CRIT
SEC101
[SEC101] Unsafe Java object deserialization (ObjectInputStream): Java ObjectInputStream d…
build-logic/documentation/src/main/groo…:46
CRIT
MINED005
[MINED005] Lua Loadstring: loadstring/load executes Lua code. Code injection.
platforms/core-configuration/kotlin-dsl…:80
CRIT
MINED005
[MINED005] Lua Loadstring: loadstring/load executes Lua code. Code injection.
build-logic/documentation/src/main/groo…:93
CRIT
MINED005
[MINED005] Lua Loadstring: loadstring/load executes Lua code. Code injection.
build-logic/documentation/src/main/groo…:103
CRIT
SEC084
[SEC084] JS: require() with non-literal: require(<variable>) loads arbitrary modules — eq…
build-logic-commons/gradle-plugin/src/m…:37
CRIT
SEC084
[SEC084] JS: require() with non-literal: require(<variable>) loads arbitrary modules — eq…
build-logic-commons/basics/src/main/kot…:27
CRIT
SEC084
[SEC084] JS: require() with non-literal: require(<variable>) loads arbitrary modules — eq…
.teamcity/src/main/kotlin/promotion/Pub…:54
CRIT
MINED116
[MINED116] Workflow uses `secrets.DEVELOCITY_ACCESS_KEY` on a `pull_request` trigger: Thi…
.github/workflows/contributor-pr.yml:18
HIGH
MINED010
[MINED010] Ruby System Call: system / backtick run shell. Command injection if any arg dy…
platforms/core-configuration/configurat…:200
HIGH
MINED010
[MINED010] Ruby System Call: system / backtick run shell. Command injection if any arg dy…
platforms/core-configuration/configurat…:60
HIGH
MINED010
[MINED010] Ruby System Call: system / backtick run shell. Command injection if any arg dy…
platforms/core-configuration/configurat…:114
HIGH
SEC027
[SEC027] XML External Entity (XXE) — Node.js xml parsers: Node.js XML parsers can expand …
build-logic/performance-testing/src/mai…:25
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
build-logic/performance-testing/src/mai…:110
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
build-logic/packaging/src/main/kotlin/g…:131
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
build-logic/documentation/src/main/groo…:80
HIGH
SEC024
[SEC024] XML External Entity (XXE) — Java parser default: Java XML parsers accept externa…
build-logic/documentation/src/main/groo…:75
HIGH
SEC024
[SEC024] XML External Entity (XXE) — Java parser default: Java XML parsers accept externa…
build-logic/documentation/src/main/groo…:39
HIGH
SEC024
[SEC024] XML External Entity (XXE) — Java parser default: Java XML parsers accept externa…
build-logic/build-update-utils/src/main…:67
HIGH
MINED011
[MINED011] Scala Get On Option: Option.get throws NoSuchElementException on None. Use get…
build-logic/binary-compatibility/src/ma…:55
HIGH
MINED011
[MINED011] Scala Get On Option: Option.get throws NoSuchElementException on None. Use get…
build-logic/binary-compatibility/src/ma…:40
HIGH
MINED011
[MINED011] Scala Get On Option: Option.get throws NoSuchElementException on None. Use get…
build-logic/binary-compatibility/src/ma…:78
HIGH
MINED029
[MINED029] Kotlin Null Bang: x!! throws NullPointerException if x is null. Bypasses Kotli…
build-logic-settings/architecture-docs/…:72
HIGH
MINED029
[MINED029] Kotlin Null Bang: x!! throws NullPointerException if x is null. Bypasses Kotli…
build-logic-commons/module-identity/src…:62
HIGH
MINED029
[MINED029] Kotlin Null Bang: x!! throws NullPointerException if x is null. Bypasses Kotli…
build-logic-commons/basics/src/main/kot…:111
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
build-logic-commons/publishing/src/main…:128
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
build-logic-commons/publishing/src/main…:77
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
.teamcity/src/main/kotlin/configuration…:133
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
.teamcity/scripts/FindCommits.java:97
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
.teamcity/scripts/CheckWrapper.java:109
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
.teamcity/scripts/CheckBadMerge.java:173
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
build-logic/build-update-utils/src/main…:131
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
build-logic/binary-compatibility/src/ma…:105
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
.teamcity/.mvn/wrapper/MavenWrapperDown…:87
HIGH
MINED134
[MINED134] Binary file `.teamcity/.mvn/wrapper/maven-wrapper.jar` committed in source rep…
.teamcity/.mvn/wrapper/maven-wrapper.jar:1
HIGH
MINED134
[MINED134] Binary file `gradle/wrapper/gradle-wrapper.jar` committed in source repo: `gra…
gradle/wrapper/gradle-wrapper.jar:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/fundamentals/authoring-…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/fundamentals/authoring-…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/fundamentals/authoring-…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/fundamentals/authoring-…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/fundamentals/authoring-…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/fundamentals/authoring-…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/integration-tests/webAp…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/integration-tests/webAp…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/reference/core-plugins/…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/reference/core-plugins/…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/reference/dependency-ma…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/reference/dependency-ma…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/reference/dependency-ma…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/unused/plugins/multipro…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/unused/plugins/pluginVe…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/unused/plugins/consumin…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/unused/plugins/consumin…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/unused/plugins/resoluti…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED134
