C++ SCHX ยท rev 4
Publication security ยท current

Web Bro security architecture

Defense-in-depth static analysis, media integrity, scan-context binding and runtime isolation.

currentstatus
Security developers ยท App developers ยท Operatorsaudience
School-GIT docssource
SCHX nativeruntime
SCHX / FEATURE LAYER

System flow

1

Validate package

2

Analyze media

3

Analyze code + behavior

4

Run available external engines

5

Bind report to exact context

6

Commit only on pass

SCHX / FEATURE LAYER

Source map

  • lib/cdn/apps/security/app-security-scanner.ts
  • lib/cdn/apps/security/scan-context.ts
  • lib/cdn/apps/media-security/app-media-analyzer.ts
  • app/api/cdn/apps/security/scan/route.ts
SCHX / FEATURE LAYER

The scanner does not execute submitted application code

Publication analysis is static/structural. It does not run npm install, package lifecycle scripts, app build commands or arbitrary uploaded code.

SCHX / FEATURE LAYER

Built-in analysis

The security report records what engines ran, what they found and whether optional coverage was unavailable or errored.

  • Package/path and file identity validation.
  • Malware behavior heuristics.
  • Secret exposure detection.
  • Behavior correlation.
  • Network intent analysis.
  • Babel AST JavaScript/TypeScript analysis.
  • HTML trust-boundary analysis.
  • Package supply-chain analysis.
SCHX / FEATURE LAYER

Immutable context binding

A security scan is valid only for the exact package/runtime/media context it analyzed. The final commit re-checks the scan identifiers and deterministic context hashes before storing immutable release bytes.

SCHX / FEATURE LAYER

Related documentation