CRIT
MINED035
[MINED035] Js New Function: new Function(...) compiles strings to functions.
packages/core/schematics/utils/load_esm…:25
CRIT
MINED035
[MINED035] Js New Function: new Function(...) compiles strings to functions.
packages/compiler/src/output/output_jit…:109
CRIT
MINED035
[MINED035] Js New Function: new Function(...) compiles strings to functions.
modules/utilities/perf_util.ts:129
CRIT
MINED024
[MINED024] Js Eval Usage: eval() executes arbitrary code. Code injection risk.
devtools/projects/shell-browser/src/app…:76
CRIT
MINED019
[MINED019] Ssti Jinja From String: jinja2.Environment().from_string(user_input) — full RC…
adev/src/app/editor/code-editor/utils/c…:33
CRIT
MINED123
[MINED123] Trojan Source bidi character (LRM) in source: Line 60 contains a Unicode bidir…
packages/common/locales/closure-locale.…:60
HIGH
SEC027
[SEC027] XML External Entity (XXE) — Node.js xml parsers: Node.js XML parsers can expand …
packages/compiler/src/i18n/serializers/…:97
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
packages/compiler/src/i18n/digest.ts:29
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
adev/shared-docs/services/search-histor…:71
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
adev/shared-docs/pipeline/navigation/na…:53
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
adev/shared-docs/pipeline/examples/prev…:53
HIGH
SEC083
[SEC083] JS: new RegExp() with non-literal: new RegExp(<variable>) — variable input can c…
adev/src/content/examples/form-validati…:38
HIGH
SEC083
[SEC083] JS: new RegExp() with non-literal: new RegExp(<variable>) — variable input can c…
adev/shared-docs/pipeline/shared/region…:49
HIGH
SEC083
[SEC083] JS: new RegExp() with non-literal: new RegExp(<variable>) — variable input can c…
adev/shared-docs/pipeline/api-gen/rende…:44
HIGH
MINED008
[MINED008] Swift Force Unwrap: optional! crashes on nil. Use guard let or if let.
adev/shared-docs/pipeline/shared/marked…:86
HIGH
MINED008
[MINED008] Swift Force Unwrap: optional! crashes on nil. Use guard let or if let.
adev/shared-docs/pipeline/shared/marked…:56
HIGH
MINED008
[MINED008] Swift Force Unwrap: optional! crashes on nil. Use guard let or if let.
adev/shared-docs/pipeline/api-gen/rende…:60
HIGH
MINED002
[MINED002] Dart Null Bang: value! throws on null. Use ?. or null check.
adev/shared-docs/pipeline/shared/marked…:86
HIGH
MINED002
[MINED002] Dart Null Bang: value! throws on null. Use ?. or null check.
adev/shared-docs/pipeline/shared/marked…:56
HIGH
MINED002
[MINED002] Dart Null Bang: value! throws on null. Use ?. or null check.
adev/shared-docs/pipeline/api-gen/rende…:60
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
adev/shared-docs/pipeline/api-gen/rende…:43
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
adev/shared-docs/components/search-hist…:102
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
adev/shared-docs/components/search-dial…:124
HIGH
MINED010
[MINED010] Ruby System Call: system / backtick run shell. Command injection if any arg dy…
adev/shared-docs/pipeline/shared/marked…:41
HIGH
MINED010
[MINED010] Ruby System Call: system / backtick run shell. Command injection if any arg dy…
adev/shared-docs/pipeline/shared/headin…:19
HIGH
MINED010
[MINED010] Ruby System Call: system / backtick run shell. Command injection if any arg dy…
adev/scripts/routes/generate-routes.mts:57
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
adev/shared-docs/pipeline/shared/marked…:41
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
adev/shared-docs/pipeline/shared/headin…:19
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
adev/scripts/routes/generate-routes.mts:57
HIGH
SEC040
[SEC040] innerHTML XSS — template literal with server-supplied data: Setting .innerHTML w…
adev/shared-docs/pipeline/shared/marked…:31
HIGH
SEC040
[SEC040] innerHTML XSS — template literal with server-supplied data: Setting .innerHTML w…
adev/shared-docs/pipeline/api-gen/extra…:124
HIGH
SEC040
[SEC040] innerHTML XSS — template literal with server-supplied data: Setting .innerHTML w…
adev/scripts/routes/generate-routes.mts:34
HIGH
MINED122
[MINED122] package.json dep `@angular/compiler` pulled from URL/Git: `dependencies.@angul…
integration/defer/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/common` pulled from URL/Git: `dependencies.@angular…
integration/defer/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/animations` pulled from URL/Git: `dependencies.@ang…
integration/defer/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/core` pulled from URL/Git: `dependencies.@angular/c…
integration/no_ts_linker/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/compiler-cli` pulled from URL/Git: `dependencies.@a…
integration/no_ts_linker/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/compiler` pulled from URL/Git: `dependencies.@angul…
integration/no_ts_linker/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/compiler-cli` pulled from URL/Git: `devDependencies…
integration/trusted-types/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/router` pulled from URL/Git: `dependencies.@angular…
integration/trusted-types/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/platform-browser` pulled from URL/Git: `dependencie…
integration/trusted-types/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/forms` pulled from URL/Git: `dependencies.@angular/…
integration/trusted-types/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/core` pulled from URL/Git: `dependencies.@angular/c…
integration/trusted-types/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/compiler` pulled from URL/Git: `dependencies.@angul…
