Table of Contents

Enum ThreatVerdict

Namespace
Archiver.Core.Models
Assembly
Archiver.Core.dll

T-F146. Named ThreatVerdict/ThreatFinding/ThreatScanResult (not "Scan*") deliberately — TarSandboxedService.ScanForUnsafeEntriesAsync already owns "Scan" for the unrelated T-F49 traversal/symlink pre-scan; keeping the two grep-separable avoids confusing them. Inconclusive must never be silently rendered as Clean by any caller — it means "Pakko could not determine an answer" (no AMSI provider registered, a provider call failed, an entry was too large to buffer, or a tar-family entry vanished/became unreadable between extraction and scan), which is a different fact from a scan that genuinely came back negative.

public enum ThreatVerdict

Fields

Clean = 0

Scanned successfully and no threat was found.

Inconclusive = 2

Pakko could not determine an answer (no AMSI provider registered, a provider call failed, an entry was too large to buffer, etc.) — never treat this as Clean.

ThreatDetected = 1

The AV provider flagged a threat.