CRIT
MINED024
[MINED024] Js Eval Usage: eval() executes arbitrary code. Code injection risk.
packages/salesforcedx-vscode-lightning/…:176
HIGH
MINED031
[MINED031] React Direct State Mutation: this.state.X = Y mutates without setState. React …
test-workspaces/standard-workspace/src/…:16
HIGH
SEC100
[SEC100] CORS permissive Access-Control-Allow-Origin: *: Permissive CORS policy (`*` orig…
packages/salesforcedx-vscode-services/s…:39
HIGH
SEC100
[SEC100] CORS permissive Access-Control-Allow-Origin: *: Permissive CORS policy (`*` orig…
packages/salesforcedx-vscode-services/s…:156
HIGH
SEC027
[SEC027] XML External Entity (XXE) — Node.js xml parsers: Node.js XML parsers can expand …
packages/salesforcedx-vscode-apex-oas/s…:65
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
packages/salesforcedx-visualforce-marku…:16
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
packages/salesforcedx-apex-debugger/src…:58
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
packages/salesforcedx-apex-debugger/src…:70
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
packages/salesforcedx-lwc-language-serv…:153
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
packages/salesforcedx-aura-language-ser…:165
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
packages/salesforcedx-apex-debugger/src…:231
HIGH
SEC083
[SEC083] JS: new RegExp() with non-literal: new RegExp(<variable>) — variable input can c…
packages/eslint-local-rules/src/queryBu…:78
HIGH
SEC083
[SEC083] JS: new RegExp() with non-literal: new RegExp(<variable>) — variable input can c…
packages/eslint-local-rules/src/noUnuse…:107
HIGH
SEC083
[SEC083] JS: new RegExp() with non-literal: new RegExp(<variable>) — variable input can c…
packages/eslint-local-rules/src/command…:78
HIGH
SEC040
[SEC040] innerHTML XSS — template literal with server-supplied data: Setting .innerHTML w…
packages/salesforcedx-vscode-apex-oas/s…:35
HIGH
SEC040
[SEC040] innerHTML XSS — template literal with server-supplied data: Setting .innerHTML w…
.github/actions/validate-issue/src/node…:16
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
packages/eslint-local-rules/src/queryBu…:79
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
packages/eslint-local-rules/src/i18nUti…:78
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
.claude/skills/release/detect-state.ts:9
HIGH
MINED134
[MINED134] Binary file `packages/salesforcedx-vscode-apex/jars/apex-jorje-lsp.jar` commit…
packages/salesforcedx-vscode-apex/jars/…:1
HIGH
MINED134
[MINED134] Binary file `yourkit-distro/bin/linux-x86-64/libyjpagent.so` committed in sour…
yourkit-distro/bin/linux-x86-64/libyjpa…:1
HIGH
MINED134
[MINED134] Binary file `yourkit-distro/bin/windows-x86-32/yjpagent.dll` committed in sour…
yourkit-distro/bin/windows-x86-32/yjpag…:1
HIGH
MINED134
[MINED134] Binary file `yourkit-distro/bin/linux-arm-64/libyjpagent.so` committed in sour…
yourkit-distro/bin/linux-arm-64/libyjpa…:1
HIGH
MINED134
[MINED134] Binary file `yourkit-distro/bin/linux-arm-32/libyjpagent.so` committed in sour…
yourkit-distro/bin/linux-arm-32/libyjpa…:1
HIGH
MINED134
[MINED134] Binary file `yourkit-distro/bin/linux-x86-32/libyjpagent.so` committed in sour…
yourkit-distro/bin/linux-x86-32/libyjpa…:1
HIGH
MINED134
[MINED134] Binary file `yourkit-distro/bin/mac/libyjpagent.dylib` committed in source rep…
yourkit-distro/bin/mac/libyjpagent.dylib:1
HIGH
MINED134
[MINED134] Binary file `yourkit-distro/bin/windows-x86-64/yjpagent.dll` committed in sour…
yourkit-distro/bin/windows-x86-64/yjpag…:1
HIGH
MINED134
[MINED134] Binary file `yourkit-distro/bin/windows-arm-64/yjpagent.dll` committed in sour…
yourkit-distro/bin/windows-arm-64/yjpag…:1
HIGH
MINED115
[MINED115] Action `actions/setup-node` pinned to mutable ref `@v4`: `uses: actions/setup-…
.github/workflows/servicesE2E.yml:57
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/servicesE2E.yml:52
HIGH
MINED115
[MINED115] Action `actions/setup-node` pinned to mutable ref `@v4`: `uses: actions/setup-…
