OpenVSX Registry Verified

GitHub Pull Requests

by GitHub
e037bb88-2fa2-577b-8803-3be932456fd8 | v0.166.1
42/ 100
MEDIUM risk
-28 since v0.166.0
69 → 42 · false positives removed
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (42/100) still counts them.

Analysis record

Analysed
1 weeks ago
Version
v0.166.1
Artifact
SHA256 898…249
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

111 detail rows
Showing 25 of 31 · highest severity first

YARA Rule Matches

13 rules
SeverityRuleHitsFilesMetadata
LOWDebuggerStatementsShouldNotBeUsed 1
eslint.config.mjs
-
LOWNoUseWeakRandom 5
dist/webview-pr-description.jsdist/browser/extension.jsdist/extension.js +2 more
-
LOWpostinstall file download 13
eslint.config.mjspackage.jsonpackage.nls.json +10 more
-
LOWcredential git credentials 1
changelog.md
-
LOWSQLInjection 2
dist/webview-open-pr-view.jsdist/webview-pr-description.js
-
LOWpostinstall crypto operations 10
dist/webview-create-pr-view-new.jsresources/emojis.jsondist/webview-open-pr-view.js +7 more
-
LOWpostinstall file manipulation 10
dist/webview-create-pr-view-new.jspackage.nls.jsondist/webview-pr-description.js +7 more
-
LOWpostinstall system command 12
dist/webview-pr-description.jsdist/webview-create-pr-view-new.jspackage.nls.json +9 more
-
LOWpostinstall registry modification 2
dist/browser/extension.jsdist/extension.js
-
LOWpostinstall obfuscation 9
dist/webview-create-pr-view-new.jsdist/webview-pr-description.jsdist/webview-open-pr-view.js +6 more
-
LOWpostinstall network communication 8
LICENSE.txtchangelog.mdpackage.json +5 more
-
LOWcredential env files 2
dist/browser/extension.jsdist/extension.js
-
LOWpostinstall persistence mechanism 5
dist/browser/extension.jsdist/extension.jschangelog.md +2 more
-

Publisher Evidence

Low

GitHub

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

65
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
539
Portfolio

12 evidence rows available.

Finding Categories

YARA Rules Matched

13 rules(80 hits)
DebuggerStatementsShouldNotBeUsed NoUseWeakRandom postinstall file download credential git credentials SQLInjection postinstall crypto operations postinstall file manipulation postinstall system command postinstall registry modification postinstall obfuscation postinstall network communication credential env files postinstall persistence mechanism

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The GitHub Pull Requests extension (version 0.144.0) is published by GitHub itself and has over 5.7 million users, indicating it is a legitimate, widely-trusted development tool. The extension's stated purpose is to provide Pull Request and Issue integration for GitHub repositories within the IDE environment.

Filesystem and Process Access Justification

The evidence bundle contains no findings related to filesystem access, process execution, or network behavior. All 29 findings in this bundle are dependency declarations extracted from the package.json file located at /tmp/extract-c9358907d2d3a3a70989e264b362a66b8b4f31f718115902dec2a513ec64c372-3331917101/extension/package.json. These dependencies include legitimate libraries such as @octokit/[email protected] (GitHub's official REST API client), @vscode/codicons@^0.0.36 (VS Code icon library), and marked@^4.0.10 (Markdown parser). These are standard dependencies for a GitHub integration extension and do not indicate any suspicious behavior. A pull request extension legitimately needs to read workspace files to display code changes, diff information, and related files from the repository.

Credential Access Findings

The findings summary explicitly shows zero findings in the secret category ("secret":"0"). There are no credential-access findings in this bundle. The extension does not have any findings that target .env files, .ssh directories, cloud credentials, or VS Code's secret storage. The dependency @octokit/rest is used for authenticating with GitHub's API through GitHub's official authentication mechanisms, which is expected behavior for this extension.

Strongest Counterargument

The strongest counterargument to this verdict is the presence of 29 findings in the bundle. However, all 29 findings are classified as dependency type with severity: low, and the findings summary confirms there are zero findings in categories that matter for security: "ioc":"0","malware-signature":"0","malware":"0","obfuscation":"0","code-smell":"0","tool-poisoning":"0". Dependency declarations in package.json are normal for any Node.js-based extension and do not constitute security concerns. The extension is published by GitHub (verified publisher), has millions of users, and contains no actual security findings beyond standard npm dependency listings.

This extension represents expected IDE behavior with no malicious indicators.

Key Reasons

  • All 29 findings are low-severity dependency declarations, not security issues
  • Zero findings in malware, IoC, obfuscation, secret, or code-smell categories
  • Extension published by verified GitHub publisher with 5.7M+ users
  • Dependencies like @octokit/rest are legitimate for GitHub PR integration

False Positive Considerations

  • Dependency findings from package.json are normal for Node.js extensions
  • No actual security findings beyond standard npm declarations
  • High finding count is noise from bundled dependencies

Reviewed 2026-05-23; recommended action: no action; model confidence 95%.

Open VSX version history

Risk trend by version

16 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
42
Change since first
-34
Change from previous
-28
Versions:
First analyzed version
0.132.1
Mar 22, 2026
Risk range
42 to 76
Across analyzed versions
Latest analyzed version
0.166.1
Sep 19, 2026
Selected version
medium
Version
v0.166.1
1 weeks ago
Risk score
42
Findings
111
Change vs previous
-28

Pick any point on the chart to explore that version's code below.

About This Extension

Pull Request and Issue Provider for GitHub

Frequently Asked Questions