@vscode/debugadapter
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Publish env moved to bot; gitHead absence benign for this org. | ai | |
| provenance | publisher-changed-stale | AI (provenance): connor.peet→vscode-bot handoff, stable 1141d on npm. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Documented Microsoft org→vscode-bot transfer; stable publisher. | ai | |
| source-diff | obfuscated-file:lib/tests/DebugAdapter.test.js | AI (source-diff): Long-line URI-conversion assertion table in test file; benign, not obfuscation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Same org transfer to bot account; not a takeover. | ai | |
| source-diff | obfuscated-file:lib/nodeDependencies.js | AI (source-diff): Compiled TS with long lines, not obfuscation; readable Microsoft-authored code. | ai | |
| provenance | no-provenance | AI (provenance): Published by Microsoft's vscode-bot with a strong track record; lack of Sigstore provenance is not a risk signal for this well-established package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established Microsoft VS Code tooling package; short README and no keywords are cosmetic issues, not spam indicators. Stable across versions. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 1.68.0 | 1 / 3 | |
| 1.67.0 | 1 / 3 | |
| 1.66.0 | 1 / 3 | |
| 1.65.0 | 1 / 3 | |
| 1.64.0 | 1 / 3 | |
| 1.63.0 | 1 / 3 | |
| 1.61.0 | 1 / 3 | |
| 1.59.0 | 1 / 3 | |
| 1.58.0 | 1 / 2 | |
| 1.57.0 | 1 / 2 | |
| 1.56.1 | 1 / 2 | |
| 1.56.0 | 1 / 2 | |
| 1.55.1 | 1 / 2 | |
| 1.55.0 | 1 / 2 | |
| 1.54.0 | 2 / 5 | |
| 1.53.0 | 2 / 5 | |
| 1.51.1 | 2 / 5 | |
| 1.51.0 | 2 / 5 |
v1.67.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.0
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: vscode-bot.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (vscode-bot) than the most recent previously approved version (connor.peet) on 2024-02-27. It has since remained available on npm for 875 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.0
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: vscode-bot.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (vscode-bot) than the most recent previously approved version (connor.peet) on 2023-10-27. It has since remained available on npm for 997 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.63.0
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: vscode-bot.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (vscode-bot) than the most recent previously approved version (connor.peet) on 2023-08-31. It has since remained available on npm for 1054 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.0
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: vscode-bot.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (vscode-bot) than the most recent previously approved version (connor.peet) on 2023-06-05. It has since remained available on npm for 1141 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.59.0
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: vscode-bot.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (vscode-bot) than the most recent previously approved version (connor.peet) on 2023-01-29. It has since remained available on npm for 1269 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.58.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.57.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.56.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.56.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.55.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.55.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.54.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (aweinand) than the most recent previously approved version (connor.peet) on 2022-02-24, but aweinand is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.53.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.51.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.51.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.