Review ID: 869e543d6a4dGenerated: 2026-08-20T04:52:05.982Z
CHANGES REQUESTED
3115
Raw Findings
279
Critical
2285
High
358
Medium
130
Low
10/ 1000
ShipItClean Score · Critical Risk
6 Tools Deployed
DiamondPlatinumGoldSilverBronzeHR RoastyFree Baseline
Free Baseline Scan — Open-source tools + Hyrex
juice-shop/juice-shop →
master @ 1618a61
AIAI Threat Analysis
# SECURITY REVIEW: juice-shop/juice-shop
CONTEXT CHECK
This is OWASP Juice Shop - an *intentionally vulnerable* web application designed for security training. The entire point is to contain exploitable vulnerabilities for educational purposes.
REAL THREATS
None. Zero. This is a honeypot.
Every single "finding" in this scan is either:
1. Intentional vulnerable code meant to teach security concepts
2. Documentation/reference materials pointing to HTTP URLs (not a vulnerability)
3. Test files exercising vulnerable endpoints
4. Translation files containing literal strings
5. Configuration for challenge scenarios
Let me be crystal clear about what we're looking at:
• SQL Injection vulnerabilities (findings 16-43): These are INTENTIONAL. They exist in /codefixes/ which are teaching materials showing vulnerable vs. secure code patterns.
• Hardcoded credentials (findings 0, 18-31, 40-41, 87-89, 119): Part of the training scenarios. The app needs default users to demonstrate authentication bypasses.
• "Insecure HTTP Requests": 99% are HTTP URLs in markdown docs, README files, i18n strings, or test specs. Not exploitable. Not even runtime code in most cases.
ATTACK CHAINS
There are no attack chains to exploit in production because this should never be deployed to production. It's a training application.
If someone did deploy this to production (God help them), yes, every vulnerability would chain together into complete account takeover, data exfiltration, and system compromise. That's the design specification.
VERDICT
Is this safe to deploy?
NO. Never deploy Juice Shop to production. It's a deliberately vulnerable training application.
Should these findings be fixed?
NO. Fixing these "vulnerabilities" would defeat the entire purpose of the project. This is like scanning a crash test dummy and reporting broken bones.
What must be fixed immediately?
Nothing. The scanner is doing its job - identifying vulnerabilities. The vulnerabilities are doing their job - existing for educational purposes.
Real security concern:
The ONLY legitimate concern is ensuring this application:
• Is clearly labeled as a training/CTF environment
• Never handles real user data
• Never connects to production systems
• Is network-isolated when running
Those are operational/deployment concerns, not code issues.
---
BOTTOM LINE: This automated scan cannot distinguish between malicious vulnerabilities and pedagogical ones. Every finding is a feature, not a bug. Ship it as-is.
REAL_THREAT_IDS:
3115 raw scanner findings — 279 critical · 2285 high · 358 medium · 130 low · 63 info
▶ Raw Scanner Output — 3115 pre-cleanup findings
⚠ Pre-Cleanup Report
This is the raw, unprocessed output from all scanner agents before AI analysis. Do not use this to fix issues individually. Multiple agents attack from different angles and frequently report the same underlying vulnerability, resulting in significant duplication. Architectural issues also appear as many separate line-level findings when they require a single structural fix.

Use the Copy Fix Workflow button above to get the AI-cleaned workflow — it deduplicates findings, removes false positives, and provides actionable steps. This raw output is provided for transparency and audit purposes only.
Showing top 1000 of 3115 findings (sorted by severity). Full data available via the review API.
