← Home

@aws/lsp-core

11
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ege0zcanrtarcrimykhaisaurishagkellerviktorsawsrahmaniaamaws-language-server-runtimes-team

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): cross-spawn and gitignore-parser are legitimate, widely-used utilities. ai
dependencies unvetted-dep:@gerhobbelt/gitignore-parser AI (dependencies): Legitimate gitignore parsing utility, used as-is by known maintainer. ai
semgrep semgrep:etc-passwd-access AI (semgrep): References appear only in test assertions verifying that path traversal to /etc/passwd is blocked, not actual credential access. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding is used to deserialize an encryption key passed at initialization — legitimate credential handling for an LSP server. ai
semgrep semgrep:child-process-import AI (semgrep): child_process is used in processUtils.js for legitimate subprocess management in an LSP server context. ai
bogus-package bogus-package AI (bogus-package): AWS-published LSP library; sparse README/keywords are cosmetic issues, not spam indicators. ai

Versions (showing 11 of 11)

Version Deps Published
0.0.21 8 / 12
0.0.19 8 / 12
0.0.18 8 / 12
0.0.16 8 / 12
0.0.14 8 / 12
0.0.8 7 / 11
0.0.7 7 / 11
0.0.6 7 / 11
0.0.5 7 / 11
0.0.2 6 / 10
0.0.1 5 / 10

v0.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.