CRIT
MINED107
[MINED107] Missing import: `queue` used but not imported: The file uses `queue.something(…
scripts/orca_filament_lib.py:50
CRIT
MINED024
[MINED024] Js Eval Usage: eval() executes arbitrary code. Code injection risk.
resources/web/homepage/js/json2.js:177
CRIT
MINED024
[MINED024] Js Eval Usage: eval() executes arbitrary code. Code injection risk.
resources/web/guide/js/json2.js:177
CRIT
MINED024
[MINED024] Js Eval Usage: eval() executes arbitrary code. Code injection risk.
resources/web/dialog/js/json2.js:177
CRIT
MINED022
[MINED022] C Strcpy: strcpy/strcat dont bounds-check; use strncpy or snprintf.
deps_src/libnest2d/tools/svgtools.hpp:111
CRIT
MINED022
[MINED022] C Strcpy: strcpy/strcat dont bounds-check; use strncpy or snprintf.
deps_src/libigl/igl/copyleft/tetgen/tet…:61
CRIT
MINED022
[MINED022] C Strcpy: strcpy/strcat dont bounds-check; use strncpy or snprintf.
deps_src/libigl/igl/copyleft/opengl2/te…:29
CRIT
MINED123
[MINED123] Trojan Source bidi character (LRM) in source: Line 2 contains a Unicode bidire…
resources/tooltip/main.js:2
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
src/libslic3r/ProjectTask.hpp:233
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
resources/web/guide/swiper/modules/mani…:30
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
resources/web/guide/swiper/modules/mani…:25
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
resources/web/guide/swiper/modules/mani…:56
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
resources/web/include/swiper/modules/hi…:27
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
resources/web/guide/swiper/modules/hist…:27
HIGH
MINED017
[MINED017] C System Call: system() invokes shell. command injection if any arg is dynamic.
deps_src/libigl/igl/launch_medit.cpp:56
HIGH
MINED134
[MINED134] Binary file `tools/7z.exe` committed in source repo: `tools/7z.exe` is a .exe …
tools/7z.exe:1
HIGH
MINED134
[MINED134] Binary file `tools/xgettext.exe` committed in source repo: `tools/xgettext.exe…
tools/xgettext.exe:1
HIGH
MINED134
[MINED134] Binary file `tools/msgfmt.exe` committed in source repo: `tools/msgfmt.exe` is…
tools/msgfmt.exe:1
HIGH
MINED134
[MINED134] Binary file `tools/msgmerge.exe` committed in source repo: `tools/msgmerge.exe…
tools/msgmerge.exe:1
HIGH
MINED115
[MINED115] Action `vedantmgoyal9/winget-releaser` pinned to mutable ref `@main`: `uses: v…
.github/workflows/winget_updater.yml:9
HIGH
MINED115
[MINED115] Action `actions/download-artifact` pinned to mutable ref `@v8`: `uses: actions…
.github/workflows/check_profiles_commen…:29
HIGH
MINED115
[MINED115] Action `microsoft/setup-msbuild` pinned to mutable ref `@v3`: `uses: microsoft…
.github/workflows/build_deps.yml:55
HIGH
MINED115
[MINED115] Action `lukka/get-cmake` pinned to mutable ref `@latest`: `uses: lukka/get-cma…
.github/workflows/build_deps.yml:46
HIGH
MINED115
[MINED115] Action `actions/cache` pinned to mutable ref `@v5`: `uses: actions/cache@v5` r…
.github/workflows/build_deps.yml:42
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/build_deps.yml:37
HIGH
MINED115
[MINED115] Action `anthropics/claude-code-base-action` pinned to mutable ref `@beta`: `us…
.github/workflows/dedupe-issues.yml:26
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/dedupe-issues.yml:23
HIGH
MINED115
[MINED115] Action `qoomon/actions--create-commit` pinned to mutable ref `@v1`: `uses: qoo…
.github/workflows/update-translation.yml:31
HIGH
MINED115
[MINED115] Action `actions/setup-python` pinned to mutable ref `@v6`: `uses: actions/setu…
.github/workflows/update-translation.yml:16
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/update-translation.yml:13
HIGH
MINED126
[MINED126] Workflow container/services image `ghcr.io/flathub-infra/flatpak-github-action…
.github/workflows/build_all.yml:145
HIGH
MINED115
[MINED115] Action `WebFreak001/deploy-nightly` pinned to mutable ref `@v3.2.0`: `uses: We…
.github/workflows/build_all.yml:228
HIGH
MINED115
[MINED115] Action `actions/upload-artifact` pinned to mutable ref `@v7`: `uses: actions/u…
.github/workflows/build_all.yml:222
HIGH
MINED115
[MINED115] Action `flatpak/flatpak-github-actions/flatpak-builder` pinned to mutable ref …
.github/workflows/build_all.yml:214
HIGH
MINED115
[MINED115] Action `actions/cache` pinned to mutable ref `@v5`: `uses: actions/cache@v5` r…
.github/workflows/build_all.yml:199
HIGH
MINED115
[MINED115] Action `actions/cache/restore` pinned to mutable ref `@v5`: `uses: actions/cac…
.github/workflows/build_all.yml:192
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/build_all.yml:173
HIGH
MINED115
[MINED115] Action `geekyeggo/delete-artifact` pinned to mutable ref `@v6`: `uses: geekyeg…