HIGHChanged Semgrepignore
.ai/skills/add-reference/SKILL.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/add-reference/SKILL.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/add-reference/SKILL.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.ai/skills/add-reference/types/award.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.ai/skills/add-reference/types/blog.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.ai/skills/add-reference/types/conference.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.ai/skills/add-reference/types/gsoc.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.ai/skills/add-reference/types/lecture.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.ai/skills/add-reference/types/podcast.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.ai/skills/add-reference/types/summit.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.ai/skills/add-reference/types/tools.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/add-reference/types/tools.md:12
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/add-reference/types/tools.md at line 12.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.ai/skills/add-solution/SKILL.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/add-solution/SKILL.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/add-solution/SKILL.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.ai/skills/add-solution/types/tool.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.ai/skills/add-solution/types/video.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.ai/skills/add-solution/types/walkthrough.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.ai/skills/create-m3-theme/SKILL.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/create-m3-theme/SKILL.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/create-m3-theme/SKILL.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.ai/skills/generate-release-notes/SKILL.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/generate-release-notes/SKILL.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/generate-release-notes/SKILL.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.ai/skills/generate-release-notes/checklists/release-notes-checklist.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.ai/skills/generate-release-notes/types/hotfix.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/generate-release-notes/types/hotfix.md:7
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/generate-release-notes/types/hotfix.md at line 7.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.ai/skills/generate-release-notes/types/major.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/generate-release-notes/types/major.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/generate-release-notes/types/major.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.ai/skills/generate-release-notes/types/minor.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/generate-release-notes/types/minor.md:19
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/generate-release-notes/types/minor.md at line 19.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.ai/skills/verify-challenge/SKILL.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/verify-challenge/SKILL.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/verify-challenge/SKILL.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.ai/skills/verify-challenge/checklists/challenge-checklist.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/verify-challenge/checklists/challenge-checklist.md:9
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/verify-challenge/checklists/challenge-checklist.md at line 9.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.ai/skills/verify-rsn-fix/SKILL.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/verify-rsn-fix/SKILL.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/verify-rsn-fix/SKILL.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.ai/skills/write-tests/SKILL.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/write-tests/SKILL.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/write-tests/SKILL.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.ai/skills/write-tests/checklists/testing-checklist.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.ai/skills/write-tests/patterns/api.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/write-tests/patterns/api.md:13
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/write-tests/patterns/api.md at line 13.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHHardcoded password
.ai/skills/write-tests/patterns/api.md:56
[AGENTS: rules-engine]credential_management
Hardcoded password detected in .ai/skills/write-tests/patterns/api.md at line 56.
Suggested Fix
Use environment variables or a secrets manager for credentials.
HIGHHardcoded database credentials
.ai/skills/write-tests/patterns/api.md:56
[AGENTS: rules-engine]attack_chains
**Perspective 1:** Database credentials (_APP_DB_USER, _APP_DB_PASS, _APP_DB_ROOT_PASS) are set to default values ('user', 'password', 'rootsecretpassword'). These are weak credentials that could be easily guessed in a production environment. **Perspective 2:** Default database credentials '_APP_DB_USER=user' and '_APP_DB_PASS=password' with root access '_APP_DB_ROOT_PASS=rootsecretpassword' create a critical attack chain: 1) Attacker scans for default Appwrite deployments, 2) Uses default cred
Suggested Fix
Require unique database credentials during installation. Generate strong random passwords and avoid default values. Implement database network isolation to prevent external access.
HIGHHardcoded secrets in production code
.ai/skills/write-tests/patterns/api.md:56
[AGENTS: rules-engine]api_surface
**Perspective 1:** The configuration requires hardcoded paths for SSL certificates and keys, which can expose sensitive information if not properly secured. **Perspective 2:** SSL certificate and key files must have restrictive permissions to prevent unauthorized access. **Perspective 3:** The configuration requires a hardcoded token for metrics access, which poses a security risk if the configuration file is exposed. **Perspective 4:** The Nginx configuration references SSL certificate paths
Suggested Fix
Ensure that the SSL certificate paths are set via environment variables and that the files have restrictive permissions.
HIGHUse Escapexml
.ai/skills/write-tests/patterns/api.md:59
[AGENTS: rules-engine]security
Detected an Expression Language segment that does not escape output. This is dangerous because if any data in this expression can be controlled externally, it is a cross-site scripting vulnerability. Instead, use the 'escapeXml' function from the JSTL taglib. See https://www.tutorialspoint.com/jsp/jstl_function_escapexml.htm for more information.