[MINED134] Binary file `platforms/documentation/docs/src/snippets/unused/plugins/resoluti…
platforms/documentation/docs/src/snippe…:1
HIGH
MINED115
[MINED115] Action `lycheeverse/lychee-action` pinned to mutable ref `@v2.8.0`: `uses: lyc…
.github/workflows/check-markdown-links.…:22
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/check-markdown-links.…:19
HIGH
MINED115
[MINED115] Action `actions/stale` pinned to mutable ref `@v10`: `uses: actions/stale@v10`…
.github/workflows/team-triage-stale.yml:16
HIGH
MINED115
[MINED115] Action `kentaro-m/auto-assign-action` pinned to mutable ref `@v2.0.2`: `uses: …
.github/workflows/auto-assign-pr-to-aut…:15
HIGH
MINED115
[MINED115] Action `peter-evans/create-or-update-comment` pinned to mutable ref `@v5`: `us…
.github/workflows/update-jdks.yml:57
HIGH
MINED115
[MINED115] Action `peter-evans/create-pull-request` pinned to mutable ref `@v8`: `uses: p…
.github/workflows/update-jdks.yml:42
HIGH
MINED115
[MINED115] Action `gradle/update-jdks-action` pinned to mutable ref `@main`: `uses: gradl…
.github/workflows/update-jdks.yml:26
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/update-jdks.yml:21
HIGH
MINED115
[MINED115] Action `slackapi/slack-github-action` pinned to mutable ref `@v3.0.3`: `uses: …
.github/workflows/notify-on-rc-for-manu…:16
HIGH
MINED115
[MINED115] Action `gradle/issue-management-action/issue-metadata` pinned to mutable ref `…
.github/workflows/issue-metadata.yml:17
HIGH
MINED115
[MINED115] Action `gradle/actions/dependency-submission` pinned to mutable ref `@v6`: `us…
.github/workflows/submit-github-depende…:22
HIGH
MINED115
[MINED115] Action `actions/setup-java` pinned to mutable ref `@v5`: `uses: actions/setup-…
.github/workflows/submit-github-depende…:17
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/submit-github-depende…:16
HIGH
MINED115
[MINED115] Action `gradle/issue-management-action/issue-comment-triage` pinned to mutable…
.github/workflows/issue-comment-triage.…:13
HIGH
MINED115
[MINED115] Action `peter-evans/create-pull-request` pinned to mutable ref `@v8`: `uses: p…
.github/workflows/update-perf-test-buck…:45
HIGH
MINED115
[MINED115] Action `gradle/actions/setup-gradle` pinned to mutable ref `@v6`: `uses: gradl…
.github/workflows/update-perf-test-buck…:40
HIGH
MINED115
[MINED115] Action `actions/setup-java` pinned to mutable ref `@v5`: `uses: actions/setup-…
.github/workflows/update-perf-test-buck…:35
HIGH
MINED115
[MINED115] Action `aws-actions/aws-secretsmanager-get-secrets` pinned to mutable ref `@v3…
.github/workflows/update-perf-test-buck…:28
HIGH
MINED115
[MINED115] Action `aws-actions/configure-aws-credentials` pinned to mutable ref `@v6`: `u…
.github/workflows/update-perf-test-buck…:23
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/update-perf-test-buck…:21
HIGH
MINED115
[MINED115] Action `peter-evans/create-pull-request` pinned to mutable ref `@v8`: `uses: p…
.github/workflows/update-test-buckets.y…:60
HIGH
MINED115
[MINED115] Action `actions/setup-java` pinned to mutable ref `@v5`: `uses: actions/setup-…
.github/workflows/update-test-buckets.y…:34
HIGH
MINED115
[MINED115] Action `aws-actions/aws-secretsmanager-get-secrets` pinned to mutable ref `@v3…
.github/workflows/update-test-buckets.y…:28
HIGH
MINED115
[MINED115] Action `aws-actions/configure-aws-credentials` pinned to mutable ref `@v6`: `u…
.github/workflows/update-test-buckets.y…:23
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/update-test-buckets.y…:21
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
platforms/core-configuration/kotlin-dsl…:188
MED
SEC127
[SEC127] AI agent stub — TODO: implement / pass placeholder body: Function body left as T…
platforms/core-configuration/dependency…:50
MED
SEC123
[SEC123] Production stack trace / debug output exposed: Debug mode left on in production …
platforms/core-configuration/configurat…:131
MED
SEC012
[SEC012] ZipSlip — Archive Path Traversal: Archive extraction without path validation all…
platforms/core-configuration/file-opera…:217
MED
SEC012
[SEC012] ZipSlip — Archive Path Traversal: Archive extraction without path validation all…
build-logic/binary-compatibility/src/ma…:50
MED
SEC012
[SEC012] ZipSlip — Archive Path Traversal: Archive extraction without path validation all…
build-logic-commons/basics/src/main/kot…:138
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
.teamcity/scripts/FindCommits.java:92
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
.teamcity/scripts/CheckWrapper.java:109
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
.teamcity/scripts/CheckBadMerge.java:173
MED
AGT007
localStorage write failures are swallowed silently
platforms/documentation/docs/src/docs/u…:12
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
.teamcity/scripts/CheckWrapper.java:74
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
.teamcity/scripts/CheckBadMerge.java:110
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
.teamcity/.mvn/wrapper/MavenWrapperDown…:27
LOW
AIC003
Duplicated implementation block across source files
.teamcity/src/main/kotlin/promotion/Sta…:11
INFO
MINED053
[MINED053] Placeholder Default Username: [email protected] / [email protected] / admin/admin…
platforms/core-configuration/kotlin-dsl…:141
INFO
MINED059
[MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message.
