{
  "schema": "odyssey-scans-v1",
  "generated": "2026-08-15T18:58:00Z",
  "packages": {
    "sniffnet": {
      "version": "1.5.1_1",
      "state": "passed",
      "scanned": "2026-08-03T20:36:40Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "brave": {
      "version": "1.93.129_1",
      "state": "passed",
      "scanned": "2026-08-03T20:40:32Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "dbeaver": {
      "version": "26.1.4_1",
      "state": "cleared",
      "scanned": "2026-08-03T21:07:15Z",
      "flagged_at": "2026-08-03T21:06:29Z",
      "note": "The single high-severity flag is java_credential_exfil_combo on org/eclipse/swt/browser/WebKit.class, inside the bundled Eclipse SWT library. This is a known co-occurrence false positive: that class contains getenv, an openConnection call and a URL string in the same class, which the rule flags together — but it is Eclipse's standard SWT WebKit browser binding, not credential exfiltration. diff_new_yara is empty: the class is unchanged from the previous version, and all new files in this build are the normal DBeaver 26.1.4 version bump (renamed driver .jar plugins, Eclipse features, p2 profiles). The 110 warnings are the usual noise from DBeaver's many bundled JDBC driver jars, none high-severity. Confirmed false positive.",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "odyssey-labwc": {
      "version": "1.0_51",
      "state": "passed",
      "scanned": "2026-08-04T20:12:14Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "zen-browser": {
      "version": "1.21.10b_1",
      "state": "cleared",
      "scanned": "2026-08-03T18:21:19Z",
      "flagged_at": "2026-08-03T18:21:01Z",
      "note": "The ssh_key_access rule matched a single ASCII occurrence of \"id_rsa\" inside omni.ja (the browser's packaged JavaScript). It appears in a source-code comment in the Firefox/Zen devtools heap-snapshot code stating that the Remote Debugging Protocol must only open snapshot files and NOT files like ~/.ssh/id_rsa. The match is a comment describing a security boundary, not code that reads SSH keys. No other credential patterns present. Confirmed false positive.",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "bitwarden": {
      "version": "2026.7.0_1",
      "state": "passed",
      "scanned": "2026-08-03T21:13:27Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "cryptomator": {
      "version": "1.19.3_1",
      "state": "passed",
      "scanned": "2026-06-30T18:11:26Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "odyssey-controlcenter": {
      "version": "1.2_85",
      "state": "passed",
      "scanned": "2026-08-14T15:41:42Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "ollama": {
      "version": "0.32.5_1",
      "state": "cleared",
      "scanned": "2026-08-03T20:53:43Z",
      "flagged_at": "2026-08-03T20:52:51Z",
      "note": "The ssh_key_access and system_secret_access rules matched a cluster of strings inside the ollama Go binary: id_rsa, id_ed25519, .ssh/config, .aws/config, /etc/passwd, /etc/shadow, secrets.yml — appearing together with curl/wget command examples and tool-calling markers. On inspection this is ollama's tool-use security deny-list: sensitive paths ollama's filesystem tool refuses to let a model read, preventing a prompt-injected model from exfiltrating credentials. Defensive code, the opposite of credential access. Matches the documented ollama tool-use hardening pattern. No new YARA hits in this version's diff versus the previous verified build. Confirmed false positive. Upstream ollama 0.32.5, checksum-pinned in the build recipe.",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "solaar": {
      "version": "1.1.20_3",
      "state": "passed",
      "scanned": "2026-07-01T13:22:52Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "aquamarine": {
      "version": "0.12.1_1",
      "state": "passed",
      "scanned": "2026-07-01T13:46:02Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "glaze": {
      "version": "7.9.0_1",
      "state": "passed",
      "scanned": "2026-07-11T18:30:51Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "lua55": {
      "version": "5.5.0_2",
      "state": "passed",
      "scanned": "2026-07-01T14:29:29Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "hyprland": {
      "version": "0.55.4_5",
      "state": "passed",
      "scanned": "2026-07-18T10:37:24Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "odyssey-hyprland": {
