Security engine coverage
How to read the difference between built-in analysis, external scanners that completed, scanners that are unavailable and scanners that errored.
Source map
- lib/cdn/apps/security/app-security-scanner.ts
- components/cdn/apps/AppSecurityScanReport.tsx
Built-in engines
Built-in scanners are part of the Web Bro security library and do not depend on separately installed antivirus CLIs. When the report says they passed, they actually ran against the submitted package.
Optional external engines
Unavailable means the host tool was not present/configured. Error means the tool was detected and attempted but did not complete successfully. These states should remain visible instead of being represented as a pass.
- Microsoft Defender Antivirus.
- ClamAV.
- YARA-X.
- Semgrep.
- Trivy.
- Google OSV-Scanner.
- VirusTotal hash reputation when configured.
Correct wording
A clean report should be interpreted as โno threats found by the engines that ran,โ not โevery possible security engine passed.โ The UI should show external coverage separately from built-in static coverage.