CRIT
MINED123
[MINED123] Trojan Source bidi character (LRM) in source: Line 2 contains a Unicode bidire…
graphql/internal/graphiql/graphiql.min.…:2
HIGH
SEC090
[SEC090] Go: math/rand used near crypto context: math/rand is not cryptographically secur…
p2p/dnsdisc/sync.go:21
HIGH
MINED033
[MINED033] Go Recover Without Log: defer func() { recover() }() that silently swallows pa…
log/format.go:125
HIGH
MINED033
[MINED033] Go Recover Without Log: defer func() { recover() }() that silently swallows pa…
internal/utesting/utesting.go:253
HIGH
MINED033
[MINED033] Go Recover Without Log: defer func() { recover() }() that silently swallows pa…
internal/jsre/pretty.go:113
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
internal/jsre/jsre.go:275
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
graphql/service.go:108
HIGH
SEC093
[SEC093] Go: exec.Command with non-literal: exec.Command(<var>) — variable command name a…
crypto/signify/signify_fuzz.go:88
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
core/state/snapshot/conversion.go:359
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
core/state/snapshot/context.go:180
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
core/blockchain_stats.go:68
HIGH
MINED016
[MINED016] Go Error Ignored: _, err := fn() with err not checked. Go anti-pattern.
cmd/devp2p/dns_cloudflare.go:146
HIGH
MINED016
[MINED016] Go Error Ignored: _, err := fn() with err not checked. Go anti-pattern.
cmd/devp2p/discv5cmd.go:87
HIGH
MINED016
[MINED016] Go Error Ignored: _, err := fn() with err not checked. Go anti-pattern.
accounts/scwallet/hub.go:132
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
accounts/scwallet/hub.go:185
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
accounts/manager.go:191
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
accounts/keystore/account_cache.go:43
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/go.yml:20
HIGH
MINED115
[MINED115] Action `actions/github-script` pinned to mutable ref `@v7`: `uses: actions/git…
.github/workflows/validate_pr.yml:54
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/validate_pr.yml:51
HIGH
MINED115
[MINED115] Action `actions/github-script` pinned to mutable ref `@v7`: `uses: actions/git…
.github/workflows/validate_pr.yml:12
HIGH
MINED115
[MINED115] Action `vmactions/freebsd-vm` pinned to mutable ref `@v1`: `uses: vmactions/fr…
.github/workflows/freebsd.yml:19
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/freebsd.yml:13
HIGH
MINED128
[MINED128] go.mod replaces `github.com/ethereum/go-ethereum` — points to a LOCAL path: `r…
cmd/keeper/go.mod:46
HIGH
MINED126
[MINED126] Workflow container/services image `sagemath/sagemath:latest` unpinned: `contai…
crypto/secp256k1/libsecp256k1/.github/w…:856
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:873
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:861
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:841
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:808
HIGH
MINED115
[MINED115] Action `ilammy/msvc-dev-cmd` pinned to mutable ref `@v1`: `uses: ilammy/msvc-d…
crypto/secp256k1/libsecp256k1/.github/w…:783
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:780
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:752
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:700
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:641
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:587
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:531
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:467
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:410
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:355
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:308
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:251
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:198
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:152
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
crypto/secp256k1/libsecp256k1/.github/w…:101
HIGH
MINED118
[MINED118] Dockerfile FROM `debian:stable-slim` not pinned by digest: `FROM debian:stable…
crypto/secp256k1/libsecp256k1/ci/linux-…:1
HIGH
MINED118
[MINED118] Dockerfile FROM `alpine:latest` not pinned by digest: `FROM alpine:latest` res…
Dockerfile:20
HIGH
MINED118
[MINED118] Dockerfile FROM `golang:1.26-alpine` not pinned by digest: `FROM golang:1.26-a…
Dockerfile:7
HIGH
MINED118
[MINED118] Dockerfile FROM `alpine:latest` not pinned by digest: `FROM alpine:latest` res…
Dockerfile.alltools:27
HIGH
MINED118
[MINED118] Dockerfile FROM `golang:1.26-alpine` not pinned by digest: `FROM golang:1.26-a…
Dockerfile.alltools:7
HIGH
SEC013
[SEC013] Path Traversal — User Input in File Path: User-controlled input used in file pat…
crypto/secp256k1/libsecp256k1/tools/tes…:14
HIGH
SEC013
[SEC013] Path Traversal — User Input in File Path: User-controlled input used in file pat…
cmd/workload/filtertest.go:155
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
internal/jsre/jsre.go:275
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
graphql/service.go:108
MED
SEC094
[SEC094] Go: world-writable file permissions: File or directory created with world-writab…
cmd/workload/prooftest.go:65
MED
SEC094
[SEC094] Go: world-writable file permissions: File or directory created with world-writab…
cmd/workload/historytest.go:60
MED
SEC094
[SEC094] Go: world-writable file permissions: File or directory created with world-writab…
cmd/workload/filtertest.go:161
MED
SEC112
[SEC112] Go html/template bypass — text/template used for HTML output, or template.HTML o…
crypto/signify/signify.go:96
MED
SEC112