.github/workflows/build_all.yml:139
HIGH
MINED115
[MINED115] Action `EnricoMi/publish-unit-test-result-action` pinned to mutable ref `@v2`:…
.github/workflows/build_all.yml:134
HIGH
MINED115
[MINED115] Action `actions/upload-artifact` pinned to mutable ref `@v7`: `uses: actions/u…
.github/workflows/build_all.yml:127
HIGH
MINED115
[MINED115] Action `lukka/get-cmake` pinned to mutable ref `@latest`: `uses: lukka/get-cma…
.github/workflows/build_all.yml:116
HIGH
MINED115
[MINED115] Action `actions/download-artifact` pinned to mutable ref `@v8`: `uses: actions…
.github/workflows/build_all.yml:113
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/build_all.yml:103
HIGH
MINED115
[MINED115] Action `oven-sh/setup-bun` pinned to mutable ref `@v2`: `uses: oven-sh/setup-b…
.github/workflows/auto-close-duplicates…:21
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/auto-close-duplicates…:18
HIGH
MINED118
[MINED118] Dockerfile FROM `docker.io/ubuntu:24.04` not pinned by digest: `FROM docker.io…
scripts/Dockerfile:1
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/orca_extra_profile_check.py:266
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/orca_extra_profile_check.py:440
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/orca_extra_profile_check.py:389
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/orca_extra_profile_check.py:346
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/orca_extra_profile_check.py:308
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/orca_extra_profile_check.py:214
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/orca_extra_profile_check.py:152
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/orca_extra_profile_check.py:78
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/orca_extra_profile_check.py:245
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/orca_filament_lib.py:237
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/orca_filament_lib.py:113
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/orca_filament_lib.py:282
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/orca_filament_lib.py:139
MED
MINED109
[MINED109] Mutable default argument in `create_ordered_profile` (list): `def create_order…
scripts/orca_filament_lib.py:6
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/optimize_cover_images.py:434
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/optimize_cover_images.py:361
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
scripts/optimize_cover_images.py:63
MED
SEC041
[SEC041] Tabnabbing — target="_blank" without rel="noopener noreferrer": <a target="_blan…
resources/web/guide/21/21.js:18
MED
SEC041
[SEC041] Tabnabbing — target="_blank" without rel="noopener noreferrer": <a target="_blan…
resources/web/guide/0/load.js:27
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
resources/web/guide/js/common.js:12
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
resources/web/dialog/js/common.js:12
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
resources/web/dialog/ExportPresetDialog…:49
MED
SEC136
[SEC136] AI-typical over-broad exception handler swallowing all errors: Catch-all excepti…
resources/web/guide/js/globalapi.js:181
MED
SEC136
[SEC136] AI-typical over-broad exception handler swallowing all errors: Catch-all excepti…
resources/web/dialog/js/globalapi.js:181
MED
SEC136
[SEC136] AI-typical over-broad exception handler swallowing all errors: Catch-all excepti…
resources/web/dialog/ExportPresetDialog…:355
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
resources/web/dialog/js/json2.js:177
MED
DKR009
Dockerfile separates apt update from install
scripts/Dockerfile:5
MED
DKR001
Docker final stage has no non-root USER
scripts/Dockerfile:1
MED
DKR001
Docker final stage has no non-root USER
.devcontainer/Dockerfile:2
MED
AIC004
Suspicious implementation file appears unreferenced
deps_src/libigl/igl/stdin_to_temp.h:1
MED
AIC004
Suspicious implementation file appears unreferenced
deps_src/libigl/igl/stdin_to_temp.cpp:1
MED
AIC004
Suspicious implementation file appears unreferenced
deps_src/libigl/igl/min_quad_with_fixed…:1
MED
DKR014
Dockerfile copies broad context with incomplete .dockerignore
scripts/Dockerfile:61
LOW
COMP001
[COMP001] High cognitive complexity: Function `traverse_files` has cognitive complexity 9…
resources/profiles/check_unused_setting…:18
LOW
AIC003
Duplicated implementation block across source files
deps_src/Shiny/ShinyNodePool.h:7
LOW
AIC003
Duplicated implementation block across source files
deps_src/Shiny/ShinyNodePool.h:1
LOW
AIC003
Duplicated implementation block across source files
deps_src/Shiny/ShinyNodePool.c:1
LOW
AIC003
Duplicated implementation block across source files
