← Home

@ripple-ts/language-server

Language Server Protocol implementation for Ripple

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

leonidaz_npmtrueadmwebeferen

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/typescriptService-CWMxKghf.js AI (source-diff): Rolldown-bundled TypeScript language service; network+dynamic-exec is expected for LSP + TS compiler APIs. ai
source-diff net-exec-file:dist/server-DYOT_ulV.js AI (source-diff): Rolldown-bundled LSP server; network+exec pattern is inherent to LSP communication and TypeScript service loading, not malware. ai
source-diff net-exec-file:dist/server-CiwRUSRR.js AI (source-diff): Rolldown-bundled LSP server; network+exec pattern is inherent to the language server use case, not malware. ai
source-diff net-exec-file:dist/server-BNcMp4pJ.js AI (source-diff): Rolldown-bundled LSP server; network+exec pattern is from bundled Volar/TS tooling, not malware. SLSA provenance confirms CI build integrity. ai
source-diff net-exec-file:dist/typescriptService-CVPtEiKA.js AI (source-diff): Rolldown-bundled TypeScript language service; network+exec pattern is from bundled volar/TS tooling, not malware. ai
source-diff net-exec-file:dist/server-CPmlKSwW.js AI (source-diff): Standard rolldown bundle for an LSP server; network+exec pattern is expected for language server functionality, not malware. ai
publish-pattern new-deps-added AI (publish-pattern): volar-service-css is a legitimate Volar ecosystem CSS service; addition is consistent with language server feature expansion. ai
source-diff net-exec-file:dist/server-BvQFo7aV.js AI (source-diff): Standard rolldown bundle for an LSP server; network+exec pattern is expected for language server functionality, not malware. ai
source-diff net-exec-file:dist/typescriptService-mlv6mda-.js AI (source-diff): Large bundled TypeScript service file; rolldown runtime boilerplate, not dropper malware. Consistent with language server embedding TS tooling. ai
phantom-deps phantom-dep:volar-service-typescript AI (phantom-deps): volar-service-typescript is a declared runtime dep used via config/plugin registration, not direct import; stable false positive. ai
source-diff source-size-tripled AI (source-diff): Size increase explained by bundling TypeScript language service; expected for this package type. ai
dependencies unvetted-dep:@ripple-ts/typescript-plugin AI (dependencies): Sibling package from the same monorepo; expected dependency for this package across all versions. ai

Versions (showing 51 of 99)

View all versions
Version Deps Published
0.3.72 7 / 4
0.3.71 7 / 4
0.3.70 7 / 4
0.3.69 7 / 4
0.3.68 7 / 4
0.3.67 7 / 4
0.3.66 7 / 4
0.3.65 7 / 4
0.3.64 7 / 4
0.3.63 7 / 4
0.3.62 7 / 4
0.3.61 7 / 2
0.3.60 7 / 2
0.3.59 7 / 2
0.3.58 7 / 2
0.3.57 7 / 2
0.3.54 7 / 2
0.3.53 7 / 2
0.3.52 7 / 2
0.3.51 7 / 2
0.3.49 7 / 2
0.3.48 7 / 2
0.3.47 7 / 2
0.3.46 7 / 2
0.3.45 7 / 2
0.3.44 7 / 2
0.3.43 7 / 2
0.3.42 7 / 2
0.3.41 7 / 2
0.3.40 7 / 2
0.3.39 7 / 2
0.3.38 7 / 2
0.3.37 7 / 2
0.3.36 7 / 2
0.3.35 7 / 2
0.3.34 7 / 2
0.3.33 7 / 2
0.3.32 7 / 2
0.3.31 7 / 2
0.3.30 7 / 2
0.3.29 7 / 2
0.3.28 7 / 2
0.3.27 7 / 2
0.3.26 7 / 2
0.3.5 6 / 1
0.3.4 6 / 1
0.2.208 6 / 1
0.2.207 6 / 1
0.2.206 6 / 1
0.2.205 6 / 1
0.2.204 6 / 1

v0.3.72

2 findings
HIGH New file with network + code execution: dist/server-DYOT_ulV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.71

2 findings
HIGH New file with network + code execution: dist/server-CiwRUSRR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.70

2 findings
HIGH New file with network + code execution: dist/server-CiwRUSRR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.69

2 findings
HIGH New file with network + code execution: dist/server-CiwRUSRR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.68

2 findings
HIGH New file with network + code execution: dist/server-CPmlKSwW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.67

2 findings
HIGH New file with network + code execution: dist/server-CPmlKSwW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.66

2 findings
HIGH New file with network + code execution: dist/server-CPmlKSwW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.65

2 findings
HIGH New file with network + code execution: dist/server-CPmlKSwW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.64

2 findings
HIGH New file with network + code execution: dist/server-CPmlKSwW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.63

2 findings
HIGH New file with network + code execution: dist/server-CPmlKSwW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.62

2 findings
HIGH New file with network + code execution: dist/server-CPmlKSwW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.61

2 findings
HIGH New file with network + code execution: dist/server-BNcMp4pJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.60

2 findings
HIGH New file with network + code execution: dist/server-BNcMp4pJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.59

2 findings
HIGH New file with network + code execution: dist/server-BNcMp4pJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.58

2 findings
HIGH New file with network + code execution: dist/server-BNcMp4pJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.57

2 findings
HIGH New file with network + code execution: dist/server-BvQFo7aV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.54

2 findings
HIGH New file with network + code execution: dist/typescriptService-mlv6mda-.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.53

2 findings
HIGH New file with network + code execution: dist/typescriptService-mlv6mda-.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.52

2 findings
HIGH New file with network + code execution: dist/typescriptService-mlv6mda-.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.51

2 findings
HIGH New file with network + code execution: dist/typescriptService-mlv6mda-.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.49

2 findings
HIGH New file with network + code execution: dist/typescriptService-mlv6mda-.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.48

2 findings
HIGH New file with network + code execution: dist/typescriptService-mlv6mda-.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.47

2 findings
HIGH New file with network + code execution: dist/typescriptService-mlv6mda-.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.46

2 findings
HIGH New file with network + code execution: dist/typescriptService-CVPtEiKA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.45

2 findings
HIGH New file with network + code execution: dist/typescriptService-CVPtEiKA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.44

2 findings
HIGH New file with network + code execution: dist/typescriptService-CVPtEiKA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.43

2 findings
HIGH New file with network + code execution: dist/typescriptService-CVPtEiKA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.42

2 findings
HIGH New file with network + code execution: dist/typescriptService-CWMxKghf.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.208

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.207

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.206

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.205

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.204

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.