← Home

@aws/lsp-codewhisperer

CodeWhisperer Language Server

14
Versions
Apache-2.0
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ege0zcanrtarcrimykhaiviktorsawsrahmaniaamaws-language-server-runtimes-team

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): New deps are official Amazon-internal SDK bundles required for the service client. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Localhost OAuth redirect (127.0.0.1) for MCP client, not exfil to external host. ai
maintainer-change maintainer-removed AI (maintainer-change): AWS org package published via GitHub Actions CI/CD with SLSA provenance; maintainer rotation is expected for org-managed packages. ai
dependencies unvetted-dep:@amzn/codewhisperer AI (dependencies): Internal bundled dep; not a registry package by design. ai
npm-metadata url-dep:@amazon/elastic-gumby-frontend-client AI (npm-metadata): Bundled internal Amazon SDK; file: dep is intentional and consistent across all versions. ai
npm-metadata url-dep:@amzn/codewhisperer AI (npm-metadata): Bundled internal Amazon SDK; file: dep is intentional and consistent across all versions. ai
npm-metadata url-dep:@amzn/codewhisperer-runtime AI (npm-metadata): Bundled internal Amazon SDK; file: dep is intentional and consistent across all versions. ai
dependencies unvetted-dep:@amazon/elastic-gumby-frontend-client AI (dependencies): Internal bundled dep; not a registry package by design. ai
dependencies unvetted-dep:@amzn/codewhisperer-runtime AI (dependencies): Internal bundled dep; not a registry package by design. ai
dependencies unvetted-dep:@amzn/amazon-q-developer-streaming-client AI (dependencies): Bundled internal tarball from AWS monorepo; not a registry dep to vet separately. ai
dependencies unvetted-dep:@amzn/codewhisperer-streaming AI (dependencies): Bundled internal tarball from AWS monorepo; not a registry dep to vet separately. ai
npm-metadata url-dep:@amzn/codewhisperer-streaming AI (npm-metadata): Internal AWS streaming client bundled as tarball; stable pattern for this monorepo package. ai
phantom-deps phantom-dep:hpagent AI (phantom-deps): hpagent is a proxy agent used via config/options passing, not direct import; stable false positive. ai
npm-metadata url-dep:@types/local-indexing AI (npm-metadata): Dev-only local type definition tgz; no runtime risk. ai
npm-metadata url-dep:@amzn/amazon-q-developer-streaming-client AI (npm-metadata): Intentional bundled local tgz dep pattern used consistently across this package's versions. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall installs transitive deps consistent with bundled file-path dependency pattern in this monorepo package. ai
semgrep semgrep:child-process-import AI (semgrep): child_process used to manage Docker containers for MCP tooling — core feature of an agentic coding assistant. ai
phantom-deps phantom-dep:@mozilla/readability AI (phantom-deps): Declared in package.json; stable false positive for this package. ai
semgrep semgrep:env-spread AI (semgrep): env-spread is used to pass environment variables to a bash execution tool — expected behavior for an agentic coding assistant. ai
semgrep semgrep:etc-passwd-access AI (semgrep): Finding is in a path-sanitization guard that blocks /etc/passwd traversal attacks, not credential harvesting code. ai
semgrep semgrep:eval-usage AI (semgrep): eval used only for dynamic ESM import of a local vector library path; not user-controlled input. ai
phantom-deps phantom-dep:encoding-japanese AI (phantom-deps): Declared in package.json; stable false positive for this package. ai
phantom-deps phantom-dep:picomatch AI (phantom-deps): Declared in package.json but used transitively; stable false positive for this package. ai

Versions (showing 14 of 14)

Version Deps Published
0.0.120 41 / 22
0.0.116 41 / 22
0.0.113 41 / 22
0.0.89 39 / 21
0.0.59 35 / 20
0.0.56 35 / 18
0.0.52 35 / 18
0.0.51 35 / 18
0.0.50 35 / 18
0.0.47 34 / 18
0.0.46 34 / 18
0.0.43 33 / 17
0.0.40 32 / 17
0.0.37 31 / 17

v0.0.120

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.89

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: aws-language-server-runtimes-team → GitHub Actions (on 2025-11-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (aws-language-server-runtimes-team) on 2025-11-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.