← Home

@aws/language-server-runtimes

Runtimes to host Language Servers for AWS

3
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ege0zcanrtarcrimykhaiviktorsawsrahmaniaamaws-language-server-runtimes-team

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD publishing with SLSA attestation; legitimate automation change for this AWS package. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy followed by GitHub Actions publishing with SLSA attestation; consistent with CI/CD pipeline migration, not takeover. ai
dependencies unvetted-dep:mac-ca AI (dependencies): mac-ca is a well-known macOS CA certificate accessor; legitimate use for TLS in AWS tooling. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 used for credential key decoding in auth module — legitimate crypto pattern, not payload obfuscation. ai
semgrep semgrep:child-process-import AI (semgrep): child_process used only for Mac proxy settings detection via scutil — expected system utility usage. ai
bogus-package bogus-package AI (bogus-package): Established AWS package; README link density and missing keywords are false positives for SDK-style documentation. ai

Versions (showing 3 of 103)

Version Deps Published
0.2.6 5 / 9
0.2.5 5 / 9
0.2.4 5 / 9

v0.2.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.