integration/trusted-types/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/common` pulled from URL/Git: `dependencies.@angular…
integration/trusted-types/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/animations` pulled from URL/Git: `dependencies.@ang…
integration/trusted-types/package.json:1
HIGH
MINED122
[MINED122] package.json dep `@angular/compiler-cli` pulled from URL/Git: `devDependencies…
integration/platform-server-zoneless/pa…:1
HIGH
MINED122
[MINED122] package.json dep `@angular/router` pulled from URL/Git: `dependencies.@angular…
integration/platform-server-zoneless/pa…:1
HIGH
MINED122
[MINED122] package.json dep `@angular/platform-server` pulled from URL/Git: `dependencies…
integration/platform-server-zoneless/pa…:1
HIGH
MINED122
[MINED122] package.json dep `@angular/platform-browser` pulled from URL/Git: `dependencie…
integration/platform-server-zoneless/pa…:1
HIGH
MINED122
[MINED122] package.json dep `@angular/forms` pulled from URL/Git: `dependencies.@angular/…
integration/platform-server-zoneless/pa…:1
HIGH
MINED122
[MINED122] package.json dep `@angular/core` pulled from URL/Git: `dependencies.@angular/c…
integration/platform-server-zoneless/pa…:1
HIGH
MINED122
[MINED122] package.json dep `@angular/compiler` pulled from URL/Git: `dependencies.@angul…
integration/platform-server-zoneless/pa…:1
HIGH
MINED122
[MINED122] package.json dep `@angular/common` pulled from URL/Git: `dependencies.@angular…
integration/platform-server-zoneless/pa…:1
HIGH
MINED122
[MINED122] package.json dep `@angular/animations` pulled from URL/Git: `dependencies.@ang…
integration/platform-server-zoneless/pa…:1
HIGH
MINED122
[MINED122] package.json dep `@angular/ng-dev` pulled from URL/Git: `devDependencies.@angu…
package.json:1
HIGH
MINED122
[MINED122] package.json dep `domino` pulled from URL/Git: `dependencies.domino` = `https:…
package.json:1
MED
SEC134
[SEC134] AI scaffold leftover — Lorem ipsum / example.com / John Doe in code: Lorem ipsum…
adev/src/content/tutorials/signals/step…:75
MED
SEC134
[SEC134] AI scaffold leftover — Lorem ipsum / example.com / John Doe in code: Lorem ipsum…
adev/src/content/tutorials/signals/step…:93
MED
SEC136
[SEC136] AI-typical over-broad exception handler swallowing all errors: Catch-all excepti…
adev/src/app/editor/code-editor/extensi…:84
MED
SEC041
[SEC041] Tabnabbing — target="_blank" without rel="noopener noreferrer": <a target="_blan…
adev/src/app/app.component.ts:104
MED
SEC041
[SEC041] Tabnabbing — target="_blank" without rel="noopener noreferrer": <a target="_blan…
adev/shared-docs/pipeline/shared/marked…:56
MED
SEC041
[SEC041] Tabnabbing — target="_blank" without rel="noopener noreferrer": <a target="_blan…
adev/shared-docs/pipeline/api-gen/rende…:50
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
adev/shared-docs/pipeline/shared/marked…:41
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
adev/shared-docs/pipeline/shared/headin…:19
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
adev/scripts/routes/generate-routes.mts:57
MED
AUC001
[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks…
—
MED
AGT007
localStorage write failures are swallowed silently
adev/shared-docs/providers/local-storag…:64
MED
WEB003
Public web service has no security.txt
.well-known/security.txt
MED
AGT006
React interval is created without an explicit cleanup
adev/shared-docs/testing/testing-helper…:213
MED
WEB015
Public web app has no Content Security Policy
index.html
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:6
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:5
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:6
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:4
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:4
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:4
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/first-app/st…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/deferrable-v…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/deferrable-v…:6
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/deferrable-v…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/deferrable-v…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/deferrable-v…:17
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/deferrable-v…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/deferrable-v…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/deferrable-v…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/deferrable-v…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/deferrable-v…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/deferrable-v…:1
LOW
AIC003
Duplicated implementation block across source files
adev/src/content/tutorials/deferrable-v…:1
LOW
WEB002
Public web app has no sitemap
sitemap.xml
LOW
AIC002
Source file name looks like an AI patch artifact
packages/zone.js/lib/common/error-rewri…:1
LOW
WEB011
Public web app has no humans.txt
humans.txt
INFO
MINED047
[MINED047] Emoji In Source: Emoji ✅ ❌ 🚀 in code/comments — common AI output unless explic…
packages/common/locales/ff-MR.ts:64
INFO
MINED047
[MINED047] Emoji In Source: Emoji ✅ ❌ 🚀 in code/comments — common AI output unless explic…
packages/common/locales/ff-GN.ts:64
INFO
MINED047
[MINED047] Emoji In Source: Emoji ✅ ❌ 🚀 in code/comments — common AI output unless explic…
packages/common/locales/ff-CM.ts:64
INFO
MINED057
[MINED057] Todo Bomb: Code path with a TODO/FIXME/HACK comment that gates correctness — l…
adev/src/content/tutorials/signals/step…:63
INFO
MINED049
[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout.