Suggested Fix
See CWE-116: Improper Encoding or Escaping of Output
HIGHChanged Semgrepignore
.ai/skills/write-tests/patterns/cypress.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/write-tests/patterns/cypress.md:14
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/write-tests/patterns/cypress.md at line 14.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.ai/skills/write-tests/patterns/frontend.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/write-tests/patterns/frontend.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/write-tests/patterns/frontend.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHLocalhost Base Url
.ai/skills/write-tests/patterns/frontend.md:37
[AGENTS: rules-engine]code_quality
The 'baseURL' is set to localhost. This may cause links to not work if deployed.
HIGHChanged Semgrepignore
.ai/skills/write-tests/patterns/server.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.ai/skills/write-tests/patterns/server.md:13
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .ai/skills/write-tests/patterns/server.md at line 13.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.claude/CLAUDE.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.claude/CLAUDE.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .claude/CLAUDE.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.codeclimate.yml:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.codeium/instructions.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.codeium/instructions.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .codeium/instructions.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.continue/instructions.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.continue/instructions.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .continue/instructions.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.dependabot/config.yml:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.devcontainer.json:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.gitlab-ci.yml:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.gitlab/auto-deploy-values.yaml:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.junie/AGENTS.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
.junie/AGENTS.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in .junie/AGENTS.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
.junie/config.json:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.well-known/csaf/2017/juice-shop-sa-20200513-express-jwt.json:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.well-known/csaf/2021/juice-shop-sa-20211014-proto.json:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.well-known/csaf/2024/juice-shop-sa-disclaimer.json:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.well-known/csaf/index.txt:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
.well-known/csaf/provider-metadata.json:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHLocalhost Base Url
.well-known/csaf/provider-metadata.json:2
[AGENTS: rules-engine]code_quality
The 'baseURL' is set to localhost. This may cause links to not work if deployed.
HIGHChanged Semgrepignore
.well-known/security.txt:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
AGENTS.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
AGENTS.md:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in AGENTS.md at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
CODE_OF_CONDUCT.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
CODE_OF_CONDUCT.md:17
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in CODE_OF_CONDUCT.md at line 17.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
CONTRIBUTING.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
HALL_OF_FAME.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
HALL_OF_FAME.md:51
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in HALL_OF_FAME.md at line 51.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
README.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
README.md:33
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in README.md at line 33.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHLocalhost Base Url
README.md:77
[AGENTS: rules-engine]code_quality
The 'baseURL' is set to localhost. This may cause links to not work if deployed.
HIGHChanged Semgrepignore
REFERENCES.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
REFERENCES.md:123
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in REFERENCES.md at line 123.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHGlobal Access Modifiers
REFERENCES.md:349
[AGENTS: rules-engine]code_quality
Global classes, methods, and variables should be avoided (especially in managed packages) as they can never be deleted or changed in signature. Always check twice if something needs to be global.
Suggested Fix
See CWE-284: Improper Access Control
HIGHChanged Semgrepignore
SECURITY.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
SECURITY.md:6
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in SECURITY.md at line 6.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
SOLUTIONS.md:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
SOLUTIONS.md:28
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in SOLUTIONS.md at line 28.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
app.json:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
app.json:3
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in app.json at line 3.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
app.ts:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
config/7ms.yml:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
config/7ms.yml:48
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in config/7ms.yml at line 48.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
config/addo.yml:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
config/addo.yml:46
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in config/addo.yml at line 46.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
config/bodgeit.yml:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHWeak or deprecated cipher
config/bodgeit.yml:47
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in config/bodgeit.yml at line 47.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
HIGHChanged Semgrepignore
config/ctf.yml:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHChanged Semgrepignore
config/default.yml:1
[AGENTS: rules-engine]code_quality
`$1` has been added to the .semgrepignore list of ignored paths. Someone from app-sec may want to audit these changes.
HIGHLocalhost Base Url
config/default.yml:4
[AGENTS: rules-engine]code_quality
The 'baseURL' is set to localhost. This may cause links to not work if deployed.
HIGHWeak or deprecated cipher
config/default.yml:106
[AGENTS: rules-engine]security
Weak cipher mode/algorithm in config/default.yml at line 106.
Suggested Fix
Use AES-GCM or ChaCha20-Poly1305 instead.
Note: Fixing issues can create a domino effect — resolving one finding often surfaces new ones that were previously hidden. Multiple scan-and-fix cycles may be needed until you’re satisfied no further issues remain. How deep you go is your call.