← Home

@aws/language-server-runtimes

Runtimes to host Language Servers for AWS

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ege0zcanrtarcrimykhaiviktorsawsrahmaniaamaws-language-server-runtimes-team

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD publishing with SLSA attestation; legitimate automation change for this AWS package. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy followed by GitHub Actions publishing with SLSA attestation; consistent with CI/CD pipeline migration, not takeover. ai
dependencies unvetted-dep:mac-ca AI (dependencies): mac-ca is a well-known macOS CA certificate accessor; legitimate use for TLS in AWS tooling. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 used for credential key decoding in auth module — legitimate crypto pattern, not payload obfuscation. ai
semgrep semgrep:child-process-import AI (semgrep): child_process used only for Mac proxy settings detection via scutil — expected system utility usage. ai
bogus-package bogus-package AI (bogus-package): Established AWS package; README link density and missing keywords are false positives for SDK-style documentation. ai

Versions (showing 100 of 103)

Version Deps Published
0.3.19 18 / 15
0.3.18 18 / 15
0.3.17 18 / 15
0.3.16 18 / 15
0.3.15 18 / 15
0.3.14 20 / 15
0.3.13 20 / 15
0.3.12 20 / 15
0.3.11 20 / 16
0.3.10 20 / 16
0.3.9 20 / 15
0.3.8 20 / 15
0.3.7 20 / 15
0.3.6 20 / 15
0.3.5 20 / 15
0.3.4 20 / 15
0.3.3 20 / 15
0.3.1 20 / 15
0.3.0 20 / 15
0.2.129 21 / 15
0.2.128 21 / 15
0.2.127 21 / 15
0.2.126 21 / 15
0.2.125 21 / 15
0.2.124 21 / 15
0.2.123 21 / 15
0.2.122 21 / 15
0.2.121 21 / 15
0.2.120 21 / 15
0.2.119 21 / 15
0.2.118 21 / 15
0.2.117 21 / 15
0.2.116 21 / 15
0.2.115 21 / 15
0.2.114 21 / 15
0.2.113 21 / 15
0.2.112 21 / 15
0.2.111 21 / 15
0.2.110 21 / 15
0.2.109 21 / 15
0.2.108 21 / 15
0.2.107 21 / 15
0.2.106 21 / 15
0.2.105 21 / 15
0.2.104 21 / 15
0.2.103 21 / 15
0.2.102 21 / 15
0.2.101 21 / 15
0.2.100 21 / 15
0.2.99 21 / 15
0.2.98 21 / 15
0.2.97 21 / 15
0.2.96 21 / 15
0.2.95 21 / 15
0.2.94 21 / 15
0.2.93 21 / 15
0.2.92 20 / 15
0.2.91 20 / 15
0.2.90 20 / 15
0.2.89 20 / 15
0.2.88 19 / 16
0.2.87 19 / 16
0.2.86 19 / 16
0.2.85 19 / 16
0.2.84 19 / 16
0.2.83 19 / 16
0.2.82 19 / 16
0.2.81 18 / 16
0.2.80 18 / 16
0.2.79 18 / 16
0.2.78 19 / 15
0.2.35 8 / 9
0.2.34 8 / 9
0.2.33 5 / 9
0.2.32 5 / 9
0.2.31 5 / 9
0.2.30 5 / 9
0.2.29 5 / 9
0.2.28 5 / 9
0.2.27 5 / 9
0.2.26 5 / 9
0.2.25 5 / 9
0.2.24 5 / 9
0.2.23 5 / 9
0.2.22 5 / 9
0.2.21 5 / 9
0.2.20 5 / 9
0.2.19 5 / 9
0.2.18 5 / 9
0.2.17 5 / 9
0.2.16 5 / 9
0.2.15 5 / 9
0.2.14 5 / 9
0.2.13 5 / 9
0.2.12 5 / 9
0.2.11 5 / 9
0.2.10 5 / 9
0.2.9 5 / 9
0.2.8 5 / 9
0.2.7 5 / 9
Showing 100 of 103 Next page →

v0.3.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.