Spectra Assure
Community
Docs
warningRisk: Tampering
Scanned: 2 days ago

Go

Artifact:
Rich Go language support for Visual Studio Code
License: Permissive (MIT)
Published: 15 days ago

Publisher: golang



SAFE Assessment

Compliance

Licenses
No license compliance issues
Secrets
No sensitive information found

Security

Vulnerabilities
No known vulnerabilities detected
Hardening
No application hardening issues

Threats

Tampering
1 components with malware history
Malware
No evidence of malware inclusion

INCIDENTS FOR THIS VERSION:

Popularity

17.14M
Total Installs
Contributor
Declared Dependencies
17
Dependents

Top issues

Problem

Software developers use programming and design knowledge to build reusable software components. Software components are the basic building blocks for modern applications. Software consumed by an enterprise consists of hundreds, and sometimes even thousands of open source components. Software developers publish components they have authored to public repositories. Some open source projects have a history of security lapses that culminated with a publication of one or more malicious component versions. To ensure that repeated supply chain incidents do not occur, the open source project should be closely monitored for up to two years. All software package versions that are published within two years of the malware incident will convey a warning about the history of security incidents tied to the open source project.

Prevalence in Visual Studio Code community

24 packages
found in
Top 100
102 packages
found in
Top 1k
326 packages
found in
Top 10k
1057 packages
in community

Next steps

Inspect behaviors exhibited by the detected software components.
If the software behaviors differ from expected, investigate the build and release environment for software supply chain compromise.
Revise the use of components that raise these alarms. If you can't deprecate those components, make sure that their versions are pinned.
Avoid using this software package until it is vetted as safe.

Top behaviors

Prevalence in Visual Studio Code community

Behavior often found in this community (Common)
85 packages
found in
Top 100
673 packages
found in
Top 1k
4329 packages
found in
Top 10k
28768 packages
in community

Prevalence in Visual Studio Code community

Behavior often found in this community (Common)
81 packages
found in
Top 100
631 packages
found in
Top 1k
3887 packages
found in
Top 10k
24357 packages
in community

Prevalence in Visual Studio Code community

Behavior often found in this community (Common)
73 packages
found in
Top 100
573 packages
found in
Top 1k
3170 packages
found in
Top 10k
17492 packages
in community

Prevalence in Visual Studio Code community

Behavior often found in this community (Common)
76 packages
found in
Top 100
599 packages
found in
Top 1k
3178 packages
found in
Top 10k
16700 packages
in community

Prevalence in Visual Studio Code community

Behavior often found in this community (Common)
47 packages
found in
Top 100
303 packages
found in
Top 1k
1634 packages
found in
Top 10k
8176 packages
in community

Top vulnerabilities

No vulnerabilities found.