Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

saurav-z/vsc-ssh-extension

https://github.com/saurav-z/vsc-ssh-extension · scanned 2026-07-28 10:52 UTC (0 minutes ago)

32 raw signals (0 security + 32 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 0 minutes ago · v1 · 32 actionable findings from 1 signal source. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: excluding tests × Reset all
Scan summary Repository scanned at 94.2/100 with 70.0% coverage. It contains 55 nodes across 0 cross-layer flows, written primarily in mixed languages. Engine surfaced 32 findings — concentrated in dependencies (27), security (2), quality (2). Risk profile is high: 0 critical, 18 high, 9 medium. Recommended next step: open the dependencies layer findings first — that's where the highest-impact wins live.

Showing 32 of 32 actionable findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

high System graph security security conf 0.90 Insecure pattern 'node_child_process' in src/keyDeploy.ts:19
Found a known-risky pattern (node_child_process). Review and replace if possible.
src/keyDeploy.ts:19 Node child process
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.14: GHSA-3jxr-9vmj-r5cp
OSV.dev reports `brace-expansion` at version `1.1.14` (resolved in `package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expansion: DoS via exponent…
package-lock.json ScaOsvGhsa 3jxr 9vmj r5cp
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.14: GHSA-mh99-v99m-4gvg
OSV.dev reports `brace-expansion` at version `1.1.14` (resolved in `package-lock.json`) is affected by GHSA-mh99-v99m-4gvg (aka CVE-2026-14257). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expansion: DoS via unbounde…
package-lock.json ScaOsvGhsa mh99 v99m 4gvg
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 2.1.0: GHSA-3jxr-9vmj-r5cp
OSV.dev reports `brace-expansion` at version `2.1.0` (resolved in `package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expansion: DoS via exponenti…
package-lock.json ScaOsvGhsa 3jxr 9vmj r5cp
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 2.1.0: GHSA-mh99-v99m-4gvg
OSV.dev reports `brace-expansion` at version `2.1.0` (resolved in `package-lock.json`) is affected by GHSA-mh99-v99m-4gvg (aka CVE-2026-14257). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expansion: DoS via unbounded…
package-lock.json ScaOsvGhsa mh99 v99m 4gvg
high System graph dependencies dependencies conf 0.90 Vulnerable dependency fast-uri 3.1.0: GHSA-4c8g-83qw-93j6
OSV.dev reports `fast-uri` at version `3.1.0` (resolved in `package-lock.json`) is affected by GHSA-4c8g-83qw-93j6 (aka CVE-2026-13676). Note: `fast-uri` is a transitive dependency — pulled in by another package, not declared directly in a manifest. fast-uri vulnerable to host confusion via failed…
package-lock.json ScaOsvGhsa 4c8g 83qw 93j6
high System graph dependencies dependencies conf 0.90 Vulnerable dependency fast-uri 3.1.0: GHSA-q3j6-qgpj-74h6
OSV.dev reports `fast-uri` at version `3.1.0` (resolved in `package-lock.json`) is affected by GHSA-q3j6-qgpj-74h6 (aka CVE-2026-6321). Note: `fast-uri` is a transitive dependency — pulled in by another package, not declared directly in a manifest. fast-uri vulnerable to path traversal via percent…
package-lock.json ScaOsvGhsa q3j6 qgpj 74h6
high System graph dependencies dependencies conf 0.90 Vulnerable dependency fast-uri 3.1.0: GHSA-v2hh-gcrm-f6hx
OSV.dev reports `fast-uri` at version `3.1.0` (resolved in `package-lock.json`) is affected by GHSA-v2hh-gcrm-f6hx (aka CVE-2026-16221). Note: `fast-uri` is a transitive dependency — pulled in by another package, not declared directly in a manifest. fast-uri vulnerable to host confusion via litera…
package-lock.json ScaOsvGhsa v2hh gcrm f6hx
high System graph dependencies dependencies conf 0.90 Vulnerable dependency fast-uri 3.1.0: GHSA-v39h-62p7-jpjc
OSV.dev reports `fast-uri` at version `3.1.0` (resolved in `package-lock.json`) is affected by GHSA-v39h-62p7-jpjc (aka CVE-2026-6322). Note: `fast-uri` is a transitive dependency — pulled in by another package, not declared directly in a manifest. fast-uri vulnerable to host confusion via percent…
package-lock.json ScaOsvGhsa v39h 62p7 jpjc
high System graph dependencies dependencies conf 0.90 Vulnerable dependency form-data 4.0.5: GHSA-hmw2-7cc7-3qxx
