| Author | TrackMe Limited, U.K. |
|---|---|
| Tags | cloud |
| Version | 1.0.7 |
| Hash | a3996b8a26ed50f669a6813a3238374a |
| AppInspect Request ID | 5cb8fd24-a66f-41bc-a499-cd91a7a961dd |
| Run Time | 2026-05-28T07:29:10.891959 |
| Execution Time | 110 |
| Field | Value |
|---|---|
| AppInspect Version | 4.2.1 |
| Name | Version | Is Latest |
|---|---|---|
| dynamic-checks | 1.46.0 | True |
| retire-js | 1.1.3 | True |
| static-checks | 4.2.1 | True |
| Status | Count |
|---|---|
|
Successes
|
113 |
|
Failures
|
0 |
|
Future Failures
|
1 |
|
Errors
|
0 |
|
Warnings
|
10 |
|
Not Applicable
|
123 |
|
Skipped
|
0 |
5Stanza [admin_external:ta_trackme_lookupmonitor_settings] does not define python.required. Option python.required is required for REST handlers with handlertype set to 'python'. Please update your app to be compatible with Python 3.13 and set python.required to '3.13'.
Lodash 4.17.23 and earlier are vulnerable to a prototype pollution bypass in _.unset and _.omit. The fix for CVE-2025-13465 only guards against string key members, so attackers can bypass it by passing array-wrapped path segments to delete properties from built-in prototypes including Object.prototype, Number.prototype, and String.prototype.
Lodash _.template is vulnerable to code injection via unsanitized options.imports key names. Untrusted key names are passed to the Function() constructor sink without validation, and the use of assignInWith (which enumerates inherited properties) also means that pre-existing prototype pollution on Object.prototype can flow into the Function() sink and execute arbitrary code at template compilation time.
228Splunk has begun gathering telemetry on apps submitted to appinspect, that utilize SplunkJS. Please ignore this warning as it has no impact to your Splunk app. Match: splunkjs/mvc
228As of Splunk 6.5, this functionality is deprecated and should be removed in futureapp versions. Match: splunkjs/mvc/headerview.
707 Python files found. Update these Python scripts to be cross-compatible with Python 2 and 3 for Splunk Enterprise 8.0. See https://docs.splunk.com/Documentation/Splunk/latest/Python3Migration/AboutMigration for more information. If you've finished your update, please disregard this message.
15Repeat item name 'TRUNCATE' at line 15 in [source::...trackmelookupsmonitor.log] of props.conf.
35Detected an outdated version of the Splunk SDK for Python (2.1.1). Upgrade to 3.0.0 or later.
3Detected an outdated version of the Splunk SDK for Python (2.1.1). Upgrade to 3.0.0 or later.
347The following line contains subprocess.Popen.communicate usage. Use threading and multiprocessing with discretion.
165The following line contains questionable usage `threading.Thread.start` in loop. Use threading and multiprocessing with discretion.
344The following line contains subprocess.Popen usage. Use threading and multiprocessing with discretion.
139The following line contains subprocess.Popen.communicate usage. Use threading and multiprocessing with discretion.
139The following line contains subprocess.Popen usage. Use threading and multiprocessing with discretion.
60PRIVATE IP 192.168.1.1 is found in lib/google/logging/type/http_request.proto:60
115666PUBLIC IP 1.3.1.1 is found in lib/grpc/_cython/cygrpc.cpython-310-x86_64-linux-gnu.so:115666
66PUBLIC IP 1.22.233.40 is found in lib/google/api/field_info.proto:66
60PRIVATE IP 10.0.0.1 is found in lib/google/logging/type/http_request.proto:60
70PUBLIC IP 5.5.5.5 is found in lib/PySocks-1.7.1.dist-info/METADATA:70
58Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
61Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
17Detected splunktaucclib (version 8.1.0). No action required.
58Detected solnlib (version 8.1.0). No action required.
Lodash 4.17.23 and earlier are vulnerable to a prototype pollution bypass in _.unset and _.omit. The fix for CVE-2025-13465 only guards against string key members, so attackers can bypass it by passing array-wrapped path segments to delete properties from built-in prototypes including Object.prototype, Number.prototype, and String.prototype.
Lodash _.template is vulnerable to code injection via unsanitized options.imports key names. Untrusted key names are passed to the Function() constructor sink without validation, and the use of assignInWith (which enumerates inherited properties) also means that pre-existing prototype pollution on Object.prototype can flow into the Function() sink and execute arbitrary code at template compilation time.
No ../.dependencies folder found. Please check that the Splunk App package contains only valid dependencies.
No ../.dependencies folder found. Please add a .dependencies directory with an valid app folder.
No ../.dependencies folder found. Please add a .dependencies directory that contains an app folder with an app.manifest.
authentication.conf does not exist
authentication.conf does not exist
authentication.conf does not exist
authentication.conf does not exist
authorize.conf does not exist
Didn't find any flash files.
alert_actions.conf does not exist
distsearch.conf does not exist
authorize.conf does not exist
indexes.conf does not exist
inputs.conf does not exist
inputs.conf does not exist
The `lookups` directory does not exist.