[SEC112] Go html/template bypass — text/template used for HTML output, or template.HTML o…
cmd/rlpdump/main.go:147
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
metrics/exp/exp.go:65
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
internal/debug/flags.go:328
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
cmd/devp2p/discv4cmd.go:190
MED
DKR003
Dockerfile base image uses the latest tag
Dockerfile.alltools:27
MED
DKR003
Dockerfile base image uses the latest tag
Dockerfile:20
MED
AUC001
[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks…
—
MED
DKR001
Docker final stage has no non-root USER
Dockerfile.alltools:27
MED
DKR001
Docker final stage has no non-root USER
Dockerfile:20
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
rpc/service.go:204
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
crypto/secp256k1/libsecp256k1/tools/tes…:83
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
cmd/devp2p/internal/ethtest/engine.go:58
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
cmd/devp2p/internal/ethtest/chain.go:197
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
cmd/devp2p/discv4cmd.go:305
LOW
AIC003
Duplicated implementation block across source files
core/types/tx_setcode.go:118
LOW
AIC003
Duplicated implementation block across source files
core/types/tx_setcode.go:117
LOW
AIC003
Duplicated implementation block across source files
core/types/tx_legacy.go:49
LOW
AIC003
Duplicated implementation block across source files
core/types/tx_dynamic_fee.go:38
LOW
AIC003
Duplicated implementation block across source files
core/types/gen_header_json.go:150
LOW
AIC003
Duplicated implementation block across source files
core/state/snapshot/snapshot.go:469
LOW
AIC003
Duplicated implementation block across source files
core/state/snapshot/disklayer.go:51
LOW
AIC003
Duplicated implementation block across source files
core/state/reader.go:38
LOW
AIC003
Duplicated implementation block across source files
core/state/database_ubt.go:79
LOW
AIC003
Duplicated implementation block across source files
consensus/ethash/consensus.go:341
LOW
AIC003
Duplicated implementation block across source files
common/fdlimit/fdlimit_unix.go:19
LOW
AIC003
Duplicated implementation block across source files
common/fdlimit/fdlimit_unix.go:3
LOW
AIC003
Duplicated implementation block across source files
common/fdlimit/fdlimit_darwin.go:20
LOW
AIC003
Duplicated implementation block across source files
cmd/workload/tracetestgen.go:146
LOW
AIC003
Duplicated implementation block across source files
cmd/workload/tracetest.go:89
LOW
AIC003
Duplicated implementation block across source files
cmd/workload/main.go:10
LOW
AIC003
Duplicated implementation block across source files
cmd/evm/staterunner.go:52
LOW
AIC003
Duplicated implementation block across source files
cmd/evm/internal/t8ntool/gen_execresult…:12
LOW
AIC003
Duplicated implementation block across source files
cmd/ethkey/inspect.go:34
LOW
AIC003
Duplicated implementation block across source files
accounts/usbwallet/trezor.go:180
LOW
AIC003
Duplicated implementation block across source files
accounts/usbwallet/hub.go:161
LOW
AIC003
Duplicated implementation block across source files
accounts/abi/event.go:18
LOW
AIC003
Duplicated implementation block across source files
accounts/abi/bind/v2/internal/contracts…:2
LOW
AIC003
Duplicated implementation block across source files
accounts/abi/bind/v2/internal/contracts…:102
LOW
AIC003
Duplicated implementation block across source files
accounts/abi/bind/v2/internal/contracts…:8
LOW
AIC003
Duplicated implementation block across source files
accounts/abi/bind/v2/internal/contracts…:2
LOW
AIC003
Duplicated implementation block across source files
accounts/abi/bind/v2/internal/contracts…:2
LOW
AIC003
Duplicated implementation block across source files
accounts/abi/bind/v2/internal/contracts…:2
LOW
AIC003
Duplicated implementation block across source files
accounts/abi/bind/v2/base.go:59
LOW
AIC003
Duplicated implementation block across source files
accounts/abi/bind/v2/auth.go:20
LOW
DKR008
.dockerignore misses sensitive defaults
.dockerignore
LOW
AIC007
Generated build artifact directory is present at repository root
build:1
LOW
CORE_NO_LICENSE
No LICENSE file
—
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
eth/tracers/internal/tracetest/makeTest…:76
INFO
MINED075
[MINED075] C Malloc No Check: malloc/calloc/realloc return value used without checking fo…
crypto/secp256k1/libsecp256k1/src/preco…:45
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
internal/download/download.go:97
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
internal/debug/flags.go:326
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
cmd/geth/misccmd.go:78
INFO
MINED047
[MINED047] Emoji In Source: Emoji ✅ ❌ 🚀 in code/comments — common AI output unless explic…
cmd/geth/consolecmd.go:39
INFO
MINED057
[MINED057] Todo Bomb: Code path with a TODO/FIXME/HACK comment that gates correctness — l…
trie/transitiontrie/transition.go:191
INFO
MINED057
[MINED057] Todo Bomb: Code path with a TODO/FIXME/HACK comment that gates correctness — l…
cmd/evm/runner.go:210
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
beacon/blsync/engineclient.go:44
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
accounts/abi/bind/v2/auth.go:55
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
accounts/abi/bind/old.go:92
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
accounts/abi/bind/v2/dep_tree.go:117
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
accounts/abi/bind/v2/auth.go:40
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
accounts/abi/abi.go:254