Spectra Assure
Community
Docs
warningRisk: Secrets
Scanned: 5 days ago

@msgpackr-extract/msgpackr-extract-linux-arm64

latest
Top 10k
Platform specific binary for msgpackr-extract on linux OS with arm64 architecture
License: Permissive (MIT)
Published: over 1 year ago



SAFE Assessment

Compliance

Licenses
No license compliance issues
Secrets
2 debugging symbols found

Security

Vulnerabilities
No known vulnerabilities detected
Hardening
No application hardening issues

Threats

Tampering
No evidence of software tampering
Malware
No evidence of malware inclusion

Popularity

91.83M
Recorded Downloads Since 2021
Contributor
Declared Dependencies
4
Dependents

Top issues

Problem

Common compilers often embed source code information into executables for debugging purposes, usually by mapping symbols to source filenames or paths. While this is typically desirable in open-source software and standard tools, that information can be used to determine security weaknesses, code repository layout, trade secrets and similar sensitive information. Such symbols make it easier to reverse-engineer a closed source application.

Prevalence in npm community

0 packages
found in
Top 100
1 packages
found in
Top 1k
115 packages
found in
Top 10k
13394 packages
in community

Next steps

Strip out such information in the linking phase by using compiler options like the -s flag in GCC, or in the post-build phase by using the strip tool.

Top behaviors

Prevalence in npm community

No behavior prevalence information at this time

Prevalence in npm community

No behavior prevalence information at this time

Top vulnerabilities

No vulnerabilities found.