`inputs.conf` does not exist.
inputs.conf does not exist
authentication.conf does not exist
The `static` directory does not exist.
audit.conf does not exist
bookmarks.conf does not exist
datatypesbnf.conf does not exist
default-mode.conf does not exist
deploymentclient.conf does not exist
deployment.conf does not exist
indexes.conf.conf does not exist
inputs.conf.conf does not exist
health.conf does not exist
inputs.conf.conf does not exist
inputs.conf does not exist
inputs.conf does not exist
inputs.conf does not exist
inputs.conf.conf does not exist
inputs.conf does not exist
inputs.conf does not exist
inputs.conf.conf does not exist
inputs.conf does not exist
instance.cfg.conf does not exist
crawl.conf does not exist
literals.conf does not exist
messages.conf does not exist
No `inputs.conf.spec` was detected.
passwords.conf does not exist
pubsub.conf does not exist
segmenters.conf does not exist
serverclass.conf does not exist
serverclass.seed.xml.conf does not exist
source-classifier.conf does not exist
sourcetypes.conf does not exist
splunk-launch.conf does not exist
telemetry.conf does not exist
`default/transforms.conf` does not exist.
user-seed.conf does not exist
wmi.conf does not exist
workload_pools.conf does not exist
workload_rules.conf does not exist
228Splunk has begun gathering telemetry on apps submitted to appinspect, that utilize SplunkJS. Please ignore this warning as it has no impact to your Splunk app. Match: splunkjs/mvc
Splunk SDK for JavaScript not found.
limits.conf does not exist
outputs.conf does not exist
data/spl2 does not exist
savedsearches.conf does not exist
No invocations of bundled NodeJS binary found.
alert_actions.conf does not exist
No `inputs.conf.spec` file exists.
inputs.conf does not exist
eventtypes.conf does not exist
crawl.conf does not exist
viewstates.conf does not exist
savedsearches.conf does not exist
outputs.conf does not exist
literals.conf does not exist
707 Python files found. Update these Python scripts to be cross-compatible with Python 2 and 3 for Splunk Enterprise 8.0. See https://docs.splunk.com/Documentation/Splunk/latest/Python3Migration/AboutMigration for more information. If you've finished your update, please disregard this message.
No static/tool_input_payload_signatures.json file exists.
tools.conf does not exist
tools.conf does not exist
tools.conf does not exist
tools.conf does not exist
tools.conf does not exist
tools.conf does not exist
tools.conf does not exist
tools.conf does not exist
tools.conf does not exist
tools.conf does not exist
README/inputs.conf.spec does not exist.
inputs.conf does not exist
No `inputs.conf.spec` file exists.
inputs.conf does not exist
inputs.conf does not exist
lookups folder does not exist
savedsearches.conf does not exist
savedsearches.conf does not exist
savedsearches.conf does not exist
savedsearches.conf does not exist
savedsearches.conf does not exist
savedsearches.conf does not exist
`local/app.conf` does not exist.
`local/app.conf` does not exist.
The local directory does not exist.
collections.conf does not exist
collections.conf does not exist
15Repeat item name 'TRUNCATE' at line 15 in [source::...trackmelookupsmonitor.log] of props.conf.
indexes.conf does not exist
indexes.conf does not exist
indexes.conf does not exist
indexes.conf does not exist
indexes.conf does not exist
No INGEST_EVAL properties were declared.
alert_actions.conf does not exist
alert_actions.conf does not exist
No `alert_actions.conf` was detected.
transforms.conf does not exist
workflow_actions.conf does not exist
5Stanza [admin_external:ta_trackme_lookupmonitor_settings] does not define python.required. Option python.required is required for REST handlers with handlertype set to 'python'. Please update your app to be compatible with Python 3.13 and set python.required to '3.13'.
5Stanza [admin_external:ta_trackme_lookupmonitor_settings] does not define python.required. Option python.required is required for REST handlers with handlertype set to 'python'. Please update your app to be compatible with Python 3.13 and set python.required to '3.13'.
datamodels.conf does not exist
No forbidden python files were found.
35Detected an outdated version of the Splunk SDK for Python (2.1.1). Upgrade to 3.0.0 or later.
Directory does not contain Splunk SDK for Python.
3Detected an outdated version of the Splunk SDK for Python (2.1.1). Upgrade to 3.0.0 or later.
347The following line contains subprocess.Popen.communicate usage. Use threading and multiprocessing with discretion.
165The following line contains questionable usage `threading.Thread.start` in loop. Use threading and multiprocessing with discretion.
344The following line contains subprocess.Popen usage. Use threading and multiprocessing with discretion.
139The following line contains subprocess.Popen.communicate usage. Use threading and multiprocessing with discretion.
139The following line contains subprocess.Popen usage. Use threading and multiprocessing with discretion.
Python httplib2 library not found.
addon_builder.conf does not exist
60PRIVATE IP 192.168.1.1 is found in lib/google/logging/type/http_request.proto:60
115666PUBLIC IP 1.3.1.1 is found in lib/grpc/_cython/cygrpc.cpython-310-x86_64-linux-gnu.so:115666
66PUBLIC IP 1.22.233.40 is found in lib/google/api/field_info.proto:66
60PRIVATE IP 10.0.0.1 is found in lib/google/logging/type/http_request.proto:60
70PUBLIC IP 5.5.5.5 is found in lib/PySocks-1.7.1.dist-info/METADATA:70
No pom.xml, build.gradle or build.gradle.kts file found
58Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
61Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
17Detected splunktaucclib (version 8.1.0). No action required.
58Detected solnlib (version 8.1.0). No action required.