adev/src/content/examples/signal-forms/…:47
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
adev/src/app/core/services/errors-handl…:28
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
adev/shared-docs/utils/zip.utils.ts:28
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
adev/shared-docs/pipeline/shared/region…:48
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
adev/shared-docs/utils/navigation.utils…:85
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
adev/shared-docs/pipeline/shared/marked…:17
INFO
MINED058
[MINED058] React Dangerously Set Html: dangerouslySetInnerHTML bypasses Reacts JSX escapi…
adev/shared-docs/pipeline/api-gen/rende…:40
INFO
MINED058
[MINED058] React Dangerously Set Html: dangerouslySetInnerHTML bypasses Reacts JSX escapi…
adev/shared-docs/pipeline/api-gen/rende…:31
INFO
MINED058
[MINED058] React Dangerously Set Html: dangerouslySetInnerHTML bypasses Reacts JSX escapi…
adev/shared-docs/pipeline/api-gen/rende…:31
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
adev/shared-docs/pipeline/shared/marked…:23
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
adev/shared-docs/pipeline/shared/marked…:27
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
adev/shared-docs/pipeline/api-gen/rende…:40
INFO
MINED051
[MINED051] Csharp Null Forgive: x! tells compiler "definitely not null" — bypasses nullab…
adev/shared-docs/pipeline/shared/marked…:86
INFO
MINED051
[MINED051] Csharp Null Forgive: x! tells compiler "definitely not null" — bypasses nullab…
adev/shared-docs/pipeline/shared/marked…:56
INFO
MINED051
[MINED051] Csharp Null Forgive: x! tells compiler "definitely not null" — bypasses nullab…
adev/shared-docs/pipeline/api-gen/rende…:60
INFO
MINED070
[MINED070] Zig Undefined Init: var x: T = undefined leaves memory uninitialized. Often a …
adev/shared-docs/pipeline/api-gen/rende…:200
INFO
MINED048
[MINED048] Php Error Suppress: @function() suppresses errors silently. Hides real issues.
integration/ng-modules-importability/in…:49
INFO
MINED048
[MINED048] Php Error Suppress: @function() suppresses errors silently. Hides real issues.
adev/shared-docs/pipeline/examples/temp…:11
INFO
MINED048
[MINED048] Php Error Suppress: @function() suppresses errors silently. Hides real issues.
adev/shared-docs/pipeline/api-gen/extra…:79
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
adev/shared-docs/pipeline/api-gen/rende…:45
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
adev/shared-docs/pipeline/api-gen/rende…:60
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
adev/shared-docs/components/navigation-…:93
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
adev/scripts/update-cross-repo-docs/ind…:32
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
adev/scripts/synonyms/update-synonyms.m…:33
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
adev/scripts/routes/generate-routes.mts:71
INFO
MINED042
[MINED042] Cpp New Without Delete: C++ raw new without RAII / unique_ptr — memory leak ri…
adev/shared-docs/pipeline/api-gen/extra…:40
INFO
MINED042
[MINED042] Cpp New Without Delete: C++ raw new without RAII / unique_ptr — memory leak ri…
adev/scripts/synonyms/update-synonyms.m…:22
INFO
MINED042
[MINED042] Cpp New Without Delete: C++ raw new without RAII / unique_ptr — memory leak ri…
adev/scripts/routes/generate-routes.mts:69