JetBrains Marketplace Verified

OpenShift Dev Spaces

by Red-Hat · 6.3K users
72c2e586-93f8-54d1-9fa9-5835c4ab86f5 | v0.0.19
36/ 100
LOW risk
No change since v0.0.18
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
Today
Version
v0.0.19
Artifact
SHA256 059…15D
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

215 detail rows
Showing 25 of 72 · highest severity first

YARA Rule Matches

9 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall obfuscation 33
devspaces-gateway-plugin/lib/bcprov-jdk18on-1.80.2.jardevspaces-gateway-plugin/lib/aws-java-sdk-core-1.12.783.jardevspaces-gateway-plugin/lib/nimbus-jose-jwt-10.9.jar +30 more
-
LOWpostinstall network communication 25
devspaces-gateway-plugin/lib/guava-33.4.0-jre.jardevspaces-gateway-plugin/lib/client-java-api-24.0.0.jardevspaces-gateway-plugin/lib/client-java-24.0.0.jar +22 more
-
LOWpostinstall crypto operations 20
devspaces-gateway-plugin/lib/kotlin-stdlib-2.1.20.jardevspaces-gateway-plugin/lib/jackson-databind-2.22.1.jardevspaces-gateway-plugin/lib/bcutil-jdk18on-1.80.2.jar +17 more
-
LOWpostinstall file manipulation 12
devspaces-gateway-plugin/lib/client-java-api-24.0.0.jardevspaces-gateway-plugin/lib/oauth2-oidc-sdk-11.38.jardevspaces-gateway-plugin/lib/commons-collections4-4.5.0.jar +9 more
-
LOWpostinstall system command 27
devspaces-gateway-plugin/lib/client-java-proto-24.0.0.jardevspaces-gateway-plugin/lib/protobuf-java-4.31.0.jardevspaces-gateway-plugin/lib/simpleclient-0.16.0.jar +24 more
-
LOWJavaDropper 3
devspaces-gateway-plugin/lib/client-java-proto-24.0.0.jardevspaces-gateway-plugin/lib/joda-time-2.12.7.jardevspaces-gateway-plugin/lib/kotlinx-serialization-core-jvm-1.8.1.jar
-
LOWpostinstall registry modification 8
devspaces-gateway-plugin/lib/httpclient-4.5.14.jardevspaces-gateway-plugin/lib/opencensus-api-0.31.1.jardevspaces-gateway-plugin/lib/protobuf-java-4.31.0.jar +5 more
-
LOWpostinstall file download 8
devspaces-gateway-plugin/lib/aws-java-sdk-core-1.12.783.jardevspaces-gateway-plugin/lib/jackson-databind-2.22.1.jardevspaces-gateway-plugin/lib/httpcore-4.4.16.jar +5 more
-
LOWpostinstall persistence mechanism 7
devspaces-gateway-plugin/lib/client-java-api-24.0.0.jardevspaces-gateway-plugin/lib/grpc-api-1.70.0.jardevspaces-gateway-plugin/lib/client-java-proto-24.0.0.jar +4 more
-

Publisher Evidence

Low

Red-Hat

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

86
Noisy-finding weight
x1.00
Publisher domain
redhat.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
64
Portfolio

11 evidence rows available.

Finding Categories

YARA Rules Matched

9 rules(143 hits)
postinstall obfuscation postinstall network communication postinstall crypto operations postinstall file manipulation postinstall system command JavaDropper postinstall registry modification postinstall file download postinstall persistence mechanism

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The OpenShift Dev Spaces extension published by Red Hat on the JetBrains marketplace presents no security concerns. All 95 findings are metadata-level hash entries tracking bundled JAR dependencies in the devspaces-gateway-plugin/lib/ directory, including standard Java libraries such as swagger-annotations-1.6.16.jar, netty-handler-4.1.126.Final.jar, grpc-context-1.70.0.jar, and httpcore-4.4.16.jar. There are zero findings in critical, high, medium, or low severity categories.

No malware signatures were detected. The findings summary shows zero results for ioc, malware-signature, malware, network, obfuscation, dependency, secret, code-smell, and tool-poisoning categories. This means the extension contains no suspicious network destinations, no credential-access patterns targeting .env files or cloud credentials, no obfuscated code, and no supply chain indicators.

The filesystem and process access is justified by the extension's stated purpose as a Dev Spaces gateway plugin. Extensions of this type require bundled dependencies to communicate with OpenShift clusters and provide development environment functionality. The presence of networking libraries like netty-handler-4.1.126.Final.jar and http-auth-aws-2.33.13.jar in the devspaces-gateway-plugin/lib/ directory is expected behavior for a cloud development tool, not evidence of exfiltration or unauthorized communication.

No credential-access findings target actual secrets. The secret category shows zero findings, meaning the analyzer detected no patterns matching .env files, SSH keys, cloud credentials, or VS Code secret storage access. The http-auth-aws-2.33.13.jar dependency is a standard AWS authentication library, not evidence of credential theft.

The strongest counterargument to this verdict is the high finding count of 95, which might suggest widespread issues. However, this is entirely explained by the presence of bundled JAR dependencies, which is normal for Java-based IDE extensions. Each bundled library generates its own metadata hash finding, creating multiplicative counts without security implications. This pattern is documented as expected behavior in the CVEQ threat model.

Red Hat is a verified enterprise software publisher with established security practices. The extension has 4,583 users on the JetBrains marketplace, indicating moderate adoption and community trust. The combination of a reputable publisher, zero security-relevant findings, and findings limited to bundled dependency metadata confirms this is a legitimate development tool with no malicious indicators.

Key Reasons

  • Zero findings in all security-relevant categories
  • All 95 findings are metadata hashes of bundled JAR dependencies
  • Publisher is verified enterprise vendor (Red Hat)
  • No credential access, malware signatures, or suspicious network activity
  • Findings pattern matches expected bundled dependency behavior

False Positive Considerations

  • Bundled JAR dependencies generating metadata hash findings
  • All findings are severity info with zero critical/high/medium/low
  • Zero findings in security-relevant categories (ioc, malware, secret, network)
  • Verified publisher (Red Hat) on legitimate marketplace (JetBrains)

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.

JetBrains version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
36
Change since first
+15
Change from previous
No change
Versions:
First analyzed version
0.0.15
Apr 5, 2026
Risk range
21 to 36
Across analyzed versions
Latest analyzed version
0.0.19
Aug 13, 2026
Selected version
low
Version
v0.0.19
1 months ago
Risk score
36
Findings
215
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Plugin for JetBrains Gateway enables local desktop development experience with the IntelliJ IDEs connected to OpenShift Dev Spaces.

Frequently Asked Questions