github.com / iamveen
iamveen/ devpod-proxmox-provider
Go·21 files·commit a50964f·scanned 2h ago·cached ✓
7/100
SAFE
No malicious patterns found. Repo signals are consistent with a legitimate project.
verdict accurate?
threat-state: safelive
FINDINGS ░▒▓
warningSSH/credential path accessAccessing .ssh, .aws/credentials, or .env files to steal authentication credentials.cmd/create.go
// Step 1: Ensure SSH keypair exists in the machine folder, generating it if needed
privKeyPath := fmt.Sprintf("%s/id_ed25519", opts.MachineFolder)
pubKeyPath := fmt.Sprintf("%s/id_ed25519.pub", op...+5Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
15 files scanned @ a50964f | 9/25/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access5
obfuscation0
supply chain0
owasp / injection0
telemetry
files 15/21rules hit 2engine v6commit a50964f
github
iamveen/devpod-proxmox-provider
3
0
158d
21 files
15 scanned(71%)
a50964f
architecture░▒▓
entry (1) flagged (1) pkg (13)
26 nodes · 30 edgesscroll to zoom · click node to jump to finding