{
  "ml": {
    "v": "7",
    "id": 4835,
    "lvl": -1,
    "conf": 0,
    "prob": 0.00002664327621459961,
    "type": "gz",
    "version": "v18.18",
    "analyzed_at": "2026-09-17T12:37:57Z"
  },
  "path": "freebsd-vm@v1.5.6",
  "raw": {
    "rev": "e86a6",
    "files": [
      {
        "id": 4835,
        "mol": "MdTh",
        "pid": 92,
        "rel": "fetched",
        "sha": "f31571b77bb9114540e1dba67674cacec9e6b8ba9059e1de84c810e569f4929d",
        "via": "https://codeload.github.com/vmactions/freebsd-vm/tar.gz/v1.5.6",
        "path": "pkg:github/vmactions/freebsd-vm@v1.5.6",
        "risk": 4,
        "size": 4584799,
        "type": "gz",
        "depth": 2,
        "facts": {
          "metrics": {
            "file": {
              "size": 4584799,
              "entropy": 8
            },
            "binary": {
              "peak_region_bytes": 4579679,
              "peak_region_entropy": 7.85
            },
            "consistency": {
              "self_dependency": 0,
              "unused_runtime_deps": 0
            }
          }
        },
        "traits": [
          {
            "id": "metadata/encoded-payload/base64",
            "conf": 0.9,
            "crit": 3,
            "desc": "Encoded content decoded: base64"
          },
          {
            "id": "third_party/SigBase/EXPL/Log4J/CVE/2021/44228/Dec21/Soft",
            "conf": 0.9,
            "crit": 3,
            "desc": "Detects indicators in server logs that indicate an exploitation attempt of CVE-2021-44228"
          },
          {
            "id": "supply-chain/install-hook/prepare",
            "conf": 0.8,
            "crit": 3,
            "desc": "Package has 'prepare' hook that runs during install"
          },
          {
            "id": "supply-chain/missing-author",
            "conf": 0.5,
            "crit": 3,
            "desc": "Package has empty or missing author field"
          }
        ]
      }
    ]
  }
}