live · scanning repos
Scanrepo
github.com
github.com / iamveen

iamveen/devpod-proxmox-provider

Go·21 files·commit a50964f·scanned 2h ago·cached ✓
7/100
SAFE
No malicious patterns found. Repo signals are consistent with a legitimate project.
verdict accurate?
threat-state: safelive

FINDINGS ░▒▓

infoSuspicious files are not reachable from entry pointsFlagged files exist but are not imported by any entry point. They may be dead code, tests, or attack payloads triggered by another mechanism.+2
warningSSH/credential path accessAccessing .ssh, .aws/credentials, or .env files to steal authentication credentials.cmd/create.go
	// Step 1: Ensure SSH keypair exists in the machine folder, generating it if needed
	privKeyPath := fmt.Sprintf("%s/id_ed25519", opts.MachineFolder)
	pubKeyPath := fmt.Sprintf("%s/id_ed25519.pub", op...
+5

Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.

15 files scanned @ a50964f | 9/25/2026 | heuristic scan — always review manually

risk by category
code execution2
network & exfiltration0
file system access5
obfuscation0
supply chain0
owasp / injection0
telemetry
files 15/21rules hit 2engine v6commit a50964f

github

iamveen/devpod-proxmox-provider

Go
3
0
158d
21 files
15 scanned(71%)
a50964f

architecture░▒▓

entry (1) flagged (1) pkg (13)
26 nodes · 30 edgesscroll to zoom · click node to jump to finding