INFO
MINED048
[MINED048] Php Error Suppress: @function() suppresses errors silently. Hides real issues.
example/c-vt-effects/build.zig:1
INFO
MINED048
[MINED048] Php Error Suppress: @function() suppresses errors silently. Hides real issues.
example/c-vt-colors/build.zig:1
INFO
MINED048
[MINED048] Php Error Suppress: @function() suppresses errors silently. Hides real issues.
example/c-vt-build-info/build.zig:1