Privacy and security
Local by design
Section titled “Local by design”KAEV has no telemetry and does not upload project files. Normal project analysis runs offline and does not install dependencies in the analyzed application. JavaScript and TypeScript source is parsed, never executed.
check, doctor, and workspace are read-only. report, init, and baseline write only when explicitly requested, use exclusive creation, and refuse to overwrite an existing file.
Source and secret handling
Section titled “Source and secret handling”- Findings do not contain raw source snippets.
- Credential evidence uses a fixed redaction marker.
- Known secret representations, bearer tokens, terminal controls, and bidi override characters are removed from reporter text.
- Normal outputs use project-relative paths and omit the analyzed absolute root.
- Machine-readable stdout is kept separate from operational and debug stderr.
- Debug stacks are shown only with
--debugorKAEV_DEBUG=1, sanitize the project root and known credential patterns, and should still be reviewed before sharing.
UI5 Linter isolation
Section titled “UI5 Linter isolation”The pinned official UI5 Linter runs in a separate child process with:
- A generated minimal configuration,
noConfig: true, andfix: false. - An allowlist derived from safely discovered project files.
- Filesystem read permission limited to the installed package, dependencies, and project.
- No filesystem write or child-process permission.
- Network entry points disabled before the analyzer is imported.
- A 512 MiB heap limit and 30-second timeout.
- Restricted environment variables and bounded, source-free external messages.
If the adapter cannot run safely, KAEV marks it unavailable instead of silently treating it as a pass. --no-ui5-lint is an explicit partial-coverage choice.
The Node permission model and offline guard are defense in depth around a trusted, pinned dependency; they are not an operating-system sandbox for arbitrary hostile code. KAEV assumes the repository is not being concurrently replaced by another hostile process.
Filesystem protections
Section titled “Filesystem protections”Source roots and external analyzer paths are validated against the project root. Root-only configuration and baseline filenames reject nested, absolute, drive-qualified, UNC, NUL, and traversal inputs. Discovery excludes symlinks, and report creation rejects symlink parent directories.
Dependency advisories
Section titled “Dependency advisories”KAEV does not run npm audit against analyzed applications. Dependency advisories for KAEV itself and the bundled analyzer are a release-maintenance concern and do not imply that scanned projects were audited.