      "version": "1.0_44",
      "state": "passed",
      "scanned": "2026-08-04T20:11:20Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "odyssey-mango": {
      "version": "1.0_23",
      "state": "passed",
      "scanned": "2026-08-04T20:13:00Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "zed": {
      "version": "1.13.2_1",
      "state": "cleared",
      "scanned": "2026-08-03T21:03:45Z",
      "flagged_at": "2026-08-03T21:03:20Z",
      "note": "The ssh_key_access rule matched the strings \"id_rsa\" (once) and \".ssh/\" (twice) inside the zed-editor Rust binary. On inspection: \"id_rsa\" appears in a configuration-example comment showing how to set up an SSH remote connection (\"args\": [\"-i\", \"/home/user/.ssh/id_rsa\"]), and \".ssh/\" appears in a comment describing the option to read ~/.ssh/config as a source of SSH connection hosts. These are part of zed's remote-development feature (opening projects on remote servers over SSH, like VS Code Remote-SSH), which uses the user's own SSH keys to connect to the user's own servers — the same way the ssh command does. They are configuration examples and comments, not code that reads or exfiltrates keys. No credential-exfiltration path is present. Confirmed false positive. Binary is the upstream zed 1.13.2 release, checksum-pinned in the build recipe.",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "calamares": {
      "version": "3.3.14_21",
      "state": "cleared",
      "scanned": "2026-08-03T06:32:39Z",
      "flagged_at": "2026-08-03T06:32:23Z",
      "note": "Checked manually : false positive!",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "odyssey-niri": {
      "version": "1.0_44",
      "state": "passed",
      "scanned": "2026-08-14T15:34:28Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "odyssey-welcome": {
      "version": "1.0_28",
      "state": "passed",
      "scanned": "2026-08-11T17:34:37Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "noctalia-qs": {
      "version": "0.0.12_7",
      "state": "passed",
      "scanned": "2026-07-29T08:55:24Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "rustdesk": {
      "version": "1.4.9_1",
      "state": "passed",
      "scanned": "2026-07-09T18:49:28Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "vscodium": {
      "version": "1.126.04524_1",
      "state": "cleared",
      "scanned": "2026-07-09T19:09:46Z",
      "flagged_at": "2026-07-09T19:06:42Z",
      "note": "The ssh_key_access rule matched in three files of VSCodium's Remote-SSH support. In terminalSuggestMain.js it reads $HOME/.ssh/known_hosts to extract hostnames and offer them as autocompletion entries when the user types ssh in the integrated terminal — local completion, no network. In sharedProcessMain.js the matches are a static list of default key paths (_defaultKeyPaths = [\"~/.ssh/id_ed25519\", \"~/.ssh/id_rsa\", \"~/.ssh/id_ecdsa\", \"~/.ssh/id_dsa\", \"~/.ssh/id_xmss\"]) with a helper that expands the tilde — the same default paths the ssh command itself uses. In sessions.desktop.main.js \"~/.ssh/id_rsa\" is the placeHolder text of an input dialog asking the user which key file to use for a remote connection. All three are part of VS Code's documented Remote-SSH feature, which uses the user's own keys to connect to the user's own servers. No code path reads a key and sends it anywhere. Confirmed false positive.",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "protonplus": {
      "version": "0.5.22_1",
      "state": "passed",
      "scanned": "2026-07-31T06:32:41Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "labwc-odyssey": {
      "version": "0.20.1_11",
      "state": "passed",
      "scanned": "2026-08-14T15:42:41Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "noctalia-shell": {
      "version": "4.7.7_6",
      "state": "passed",
      "scanned": "2026-08-04T13:26:44Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "odyssey-guinit": {
      "version": "1.1_8",
      "state": "cleared",
      "scanned": "2026-08-04T15:48:43Z",
      "flagged_at": "2026-08-04T15:42:44Z",
