OpenShift Dev Spaces
Based on the RiskyPlugins AI security review of the observed evidence.
No individual score drivers were recorded for this analysis.
Analysis record
- Analysed
- Today
- Version
- v0.0.19
- Artifact
- SHA256 059…15D
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
9 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall obfuscation | 33 | devspaces-gateway-plugin/lib/bcprov-jdk18on-1.80.2.jardevspaces-gateway-plugin/lib/aws-java-sdk-core-1.12.783.jardevspaces-gateway-plugin/lib/nimbus-jose-jwt-10.9.jar +30 more | - |
| LOW | postinstall network communication | 25 | devspaces-gateway-plugin/lib/guava-33.4.0-jre.jardevspaces-gateway-plugin/lib/client-java-api-24.0.0.jardevspaces-gateway-plugin/lib/client-java-24.0.0.jar +22 more | - |
| LOW | postinstall crypto operations | 20 | devspaces-gateway-plugin/lib/kotlin-stdlib-2.1.20.jardevspaces-gateway-plugin/lib/jackson-databind-2.22.1.jardevspaces-gateway-plugin/lib/bcutil-jdk18on-1.80.2.jar +17 more | - |
| LOW | postinstall file manipulation | 12 | devspaces-gateway-plugin/lib/client-java-api-24.0.0.jardevspaces-gateway-plugin/lib/oauth2-oidc-sdk-11.38.jardevspaces-gateway-plugin/lib/commons-collections4-4.5.0.jar +9 more | - |
| LOW | postinstall system command | 27 | devspaces-gateway-plugin/lib/client-java-proto-24.0.0.jardevspaces-gateway-plugin/lib/protobuf-java-4.31.0.jardevspaces-gateway-plugin/lib/simpleclient-0.16.0.jar +24 more | - |
| LOW | JavaDropper | 3 | devspaces-gateway-plugin/lib/client-java-proto-24.0.0.jardevspaces-gateway-plugin/lib/joda-time-2.12.7.jardevspaces-gateway-plugin/lib/kotlinx-serialization-core-jvm-1.8.1.jar | - |
| LOW | postinstall registry modification | 8 | devspaces-gateway-plugin/lib/httpclient-4.5.14.jardevspaces-gateway-plugin/lib/opencensus-api-0.31.1.jardevspaces-gateway-plugin/lib/protobuf-java-4.31.0.jar +5 more | - |
| LOW | postinstall file download | 8 | devspaces-gateway-plugin/lib/aws-java-sdk-core-1.12.783.jardevspaces-gateway-plugin/lib/jackson-databind-2.22.1.jardevspaces-gateway-plugin/lib/httpcore-4.4.16.jar +5 more | - |
| LOW | postinstall persistence mechanism | 7 | devspaces-gateway-plugin/lib/client-java-api-24.0.0.jardevspaces-gateway-plugin/lib/grpc-api-1.70.0.jardevspaces-gateway-plugin/lib/client-java-proto-24.0.0.jar +4 more | - |
Publisher Evidence
LowRed-Hat
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
11 evidence rows available.
Finding Categories
YARA Rules Matched
9 rules(143 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The OpenShift Dev Spaces extension published by Red Hat on the JetBrains marketplace presents no security concerns. All 95 findings are metadata-level hash entries tracking bundled JAR dependencies in the devspaces-gateway-plugin/lib/ directory, including standard Java libraries such as swagger-annotations-1.6.16.jar, netty-handler-4.1.126.Final.jar, grpc-context-1.70.0.jar, and httpcore-4.4.16.jar. There are zero findings in critical, high, medium, or low severity categories.
No malware signatures were detected. The findings summary shows zero results for ioc, malware-signature, malware, network, obfuscation, dependency, secret, code-smell, and tool-poisoning categories. This means the extension contains no suspicious network destinations, no credential-access patterns targeting .env files or cloud credentials, no obfuscated code, and no supply chain indicators.
The filesystem and process access is justified by the extension's stated purpose as a Dev Spaces gateway plugin. Extensions of this type require bundled dependencies to communicate with OpenShift clusters and provide development environment functionality. The presence of networking libraries like netty-handler-4.1.126.Final.jar and http-auth-aws-2.33.13.jar in the devspaces-gateway-plugin/lib/ directory is expected behavior for a cloud development tool, not evidence of exfiltration or unauthorized communication.
No credential-access findings target actual secrets. The secret category shows zero findings, meaning the analyzer detected no patterns matching .env files, SSH keys, cloud credentials, or VS Code secret storage access. The http-auth-aws-2.33.13.jar dependency is a standard AWS authentication library, not evidence of credential theft.
The strongest counterargument to this verdict is the high finding count of 95, which might suggest widespread issues. However, this is entirely explained by the presence of bundled JAR dependencies, which is normal for Java-based IDE extensions. Each bundled library generates its own metadata hash finding, creating multiplicative counts without security implications. This pattern is documented as expected behavior in the CVEQ threat model.
Red Hat is a verified enterprise software publisher with established security practices. The extension has 4,583 users on the JetBrains marketplace, indicating moderate adoption and community trust. The combination of a reputable publisher, zero security-relevant findings, and findings limited to bundled dependency metadata confirms this is a legitimate development tool with no malicious indicators.
Key Reasons
- Zero findings in all security-relevant categories
- All 95 findings are metadata hashes of bundled JAR dependencies
- Publisher is verified enterprise vendor (Red Hat)
- No credential access, malware signatures, or suspicious network activity
- Findings pattern matches expected bundled dependency behavior
False Positive Considerations
- Bundled JAR dependencies generating metadata hash findings
- All findings are severity info with zero critical/high/medium/low
- Zero findings in security-relevant categories (ioc, malware, secret, network)
- Verified publisher (Red Hat) on legitimate marketplace (JetBrains)
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.
JetBrains version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Migration Toolkit for Runtimes (MTR) by Red Hat
Red-Hat
Migration Toolkit for Applications (MTA) by Red Hat
Red-Hat
Kubernetes by Red Hat
Red-Hat
Red Hat OpenShift Dev Spaces
Red-Hat
LSP4IJ
Red-Hat
Red Hat Dependency Analytics
Red-Hat