C++ SCHX ยท rev 4
Publication security ยท reference

Security engine coverage

How to read the difference between built-in analysis, external scanners that completed, scanners that are unavailable and scanners that errored.

referencestatus
Security developers ยท Operatorsaudience
School-GIT docssource
SCHX nativeruntime
SCHX / FEATURE LAYER

Source map

  • lib/cdn/apps/security/app-security-scanner.ts
  • components/cdn/apps/AppSecurityScanReport.tsx
SCHX / FEATURE LAYER

Built-in engines

Built-in scanners are part of the Web Bro security library and do not depend on separately installed antivirus CLIs. When the report says they passed, they actually ran against the submitted package.

SCHX / FEATURE LAYER

Optional external engines

Unavailable means the host tool was not present/configured. Error means the tool was detected and attempted but did not complete successfully. These states should remain visible instead of being represented as a pass.

  • Microsoft Defender Antivirus.
  • ClamAV.
  • YARA-X.
  • Semgrep.
  • Trivy.
  • Google OSV-Scanner.
  • VirusTotal hash reputation when configured.
SCHX / FEATURE LAYER

Correct wording

A clean report should be interpreted as โ€œno threats found by the engines that ran,โ€ not โ€œevery possible security engine passed.โ€ The UI should show external coverage separately from built-in static coverage.

SCHX / FEATURE LAYER

Related documentation