      "note": "This is a matter of method, so I will say it plainly: the scanner runs\nagainst my own applications too, and this time it stopped one of them.\nThere is no fast lane for packages I wrote myself. Here is the finding\nand why it does not pass the gate on its own. \nWhat tripped it: the new user manager in guinit ships a knowledge base\nthat explains what each system group grants. To warn people that the\ndisk group is root-equivalent, the text names /etc/shadow and debugfs.\nTo describe kmem, it names /dev/mem and /dev/port. Those are quoted\nEnglish sentences shown in a dialog, not calls. The only real command\nis chpasswd, and the password goes to it on standard input so it never\nshows up in ps.",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "odyssey-browser-ram": {
      "version": "1.0.0_5",
      "state": "passed",
      "scanned": "2026-07-29T05:39:39Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "odyssey-xbps-gui": {
      "version": "1.0_26",
      "state": "passed",
      "scanned": "2026-08-05T14:01:06Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "hyprshot": {
      "version": "1.3.0_2",
      "state": "passed",
      "scanned": "2026-07-17T21:58:06Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "odyssey-portal-config": {
      "version": "1.0_2",
      "state": "passed",
      "scanned": "2026-07-17T21:58:36Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "bottles": {
      "version": "66.6_1",
      "state": "passed",
      "scanned": "2026-08-15T10:00:19Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "odyssey-kitty": {
      "version": "1.0_17",
      "state": "passed",
      "scanned": "2026-08-13T16:21:58Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "anytype": {
      "version": "0.56.1_1",
      "state": "cleared",
      "scanned": "2026-07-29T10:56:56Z",
      "flagged_at": "2026-07-29T10:56:12Z",
      "note": "same high (ssh_key_access in upstream asar) as published _2, diff vs _2 empty: no new files/urls/yara. Only change: .desktop forced to ozone x11 (ODY-164/165)",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "xdg-user-dirs": {
      "version": "0.20_3",
      "state": "passed",
      "scanned": "2026-08-02T17:07:15Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "vkbasalt-cli": {
      "version": "3.1.1.post2_2",
      "state": "passed",
      "scanned": "2026-07-20T18:44:00Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "odyssey-pkg": {
      "version": "1.0_29",
      "state": "passed",
      "scanned": "2026-08-06T07:59:01Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "appflowy": {
      "version": "0.13.0_1",
      "state": "cleared",
      "scanned": "2026-07-25T10:56:55Z",
      "flagged_at": "2026-07-25T10:53:19Z",
      "note": "The ssh_key_access rule matched inside libdart_ffi.so, AppFlowy's Rust core library. On inspection: \"known_hosts\", \"known_hosts.old\", \"authorized_keys\" and \"authorized_keys2\" are the standard default filenames an embedded SSH client library looks for (used for Git-over-SSH operations, common in apps with sync/collaboration features) — not code reading the user's actual key files. The apparent \"id_rsa\" matches are a text collision: they are fragments of OpenSSL cryptographic constant names (ossl_der_oid_id_rsassa_pkcs1_v1_5_with_sha3_*, rsaEncryption) — RSA signature-scheme identifiers, unrelated to any ~/.ssh/id_rsa file. diff_new_yara is empty: nothing changed versus the previous verified build. Confirmed false positive.",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "hyprgraphics": {
      "version": "0.5.1_6",
      "state": "passed",
      "scanned": "2026-07-29T07:32:28Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "hyprland-qt-support": {
      "version": "0.1.0_5",
      "state": "passed",
      "scanned": "2026-07-29T08:21:43Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "hyprland-qtutils": {
      "version": "0.1.5_2",
      "state": "passed",
      "scanned": "2026-07-29T08:23:48Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "obsidian": {
      "version": "1.13.4_1",
      "state": "passed",
      "scanned": "2026-08-03T20:34:45Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "norisk-client": {
      "version": "0.6.24_1",
      "state": "passed",
      "scanned": "2026-08-04T14:39:31Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "openrazer-meta": {
      "version": "3.12.4_2",
      "state": "passed",
      "scanned": "2026-08-05T09:42:53Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "facetimehd-dkms": {
      "version": "0.7.0.1_5",
      "state": "passed",
      "scanned": "2026-08-05T19:41:33Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "facetimehd-firmware": {