OSV.dev reports `form-data` at version `4.0.5` (resolved in `package-lock.json`) is affected by GHSA-hmw2-7cc7-3qxx (aka CVE-2026-12143). Note: `form-data` is a transitive dependency — pulled in by another package, not declared directly in a manifest. form-data: CRLF injection in form-data via une…
package-lock.json ScaOsvGhsa hmw2 7cc7 3qxx
high System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 4.1.1: GHSA-52cp-r559-cp3m
OSV.dev reports `js-yaml` at version `4.1.1` (resolved in `package-lock.json`) is affected by GHSA-52cp-r559-cp3m (aka CVE-2026-59869). Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. js-yaml: YAML merge-key chains can force quadratic…
package-lock.json ScaOsvGhsa 52cp r559 cp3m
high System graph dependencies dependencies conf 0.90 Vulnerable dependency linkify-it 3.0.3: GHSA-22p9-wv53-3rq4
OSV.dev reports `linkify-it` at version `3.0.3` (resolved in `package-lock.json`) is affected by GHSA-22p9-wv53-3rq4 (aka CVE-2026-48801). Note: `linkify-it` is a transitive dependency — pulled in by another package, not declared directly in a manifest. LinkifyIt#match scan loop has quadratic algo…
package-lock.json ScaOsvGhsa 22p9 wv53 3rq4
high System graph dependencies dependencies conf 0.90 Vulnerable dependency linkify-it 3.0.3: GHSA-v245-v573-v5vm
OSV.dev reports `linkify-it` at version `3.0.3` (resolved in `package-lock.json`) is affected by GHSA-v245-v573-v5vm (aka CVE-2026-59887). Note: `linkify-it` is a transitive dependency — pulled in by another package, not declared directly in a manifest. linkify-it: Quadratic-complexity DoS via the…
package-lock.json ScaOsvGhsa v245 v573 v5vm
high System graph dependencies dependencies conf 0.90 Vulnerable dependency tmp 0.2.5: GHSA-ph9p-34f9-6g65
OSV.dev reports `tmp` at version `0.2.5` (resolved in `package-lock.json`) is affected by GHSA-ph9p-34f9-6g65 (aka CVE-2026-44705). Note: `tmp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. tmp has Path Traversal via unsanitized prefix/postfix that…
package-lock.json ScaOsvGhsa ph9p 34f9 6g65
high System graph dependencies dependencies conf 0.90 Vulnerable dependency undici 7.25.0: GHSA-hm92-r4w5-c3mj
OSV.dev reports `undici` at version `7.25.0` (resolved in `package-lock.json`) is affected by GHSA-hm92-r4w5-c3mj (aka CVE-2026-6734). Note: `undici` is a transitive dependency — pulled in by another package, not declared directly in a manifest. undici vulnerable to cross-origin request routing vi…
package-lock.json ScaOsvGhsa hm92 r4w5 c3mj
high System graph dependencies dependencies conf 0.90 Vulnerable dependency undici 7.25.0: GHSA-vmh5-mc38-953g
OSV.dev reports `undici` at version `7.25.0` (resolved in `package-lock.json`) is affected by GHSA-vmh5-mc38-953g (aka CVE-2026-9697). Note: `undici` is a transitive dependency — pulled in by another package, not declared directly in a manifest. undici vulnerable to TLS certificate validation bypa…
package-lock.json ScaOsvGhsa vmh5 mc38 953g
high System graph dependencies dependencies conf 0.90 Vulnerable dependency undici 7.25.0: GHSA-vxpw-j846-p89q
OSV.dev reports `undici` at version `7.25.0` (resolved in `package-lock.json`) is affected by GHSA-vxpw-j846-p89q (aka CVE-2026-12151). Note: `undici` is a transitive dependency — pulled in by another package, not declared directly in a manifest. undici WebSocket client vulnerable to denial of ser…
package-lock.json ScaOsvGhsa vxpw j846 p89q
high System graph dependencies dependencies conf 0.90 Vulnerable dependency uuid 8.3.2: GHSA-w5hq-g745-h8pq
OSV.dev reports `uuid` at version `8.3.2` (resolved in `package-lock.json`) is affected by GHSA-w5hq-g745-h8pq (aka CVE-2026-41907, CVE-2026-41988). Note: `uuid` is a transitive dependency — pulled in by another package, not declared directly in a manifest. uuid: Missing buffer bounds check in v3/…
package-lock.json ScaOsvGhsa w5hq g745 h8pq
medium System graph security Coverage conf 1.00 No auth library detected
The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing.
auth
medium System graph cicd CI/CD security conf 1.00 No CI/CD pipelines detected
No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints.
CI/CD securityCoverage
medium System graph quality Tests conf 1.00 Very low test-to-source ratio
0 test file(s) for 10 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths.
Coverage
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 4.1.1: GHSA-h67p-54hq-rp68
OSV.dev reports `js-yaml` at version `4.1.1` (resolved in `package-lock.json`) is affected by GHSA-h67p-54hq-rp68 (aka CVE-2026-53550). Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. JS-YAML: Quadratic-complexity DoS in merge key han…
