Browse documentation
Docs/Extension management

Understanding vetting results

Read extension states and evidence without confusing a request decision with a security verdict.

Read the state first

  • Allowed means the vetted version is included in this allowlist's published feed.
  • Queued means a job is waiting, or the extension needs to be vetted again. A real waiting job shows its queue number.
  • Vetting means analysis is running now.
  • Blocked means the automated pipeline found blocking evidence.
  • Cannot vet means analysis coverage was insufficient. It does not mean safe.

Allow does not require a person to approve each security verdict. Approving a member request only admits the extension to this automated vetting flow.

Inspect the evidence

Expand an extension row to see the evidence that is available for that run. This can include publisher identity and code signing, static findings, Tier A and Tier B runtime analysis, and a judge recommendation with confidence.

Evidence varies by extension. Missing or inconclusive analysis can produce Cannot vet instead of Allowed.

Manage queued work

Select Prioritize 🚀 to move a queued extension ahead of normal-priority jobs. If a queued row no longer has a live job, Re-vet 🔄 creates a new one.

New versions

Allow keeps the currently allowed version visible while it vets a newer release. A successful Allowed result advances the published version. A Blocked or Cannot vet update does not replace the trusted version.

No automated assessment can guarantee that software is harmless. Use the evidence together with your wider endpoint and incident-response controls.