.github/workflows/validateUpdatedIssues…:90
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/validateUpdatedIssues…:89
HIGH
MINED115
[MINED115] Action `actions/setup-node` pinned to mutable ref `@v4`: `uses: actions/setup-…
.github/workflows/validateUpdatedIssues…:65
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/validateUpdatedIssues…:64
HIGH
MINED115
[MINED115] Action `actions/setup-node` pinned to mutable ref `@v4`: `uses: actions/setup-…
.github/workflows/validateUpdatedIssues…:47
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/validateUpdatedIssues…:46
HIGH
MINED115
[MINED115] Action `actions/setup-node` pinned to mutable ref `@v4`: `uses: actions/setup-…
.github/workflows/validateUpdatedIssues…:31
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/validateUpdatedIssues…:30
HIGH
MINED115
[MINED115] Action `salesforcecli/github-workflows/.github/workflows/npmPublish.yml` pinne…
.github/workflows/publishI18nPackage.yml:101
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/publishI18nPackage.yml:45
HIGH
MINED115
[MINED115] Action `salesforcecli/github-workflows/.github/actions/getGithubUserInfo` pinn…
.github/workflows/publishI18nPackage.yml:42
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/testBuildAndRelease.y…:17
HIGH
MINED115
[MINED115] Action `actions/upload-artifact` pinned to mutable ref `@v4`: `uses: actions/u…
.github/workflows/playwrightVscodeExtE2…:218
HIGH
MINED115
[MINED115] Action `actions/upload-artifact` pinned to mutable ref `@v4`: `uses: actions/u…
.github/workflows/playwrightVscodeExtE2…:210
HIGH
MINED115
[MINED115] Action `salesforcecli/github-workflows/.github/actions/retry` pinned to mutabl…
.github/workflows/playwrightVscodeExtE2…:177
HIGH
MINED115
[MINED115] Action `salesforcecli/github-workflows/.github/actions/npmInstallWithRetries` …
.github/workflows/playwrightVscodeExtE2…:154
HIGH
MINED115
[MINED115] Action `actions/setup-node` pinned to mutable ref `@v4`: `uses: actions/setup-…
.github/workflows/playwrightVscodeExtE2…:146
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/playwrightVscodeExtE2…:137
HIGH
MINED115
[MINED115] Action `actions/upload-artifact` pinned to mutable ref `@v4`: `uses: actions/u…
.github/workflows/playwrightVscodeExtE2…:114
HIGH
MINED115
[MINED115] Action `actions/upload-artifact` pinned to mutable ref `@v4`: `uses: actions/u…
.github/workflows/playwrightVscodeExtE2…:106
HIGH
MINED115
[MINED115] Action `salesforcecli/github-workflows/.github/actions/npmInstallWithRetries` …
.github/workflows/playwrightVscodeExtE2…:59
HIGH
MINED115
[MINED115] Action `actions/setup-node` pinned to mutable ref `@v4`: `uses: actions/setup-…
.github/workflows/playwrightVscodeExtE2…:51
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/playwrightVscodeExtE2…:46
HIGH
MINED122
[MINED122] package.json dep `codemirror` pulled from URL/Git: `devDependencies.codemirror…
packages/salesforcedx-aura-language-ser…:1
MED
SEC087
[SEC087] JS: weak Math.random for crypto: Math.random() is not cryptographically secure; …
packages/salesforcedx-vscode-lightning/…:109
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
packages/salesforcedx-vscode-lwc/src/te…:20
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
packages/playwright-vscode-ext/src/page…:63
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
packages/salesforcedx-lwc-language-serv…:93
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
packages/eslint-local-rules/src/queryBu…:79
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
packages/eslint-local-rules/src/i18nUti…:78
MED
JRN002
Browser storage is used for session token material
packages/salesforcedx-vscode-lightning/…:3871
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
packages/salesforcedx-vscode-lightning/…:45
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
packages/salesforcedx-vscode-lightning/…:130
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