      "version": "1.0.0_2",
      "state": "passed",
      "scanned": "2026-08-05T19:48:06Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "odyssey-base-config": {
      "version": "1.0_5",
      "state": "passed",
      "scanned": "2026-08-15T18:58:00Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "peazip-bin": {
      "version": "11.2.0_1",
      "state": "passed",
      "scanned": "2026-08-07T17:16:52Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "fvs2": {
      "version": "0.1.5_2",
      "state": "passed",
      "scanned": "2026-08-13T10:00:08Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "font-alias": {
      "version": "1.0.6_1",
      "state": "passed",
      "scanned": "2026-08-13T15:48:06Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "font-util": {
      "version": "1.4.2_1",
      "state": "passed",
      "scanned": "2026-08-13T15:48:15Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "font-hack-ttf": {
      "version": "3.003_3",
      "state": "passed",
      "scanned": "2026-08-13T15:48:22Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "font-awesome": {
      "version": "4.7.0_3",
      "state": "passed",
      "scanned": "2026-08-13T15:48:34Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "iso-codes": {
      "version": "4.20.1_1",
      "state": "passed",
      "scanned": "2026-08-13T15:48:42Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "aha": {
      "version": "0.5.1_5",
      "state": "passed",
      "scanned": "2026-08-14T07:18:49Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "niri-odyssey": {
      "version": "26.04_6",
      "state": "passed",
      "scanned": "2026-08-14T15:40:37Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "kitty": {
      "version": "0.48.2_1",
      "state": "cleared",
      "scanned": "2026-08-14T16:39:13Z",
      "flagged_at": "2026-08-14T16:19:31Z",
      "note": "False positive. /usr/lib/kitty/kittens/remote_file/main.py:114 builds an ssh command with ControlPath=~/.ssh/kitty-rf-<pid>-%C, a connection multiplexing socket. The remote_file kitten exists to open files on remote hosts over ssh, so referencing ~/.ssh is its documented purpose, not credential access.",
      "statement": "This package was flagged by Odyssey's automated safety scan and cleared by hand after review. The reason is recorded below, so you can disagree with it."
    },
    "raptor": {
      "version": "2.0.16_2",
      "state": "passed",
      "scanned": "2026-08-14T16:31:14Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "run-parts": {
      "version": "5.23.2_1",
      "state": "passed",
      "scanned": "2026-08-14T16:31:22Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "serd": {
      "version": "0.32.10_1",
      "state": "passed",
      "scanned": "2026-08-14T16:31:31Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "spice-vdagent": {
      "version": "0.23.0_1",
      "state": "passed",
      "scanned": "2026-08-14T16:31:39Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "void-artwork": {
      "version": "20221013_1",
      "state": "passed",
      "scanned": "2026-08-14T16:31:48Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "xkeyboard-config": {
      "version": "2.48_1",
      "state": "passed",
      "scanned": "2026-08-14T16:31:57Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    },
    "plan9port": {
      "version": "20250405_1",
      "state": "cleared",
      "scanned": "2026-08-14T16:35:09Z",
      "flagged_at": "2026-08-14T16:35:09Z",
      "note": "False positive. The hits are documentation and source, not behaviour: /usr/lib/plan9/man/man1/rsa.1 and ssh-agent.1 are manual pages, lookman.index is the manual index built from them, and /usr/lib/plan9/src/libsec/port/x509.c with the libsec.a it compiles into is Plan 9's own crypto library. Plan9port ships the complete Plan 9 userland, so a crypto implementation and its documentation are expected.",
      "statement": "This package was flagged by Odyssey's automated safety scan and cleared by hand after review. The reason is recorded below, so you can disagree with it."
    },
    "iceauth": {
      "version": "1.0.11_2",
      "state": "passed",
      "scanned": "2026-08-14T17:59:37Z",
      "statement": "This package passed Odyssey's automated safety scan: no malicious patterns detected (miners, credential theft, reverse shells, backdoors). Scanning raises the bar — it is not a guarantee."
    }
  }
}