package-lock.json ScaOsvGhsa h67p 54hq rp68
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency markdown-it 12.3.2: GHSA-6v5v-wf23-fmfq
OSV.dev reports `markdown-it` at version `12.3.2` (resolved in `package-lock.json`) is affected by GHSA-6v5v-wf23-fmfq (aka CVE-2026-48988). Note: `markdown-it` is a transitive dependency — pulled in by another package, not declared directly in a manifest. markdown-it: Quadratic complexity DoS in …
package-lock.json ScaOsvGhsa 6v5v wf23 fmfq
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency qs 6.15.1: GHSA-q8mj-m7cp-5q26
OSV.dev reports `qs` at version `6.15.1` (resolved in `package-lock.json`) is affected by GHSA-q8mj-m7cp-5q26 (aka CVE-2026-8723). Note: `qs` is a transitive dependency — pulled in by another package, not declared directly in a manifest. qs has a remotely triggerable DoS: qs.stringify crashes with…
package-lock.json ScaOsvGhsa q8mj m7cp 5q26
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency undici 7.25.0: GHSA-p88m-4jfj-68fv
OSV.dev reports `undici` at version `7.25.0` (resolved in `package-lock.json`) is affected by GHSA-p88m-4jfj-68fv (aka CVE-2026-9679). Note: `undici` is a transitive dependency — pulled in by another package, not declared directly in a manifest. undici vulnerable to HTTP header injection via Set-C…
package-lock.json ScaOsvGhsa p88m 4jfj 68fv
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency undici 7.25.0: GHSA-pr7r-676h-xcf6
OSV.dev reports `undici` at version `7.25.0` (resolved in `package-lock.json`) is affected by GHSA-pr7r-676h-xcf6 (aka CVE-2026-9678). Note: `undici` is a transitive dependency — pulled in by another package, not declared directly in a manifest. undici vulnerable to cross-user information disclosu…
package-lock.json ScaOsvGhsa pr7r 676h xcf6
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency webpack 5.91.0: GHSA-4vvj-4cpr-p986
OSV.dev reports `webpack` at version `5.91.0` (declared in `package.json`) is affected by GHSA-4vvj-4cpr-p986 (aka CVE-2024-43788). Note: `5.91.0` is the declared floor of a range — the installed version may be newer. Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to …
package.json ScaOsvGhsa 4vvj 4cpr p986
low System graph quality Production readiness conf 1.00 Composite production-readiness gap
Multiple low-cost hardening controls are missing together: ci, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation.
Repo hardeningGenerated repo pattern
low System graph dependencies dependencies conf 0.90 Vulnerable dependency undici 7.25.0: GHSA-35p6-xmwp-9g52
OSV.dev reports `undici` at version `7.25.0` (resolved in `package-lock.json`) is affected by GHSA-35p6-xmwp-9g52 (aka CVE-2026-6733). Note: `undici` is a transitive dependency — pulled in by another package, not declared directly in a manifest. undici vulnerable to HTTP response queue poisoning v…
package-lock.json ScaOsvGhsa 35p6 xmwp 9g52
low System graph dependencies dependencies conf 0.90 Vulnerable dependency undici 7.25.0: GHSA-g8m3-5g58-fq7m
OSV.dev reports `undici` at version `7.25.0` (resolved in `package-lock.json`) is affected by GHSA-g8m3-5g58-fq7m (aka CVE-2026-11525). Note: `undici` is a transitive dependency — pulled in by another package, not declared directly in a manifest. undici vulnerable to Set-Cookie SameSite attribute …
package-lock.json ScaOsvGhsa g8m3 5g58 fq7m
low System graph dependencies dependencies conf 0.70 Vulnerable dependency webpack 5.91.0: GHSA-38r7-794h-5758
OSV.dev reports `webpack` at version `5.91.0` (declared in `package.json`) is affected by GHSA-38r7-794h-5758 (aka CVE-2025-68157). Note: `5.91.0` is the declared floor of a range — the installed version may be newer. webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + c…
package.json ScaOsvGhsa 38r7 794h 5758
low System graph dependencies dependencies conf 0.70 Vulnerable dependency webpack 5.91.0: GHSA-8fgc-7cc6-rx7x
OSV.dev reports `webpack` at version `5.91.0` (declared in `package.json`) is affected by GHSA-8fgc-7cc6-rx7x (aka CVE-2025-68458). Note: `5.91.0` is the declared floor of a range — the installed version may be newer. webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to…
package.json ScaOsvGhsa 8fgc 7cc6 rx7x
For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/b855d492-7a7f-46e3-a07d-8e88d63898bf/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/b855d492-7a7f-46e3-a07d-8e88d63898bf/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.