packages/salesforcedx-vscode-lightning/…:202
LOW
AIC003
Duplicated implementation block across source files
packages/salesforcedx-vscode-i18n/scrip…:1
LOW
AIC003
Duplicated implementation block across source files
packages/salesforcedx-vscode-core/src/c…:41
LOW
AIC003
Duplicated implementation block across source files
packages/salesforcedx-visualforce-marku…:107
LOW
AIC003
Duplicated implementation block across source files
packages/salesforcedx-utils/src/helpers…:3
LOW
AIC003
Duplicated implementation block across source files
packages/salesforcedx-utils-vscode/src/…:48
LOW
AIC003
Duplicated implementation block across source files
packages/salesforcedx-utils-vscode/src/…:15
LOW
AIC003
Duplicated implementation block across source files
packages/playwright-vscode-ext/src/orgs…:16
LOW
AIC003
Duplicated implementation block across source files
packages/eslint-local-rules/src/package…:44
LOW
AIC003
Duplicated implementation block across source files
packages/eslint-local-rules/src/package…:13
LOW
AIC003
Duplicated implementation block across source files
packages/eslint-local-rules/src/package…:17
LOW
AIC003
Duplicated implementation block across source files
packages/eslint-local-rules/src/package…:38
LOW
AIC003
Duplicated implementation block across source files
packages/eslint-local-rules/src/package…:70
LOW
AIC003
Duplicated implementation block across source files
packages/eslint-local-rules/src/noVscod…:35
LOW
AIC003
Duplicated implementation block across source files
packages/eslint-local-rules/src/noVscod…:23
LOW
AIC003
Duplicated implementation block across source files
packages/eslint-local-rules/src/noVscod…:1
LOW
AIC003
Duplicated implementation block across source files
packages/eslint-local-rules/src/noVscod…:1
LOW
AIC003
Duplicated implementation block across source files
.github/actions/validate-issue/src/inde…:52
LOW
AIC003
Duplicated implementation block across source files
.github/actions/new-issue/src/index.ts:23
LOW
WEB005
robots.txt does not advertise a sitemap
.github/actions/validate-issue/lib/inde…
INFO
MINED098
[MINED098] Global Scope Pollution: Attaching libraries/objects directly to the global win…
scripts/bundling/process-global.js:8
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
scripts/xsd/jsonToXsdConverter.ts:146
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
packages/salesforcedx-vscode-services/s…:34
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
packages/salesforcedx-vscode-org/src/me…:9
INFO
MINED055
[MINED055] Npm Install No Lockfile: Production image runs npm install (resolves new versi…
scripts/package-lock.validation.ts:16
INFO
MINED055
[MINED055] Npm Install No Lockfile: Production image runs npm install (resolves new versi…
packages/salesforcedx-vscode-lwc/src/me…:20
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
packages/playwright-vscode-ext/src/util…:29
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
packages/playwright-vscode-ext/src/page…:39
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
packages/playwright-vscode-ext/src/page…:218
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
packages/salesforcedx-vscode-apex-debug…:235
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
packages/salesforcedx-utils-vscode/src/…:58
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
packages/eslint-local-rules/src/package…:48
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
packages/eslint-local-rules/src/package…:97
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
packages/eslint-local-rules/src/package…:176
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
packages/eslint-local-rules/src/package…:63
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
packages/playwright-vscode-ext/src/orgs…:64
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
.github/actions/new-issue/src/index.ts:26
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
.github/actions/check-feature-request/s…:26