JetBrains Marketplace Verified

GitHub Copilot modernization

by Microsoft · 155.0K users
9a7b1880-6a96-533d-b909-431d95ea323a | v1.14.0
50/ 100
MEDIUM risk
No change since v1.13.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
3 days ago
Version
v1.14.0
Artifact
SHA256 0DF…640
Source
Findings (non-IoC)

Is GitHub Copilot modernization safe?

This is the official GitHub Copilot modernization plugin for JetBrains IDEs, published by Microsoft with over 155,000 installs. The scanner flagged thousands of IOC matches, but every one comes from the extractor misreading strings inside the extension's own files, things like pom.properties (a Maven build file), liftoff-compiler.cc and v8-inspector-impl.cc (V8 engine source names), and random hex fragments that look like domains but aren't. The network_endpoints list shows the same garbage: 2-.io, 2ȟ6.ga, 3ʵj.nr and dozens more are not real connections, just minified code fragments the extractor misunderstood. The 258 code-smell findings are the standard noise from YARA rules running on bundled JavaScript. No findings show this extension stealing credentials, running postinstall scripts, or phoning home. It needs read-write access to your code to work, that's the job, and the publisher, user base, and finding patterns all line up with a legitimate Microsoft tool.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

38 detail rows
Showing 25 of 38 · highest severity first

Publisher Evidence

High

Microsoft

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x0.50
Publisher domain
microsoft.com
Trusted match
Store verification signal
Verified publisher
Verified
Extension portfolio
653
Portfolio

11 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This extension is the official GitHub Copilot modernization plugin for JetBrains IDEs, published by Microsoft with 155,025 users. The scanner produced 3,148 IOC findings and 258 code-smell findings, but zero malware signatures, zero actual malware detections, zero network behavior findings, and zero credential access findings. Every IOC finding comes from the extractor matching strings inside the extension's bundled files — file_path shows "extracted_from_files" for all of them. The matched strings are build artifacts and engine source names: pom.properties (Maven build metadata), liftoff-compiler.cc, v8-inspector-impl.cc, builtins-internal.cc, parserstates.read, date.cc, active-system-pages.cc (all V8/Chrome engine source files), kronecker.tab (math library), plus garbage domains like ﻚ.aq, 6g.td, zaty.cx that are clearly hex fragments or minified-code noise. The network_endpoints list shows the same pattern — 2-.io, 2fwww.in, 2ȟ6.ga, 3ʵj.nr and dozens more are extractor false positives, not real connections. The 258 code-smell findings are the expected YARA noise on minified JavaScript bundles; they carry severity low and finding_type code-smell, which the platform documents as non-actionable. No findings show postinstall scripts, credential reads (.env, .ssh, secret storage), or exfiltration behavior. The extension declares no permissions or host_permissions in this bundle, but as a Copilot integration it legitimately needs read_write workspace access to edit code — that capability matches its stated purpose. The strongest counterargument would be the raw finding count (3,444 total), but the breakdown shows every high-volume category is a documented false-positive source: IOC extractor on build artifacts and minified code, plus code-smell rules on bundled dependencies. Nothing in the actual findings indicates malicious behavior.

Key Reasons

  • Verified Microsoft publisher with 155k+ users on JetBrains marketplace
  • Zero malware signatures, zero malware detections, zero credential findings
  • All 3,148 IOC findings are extractor false positives on build artifacts and source filenames
  • All 258 code-smell findings are documented noise on minified JavaScript bundles
  • Network endpoints list shows same extractor garbage domains from minified code

False Positive Considerations

  • IOC extractor matching build artifacts (pom.properties) and V8 engine source filenames
  • IOC extractor matching hex fragments and minified code strings as domains
  • Code-smell YARA rules firing on bundled/minified JavaScript
  • Network endpoint extractor producing garbage domains from minified code

Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 95%.

JetBrains version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
50
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.13.0
Aug 26, 2026
Risk range
50 to 50
Across analyzed versions
Latest analyzed version
1.14.0
Sep 21, 2026
Selected version
medium
Version
v1.14.0
1 weeks ago
Risk score
50
Findings
3444
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

What is GitHub Copilot modernization?GitHub Copilot modernization is an AI assistant that helps you modernize your app faster, with a streamlined end-to-end migration...

Frequently Asked Questions