platforms/core-configuration/configurat…:48
INFO
MINED059
[MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message.
platforms/core-configuration/configurat…:58
INFO
MINED059
[MINED059] Rust Expect In Prod: .expect(...) panics same as unwrap with a custom message.
platforms/core-configuration/configurat…:34
INFO
MINED092
[MINED092] Java Runtime Exec: Runtime.getRuntime().exec(cmd) with concat string args = co…
platforms/core-configuration/configurat…:99
INFO
MINED092
[MINED092] Java Runtime Exec: Runtime.getRuntime().exec(cmd) with concat string args = co…
platforms/core-configuration/configurat…:68
INFO
MINED092
[MINED092] Java Runtime Exec: Runtime.getRuntime().exec(cmd) with concat string args = co…
platforms/core-configuration/configurat…:79
INFO
MINED069
[MINED069] Debug True Prod: Django/Flask DEBUG=True or app.debug=True in non-test files.
platforms/core-configuration/configurat…:131
INFO
MINED049
[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout.
platforms/core-configuration/kotlin-dsl…:211
INFO
MINED049
[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout.
build-logic/documentation/src/main/groo…:72
INFO
MINED083
[MINED083] Java Thread Start: Raw thread creation. Should use ExecutorService for managed…
build-logic/cleanup/src/main/java/gradl…:261
INFO
MINED086
[MINED086] Kotlin Runtime Exception: Throwing bare RuntimeException loses type info.
build-logic/build-update-utils/src/main…:99
INFO
MINED086
[MINED086] Kotlin Runtime Exception: Throwing bare RuntimeException loses type info.
build-logic/build-update-utils/src/main…:64
INFO
MINED086
[MINED086] Kotlin Runtime Exception: Throwing bare RuntimeException loses type info.
build-logic/build-update-utils/src/main…:133
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
build-logic/binary-compatibility/src/ma…:35
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
build-logic/binary-compatibility/src/ma…:37
INFO
MINED048
[MINED048] Php Error Suppress: @function() suppresses errors silently. Hides real issues.
build-logic/binary-compatibility/src/ma…:31
INFO
MINED048
[MINED048] Php Error Suppress: @function() suppresses errors silently. Hides real issues.
build-logic/binary-compatibility/src/ma…:36
INFO
MINED048
[MINED048] Php Error Suppress: @function() suppresses errors silently. Hides real issues.
build-logic/binary-compatibility/src/ma…:30
INFO
MINED042
[MINED042] Cpp New Without Delete: C++ raw new without RAII / unique_ptr — memory leak ri…
build-logic/binary-compatibility/src/ma…:29
INFO
MINED042
[MINED042] Cpp New Without Delete: C++ raw new without RAII / unique_ptr — memory leak ri…
build-logic/binary-compatibility/src/ma…:30
INFO
MINED042
[MINED042] Cpp New Without Delete: C++ raw new without RAII / unique_ptr — memory leak ri…
build-logic/binary-compatibility/src/ma…:46
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
build-logic/build-update-utils/src/main…:68
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
build-logic-commons/publishing/src/main…:83
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
build-logic-commons/publishing/src/main…:54
INFO
MINED085
[MINED085] Java Systemexit: System.exit() inside a library kills the whole JVM.
.teamcity/scripts/CheckRemoteProjectRef…:36
INFO
MINED085
[MINED085] Java Systemexit: System.exit() inside a library kills the whole JVM.
.teamcity/scripts/CheckBadMerge.java:51
INFO
MINED085
[MINED085] Java Systemexit: System.exit() inside a library kills the whole JVM.
.teamcity/.mvn/wrapper/MavenWrapperDown…:89
INFO
MINED081
[MINED081] Java Printstacktrace: Should use logger, not stack trace to stderr.
build-logic/performance-testing/src/mai…:51
INFO
MINED081
[MINED081] Java Printstacktrace: Should use logger, not stack trace to stderr.
build-logic/cleanup/src/main/java/gradl…:269
INFO
MINED081
[MINED081] Java Printstacktrace: Should use logger, not stack trace to stderr.
.teamcity/.mvn/wrapper/MavenWrapperDown…:92