← Home

@vscode/chat-lib

Chat and inline editing SDK extracted from VS Code Copilot Chat

5
Versions
SEE LICENSE IN LICENSE.txt
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

vscode-botmicrosoft1es

Keywords

chataisdkvscodecopilot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:postinstall AI (install-scripts): Microsoft-published VSCode SDK; postinstall is a tsx script runner, consistent with documented SDK setup across versions. ai
phantom-deps phantom-dep:undici AI (phantom-deps): undici is declared as a direct runtime dependency in package.json; phantom-dep finding is a false positive. ai

Versions (showing 5 of 5)

Version Deps Published
0.50.2026052010 15 / 11
0.49.2026051802 15 / 11
0.49.2026051801 15 / 11
0.46.0 15 / 11
0.44.1 15 / 12

v0.50.2026052010

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.49.2026051802

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.49.2026051801

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.