OpenVSX Registry Verified

CodeQL

by GitHub
08018f3c-4590-5696-ba0a-a92aa656dc65 | v1.17.8
51/ 100
MEDIUM risk
-7 since v1.17.7
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (51/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v1.17.8
Artifact
SHA256 1D1…029
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

41 detail rows
Showing 25 of 41 · highest severity first

Publisher Evidence

Low

GitHub

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

50
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

6
Network

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

CodeQL for Visual Studio Code Security Analysis

This extension is GitHub's official CodeQL integration for Visual Studio Code. CodeQL is a well-established static analysis tool used by developers to find security vulnerabilities in their codebases.

Filesystem and Process Access Justification

The extension's network activity is fully justified by its stated purpose. Network calls detected in extension/out/webview.js (lines 51388, 52147, 52611, 52137) and extension/out/extension.js (lines 1928, 1962) use standard fetch and XMLHttpRequest APIs. CodeQL requires these connections to synchronize queries with GitHub's CodeQL servers, download query packs, and upload analysis results. This network behavior is expected for a tool that integrates with cloud-based analysis services.

The extension declares zip-a-folder@^3.1.6 as a dependency, which is used for packaging analysis results and query packs. This is a standard Node.js package with no security concerns. Filesystem access for reading source code is the core function of a static analysis tool.

Credential and Secret Access

No credential-access findings were detected. The analysis found zero secret-related findings, and there are no indications of the extension reading .env files, SSH keys, cloud credentials, or VS Code's secret storage. This is appropriate behavior for a code analysis tool that does not need to access developer credentials.

Strongest Counterargument

The most significant concern would be the 57 code-smell findings flagged at high severity. However, these findings stem from YARA rules that match basic Node.js patterns like fetch, exec, fs, and process.env references. According to CVEQ's documented false-positive patterns, code-smell findings are classified as noise and should not drive security verdicts. The extension's network activity, while flagged as medium severity, represents legitimate communication with GitHub's CodeQL infrastructure rather than suspicious data exfiltration.

Conclusion

This extension demonstrates no malicious indicators. The 128 total findings consist entirely of expected behavior: legitimate network calls for cloud integration, standard dependency declarations, and YARA code-smell noise. The extension is published by GitHub, has over 48,000 users, and performs its stated function of static code analysis without any evidence of credential theft, data exfiltration, or supply chain compromise. The zero IoC matches, zero malware signatures, and zero obfuscation findings confirm this is a legitimate development tool.

Key Reasons

  • Official GitHub extension with 48,247 users
  • Zero IoC, malware signatures, or secret findings
  • Network calls are expected for CodeQL cloud integration
  • Code-smell findings are documented YARA noise
  • No credential theft or data exfiltration indicators

False Positive Considerations

  • Code-smell YARA rules matching standard Node.js patterns
  • Network calls flagged as suspicious despite being legitimate for cloud integration
  • Dependency scanning generating findings on standard npm packages
  • Metadata hash entries flagged as findings

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.

Open VSX version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
51
Change since first
-7
Change from previous
-7
Versions:
First analyzed version
1.17.7
Apr 18, 2026
Risk range
51 to 59
Across analyzed versions
Latest analyzed version
1.17.8
Jul 22, 2026
Selected version
medium
Version
v1.17.8
2 months ago
Risk score
51
Findings
41
Change vs previous
-7

Pick any point on the chart to explore that version's code below.

About This Extension

CodeQL for Visual Studio Code

Frequently Asked Questions