deps_src/Shiny/ShinyNode.h:7
LOW
AIC003
Duplicated implementation block across source files
deps_src/Shiny/ShinyNode.h:1
LOW
AIC003
Duplicated implementation block across source files
deps_src/Shiny/ShinyNode.c:1
LOW
AIC003
Duplicated implementation block across source files
deps_src/Shiny/ShinyManager.h:7
LOW
AIC003
Duplicated implementation block across source files
deps_src/Shiny/ShinyManager.h:1
LOW
AIC003
Duplicated implementation block across source files
deps_src/Shiny/ShinyManager.c:1
LOW
AIC003
Duplicated implementation block across source files
deps_src/Shiny/ShinyMacros.h:1
LOW
AIC003
Duplicated implementation block across source files
deps_src/Shiny/ShinyData.h:1
LOW
AIC003
Duplicated implementation block across source files
deps_src/Shiny/ShinyConfig.h:1
LOW
AIC003
Duplicated implementation block across source files
deps/MPFR/mpfr/include/mpfr.h:2
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/xmltok_impl.h:10
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/xmltok.h:19
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/xmltok.h:13
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/xmlrole.h:11
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/xmlrole.h:10
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/utf8tab.h:10
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/utf8tab.h:1
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/nametab.h:8
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/latin1tab.h:10
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/latin1tab.h:1
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/internal.h:25
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/iasciitab.h:10
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/iasciitab.h:1
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/expat_external.h:16
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/expat_config.h:11
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/expat.h:17
LOW
AIC003
Duplicated implementation block across source files
deps/EXPAT/expat/asciitab.h:10
LOW
DKR010
Dockerfile leaves apt package indexes in the image layer
scripts/Dockerfile:12
LOW
DKR011
Dockerfile installs recommended OS packages
scripts/Dockerfile:12
LOW
DKR008
.dockerignore misses sensitive defaults
.dockerignore
LOW
AIC002
Source file name looks like an AI patch artifact
deps_src/libigl/igl/stdin_to_temp.h:1
LOW
AIC002
Source file name looks like an AI patch artifact
deps_src/libigl/igl/stdin_to_temp.cpp:1
LOW
AIC002
Source file name looks like an AI patch artifact
deps_src/libigl/igl/min_quad_with_fixed…:1
LOW
AIC002
Source file name looks like an AI patch artifact
deps_src/libigl/igl/dated_copy.h:1
LOW
AIC002
Source file name looks like an AI patch artifact
deps_src/libigl/igl/dated_copy.cpp:1
INFO
MINED048
[MINED048] Php Error Suppress: @function() suppresses errors silently. Hides real issues.
src/libslic3r/MacUtils.mm:8
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
scripts/backfill-duplicate-comments.ts:26
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
scripts/auto-close-duplicates.ts:28
INFO
MINED049
[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout.
scripts/backfill-duplicate-comments.ts:87
INFO
MINED049
[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout.
scripts/auto-close-duplicates.ts:106
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
resources/web/guide/swiper/postinstall.…:33
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
resources/web/guide/js/globalapi.js:248
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
resources/web/dialog/js/globalapi.js:248
INFO
MINED042
[MINED042] Cpp New Without Delete: C++ raw new without RAII / unique_ptr — memory leak ri…
src/libslic3r/ExtrusionEntityCollection…:62
INFO
MINED042
[MINED042] Cpp New Without Delete: C++ raw new without RAII / unique_ptr — memory leak ri…
src/libslic3r/AABBMesh.cpp:77
INFO
MINED042
[MINED042] Cpp New Without Delete: C++ raw new without RAII / unique_ptr — memory leak ri…
deps_src/mcut/include/mcut/internal/tim…:68
INFO
MINED080
[MINED080] Cpp Using Namespace Std: using namespace std; pollutes the global namespace.
deps_src/libigl/igl/arap.cpp:38
INFO
MINED080
[MINED080] Cpp Using Namespace Std: using namespace std; pollutes the global namespace.
deps_src/libigl/igl/adjacency_matrix.cpp:19
INFO
MINED080
[MINED080] Cpp Using Namespace Std: using namespace std; pollutes the global namespace.
deps_src/libigl/igl/WindingNumberAABB.h:152
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
deps_src/Shiny/ShinyConfig.h:4
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
deps_src/Shiny/Shiny.h:4
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
deps/MPFR/mpfr/include/mpf2mpfr.h:20