OpenVSX Registry Verified

Go

by golang
de9e90ab-c395-5a11-8b44-c5e71a39d993 | v0.56.1
44/ 100
MEDIUM risk
No change since v0.56.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

Analysis record

Analysed
1 months ago
Version
v0.56.1
Artifact
SHA256 453…74B
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

13 detail rows

Publisher Evidence

Low

golang

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

65
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
539
Portfolio

12 evidence rows available.

Finding Categories

1
Network

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This is the official Go extension for Visual Studio Code, published by the golang developer account with over 20 million users. The extension's stated purpose is providing Go language support including debugging, which justifies all observed behaviors.

Filesystem and Process Access: The extension contains standard npm dependencies listed in /extension/package.json including [email protected], [email protected], and [email protected]. These are legitimate VS Code language server and debugging infrastructure packages. A Go language server extension must read source files to provide IntelliSense, diagnostics, and debugging capabilities—this is the extension's core function, not suspicious behavior.

Network Activity: The single network finding shows a WebSocket call in extension/dist/debugAdapter.js:13576. Debug adapters in VS Code communicate with language-specific debuggers via WebSocket connections. The Go debugger (delve) uses this protocol to communicate with the extension. This is documented, expected behavior for any debugger extension and poses no security risk.

Credential Access: No findings indicate credential access. The findings_summary shows zero secret findings and zero credential-related code-smell matches. The extension does not access .env files, SSH keys, or cloud credentials.

Strongest Counterargument: The medium-severity network finding could theoretically indicate unexpected communication. However, WebSocket communication is the standard protocol for VS Code debug adapters, and the file path extension/dist/debugAdapter.js confirms this is the debugger component, not an arbitrary network call. The extension's publisher (golang) is the official Go team, and the 20+ million user count demonstrates widespread trust in this extension.

False Positive Drivers: All 12 dependency findings are simply npm package declarations in package.json, not malicious code. The single network finding is expected debug adapter behavior. Zero malware signatures, zero IoC matches, and zero obfuscation findings confirm this is a benign extension with normal automated scanner noise.

Key Reasons

  • Official extension from golang publisher with 20+ million users
  • Zero malware signatures or IoC matches
  • All dependency findings are legitimate npm packages
  • WebSocket call is expected debug adapter behavior
  • No credential access or suspicious file operations

False Positive Considerations

  • Dependency package declarations flagged as findings
  • Debug adapter WebSocket communication flagged as network risk
  • Bundled dist/ files contain expected language server code

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.

Open VSX version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
0.52.2
Apr 18, 2026
Risk range
44 to 44
Across analyzed versions
Latest analyzed version
0.56.1
Aug 29, 2026
Selected version
medium
Version
v0.56.1
1 months ago
Risk score
44
Findings
13
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Rich Go language support for Visual Studio Code

Frequently Asked Questions