Top issues
Detected Windows executable files that embed PDB files whose integrity is verified with an insecure hashing algorithm.
Causes risk: outdated toolchains detected
hardening
Problem
Program database (PDB) files are typically only used during software development. They contain private debug symbols that make it significantly easier to reverse engineer a closed-source application. In some cases, having a program database file is equivalent to having access to the source code. Presence of program databases could indicate that one or more software components have been built using a debug profile, instead of the release.Prevalence in NuGet community
0 packages
found in 
Top 100
 14 packages
found in 
Top 1k
 69 packages
found in 
Top 10k
 19607 packages
in community
Next steps
Private debug database files should not be embedded within executables, and you should remove them from the software package before releasing it.
The integrity verification of the embedded database files should not be done with insecure hashing algorithms. SHA1 and MD5 hashes should be deprecated throughout the application, and a more secure SHA256 algorithm should be used instead.
Detected digital signatures that rely on a weak digest algorithm for integrity validation.
signatures
Problem
Digital signatures are applied to applications, packages and documents as a cryptographically secured authenticity record. Signatures verify the origin and the integrity of the object they apply to. The integrity validation relies on the cryptographic strength of the encryption and the hash verification algorithm. If either of the two is considered weak by current standards, there is a chance the signed object could be maliciously modified, without triggering the integrity failure check.Prevalence in NuGet community
0 packages
found in 
Top 100
 38 packages
found in 
Top 1k
 315 packages
found in 
Top 10k
 733240 packages
in community
Next steps
Create signatures with strong ECC key-length of at least 224 bits, or RSA key-length of at least 2048 bits, and use SHA256 as the hashing algorithm. While encryption key-length upgrade does require you to obtain a new certificate, the hashing algorithm can freely be selected during signing.
With Microsoft SignTool, you can specify the hashing algorithm using the /fd SHA256 parameter.
Problem
Debug databases are typically only used during software development. On Windows, they are usually files embedded into the executable (PDB), while on Linux, they're contained inside special executable sections. The databases contain private debug symbols that make it significantly easier to reverse-engineer a closed-source application. In some cases, having a debug database is equivalent to having access to the source code. Presence of debug databases could indicate that one or more software components have been built using a debug profile, instead of the release. Private debug databases can be embedded into software components by programming language tools.Prevalence in NuGet community
0 packages
found in 
Top 100
 15 packages
found in 
Top 1k
 76 packages
found in 
Top 10k
 21579 packages
in community
Next steps
To remediate this issue and remove private debugging information, refer to your programming language toolchain documentation.
Top behaviors
Contains IP addresses.
network
Prevalence in NuGet community
Behavior often found in this community (Common)
0 packages
found in 
Top 100
 59 packages
found in 
Top 1k
 458 packages
found in 
Top 10k
 532614 packages
in community
Contains URLs.
network
Prevalence in NuGet community
Behavior often found in this community (Common)
0 packages
found in 
Top 100
 63 packages
found in 
Top 1k
 513 packages
found in 
Top 10k
 735907 packages
in community
Contains URLs related to release pages of projects hosted on GitHub.
network
Prevalence in NuGet community
Behavior often found in this community (Common)
0 packages
found in 
Top 100
 7 packages
found in 
Top 1k
 49 packages
found in 
Top 10k
 14642 packages
in community
Contains patterns identifying the constants related to the SHA-256 hash function, from the SHA-2 hash family.
signature
Prevalence in NuGet community
Behavior often found in this community (Common)
0 packages
found in 
Top 100
 63 packages
found in 
Top 1k
 513 packages
found in 
Top 10k
 735870 packages
in community
Top vulnerabilities
No vulnerabilities found.